Network security system and method

The CyberSafe system addresses the vulnerability of BYOD devices to cyberattacks in modern communication networks through authentication, data monitoring, and policy enforcement, thereby enhancing the protection of enterprise resources and providing secure access control.

CN121729862APending Publication Date: 2026-03-24PALO ALTO NETWORKS INC
View PDF 0 Cites 0 Cited by

Patent Information

Authority / Receiving Office
CN · China
Patent Type
Applications(China)
Current Assignee / Owner
Filing Date
2024-08-17
Publication Date
2026-03-24

AI Technical Summary

Technical Problem

In modern communication networks, personal and enterprise user devices (especially BYOD) become potential nodes for cyberattacks, increasing the complexity of network protection and the risk of data leakage. In particular, in remote work environments, enterprise data faces vulnerability to cyberattacks and security challenges.

Method used

Provides the CyberSafe system, including a cloud-based data and processing security center and the CyberSafe secure browser, which enables user and device authentication, data content review and behavior monitoring by isolating a secure environment and monitoring and controlling data flow, enforcing security policies, and providing enhanced network protection and data access control.

Benefits of technology

It improves the network security of enterprise resources, reduces the risk of data leakage, enhances the ability to protect against network attacks, and ensures that user behavior complies with the enterprise's security policy.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure CN121729862A_ABST
    Figure CN121729862A_ABST
Patent Text Reader

Abstract

A method for authenticating an identity of a user equipment (UE) having a browser operative to browse and communicate with other entities, the method comprising: providing the UE with a trusted platform module (TPM) operative to generate a public / private key pair; configuring a browser to generate a request for access to a registration of a protected resource controlled by an entity, the entity enabling a UE registered with the entity to access the resource; in response to the request, operating the TPM to generate a public / private key pair; providing the entity with a UE identity, a public key, and a registration request to register the UE with the entity; and authenticating the UE identity to the entity using the public key and the private key.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] Related applications This application claims the benefit of U.S. Provisional Application 63 / 520099, filed August 17, 2023, pursuant to 35.119(e) of the United States Code, the disclosure of which is incorporated herein by reference. Technical Field

[0002] Embodiments of this disclosure relate to providing secure access channels and workspaces for communication networks and digital resources. Background Technology

[0003] The internet provides a wide range of computer and communication technologies, encompassing various virtual and bare-metal network elements (NEs) that support the operation of communication networks and provide access to them for fixed and / or mobile user equipment (UEs). These technologies have enabled information technology (IT) and operational technology (OT), the cornerstones of modern society, and provide numerous methods, devices, infrastructures, and protocols for controlling industrial equipment, supporting business operations, and generating and disseminating data, voice, and video content via the internet. Independent of physical location, the majority of the global population has easy access to all types of information via the internet. Furthermore, today, a large portion of the global community regularly uses their Bring Your Own Device (BYOD) and UEs—such as their personal smartphones, laptops, tablets, and home desktop computers—to work remotely from their homes, coffee shops, and vacation locations via connections to their employers and workgroups. The internet democratizes the consumption of information and accelerates changes in social infrastructure.

[0004] However, the benefits provided by computer and communication technologies are not without their costs. The same technologies and benefits greatly increase the difficulty of providing and maintaining legitimate personal and collective rights to confidentiality, as well as the difficulty of protecting the integrity and security of the very industrial and business operations that these technologies have enabled, from breaches and damage caused by cyberattacks.

[0005] For example, the fingerprint of a cyberattack surface characterizes each UE, whether it is an individual's spatially unconstrained BYOD or an enterprise workplace user equipment (WPUE), and provides vulnerabilities that malicious hackers can exploit to potentially cause serious damage to the UE, and more often to the entities and systems to which it is connected. Each UE, and especially a BYOD, is a potential cyberattack node for any communication network to which it is connected, in addition to being a personal communication node. For enterprises that must communicate with customers, workers, and / or colleagues who have at least partially shifted to using their personal BYODs for remote work, cyberattack vulnerabilities are amplified due to the number of their remote contacts, the software configuration in the corresponding BYODs of those contacts, and the diverse non-enterprise communications that contacts use the UEs to engage. The attraction of enterprise data and storage resources to the cloud, and the proliferation of technologies accessed and used by remote contacts, such as Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS), further complicate the provision of appropriate cyber protection. Summary of the Invention

[0006] One aspect of embodiments of this disclosure relates to providing a network security communication system, optionally referred to as the CyberSafe system or simply "CyberSafe," which provides enhanced visibility and management of communication traffic propagated by the system. CyberSafe utilizes enhanced visibility to provide network protection for authorized users of UEs (BOYD or WPUE) associated with resource subjects, and to provide these authorized users with secure access to the digital resources of the resource subjects.

[0007] Digital resources include any information in digital format, whether static or in motion, and include, for example, electronic documents, images, files, data, databases, and / or software, referring to executable code and / or data. Digital resources also include any software and / or hardware that can be used to operate on or generate digital resources. Digital resources in motion are those that are being used and / or operated on, and / or being transferred between nodes in a communication system. Static digital resources are those that are in a stored state rather than in motion.

[0008] For ease of presentation, it is assumed that the digital resource subject is owned by an enterprise (optionally referred to as "MyCompany"), which employs or participates in the task of authorizing users to access MyCompany resources using a UE associated with the resource subject. The UE associated with the resource subject is a UE configured according to embodiments of this disclosure to enable authorized users to access MyCompany resources, and may be referred to as a MyCompany UE. Users authorized to use the MyCompany UE to access MyCompany resources can be referred to as MyCompany users or simply users.

[0009] In an embodiment, CyberSafe includes, optionally cloud-based, a data and processing security center (also known as a CyberSafe center) and a web browser (also known as a CyberSafe secure web browser (SWB)) residing in a CyberSafe isolated security environment (CISE) of a MyCompany UE configured by or according to CyberSafe. In an embodiment, CISE operation is used to isolate software included in the SWB and other applications that may reside in the CISE from software within the UE and software outside the UE, also referred to as UE-peripheral software, which can be used for tasks not associated with MyCompany resources. In an embodiment, the SWB monitors and controls the movement of data in and out of the CISE and the movement of data between applications within the CISE, as well as access to MyCompany resources, to enforce CyberSafe and / or MyCompany security policies. In an embodiment, CyberSafe provides high visibility of data movement by configuring the SWB, thereby supporting high-resolution monitoring and control of data movement in and out of the CISE and data propagation by the communication system. Providing high visibility includes making communications outgoing from the CISE visible before they are encrypted by the SWB, and making communications arriving in the CISE visible after they are decrypted by the SWB. The isolation and control of data movement and access, and the enforcement of security policies according to embodiments of this disclosure, are used to provide enhanced protection against network corruption and security against data leaks originating from and / or entering MyCompany resources, which may result from communications with and via the MyCompany UE.

[0010] Isolation and control include providing procedures for registering users and UEs to MyCompany CyberSafe, enabling CyberSafe to identify and recognize these users and UEs, and restricting the registered users' and UEs' access to MyCompany resources. In an embodiment, the registration procedure provides the user and the UE that the user can use to access MyCompany resources with an identity and identification tool context, optionally referred to as context data, for check-in to use MyCompany resources. When a user attempts to check in on MyCompany, CyberSafe processes the context data to determine whether to grant the user access to MyCompany resources. For example, identity may include the MyCompany user's ID (U-ID), the MyCompany user's device ID (UE-ID), and / or the ID (B-ID) of the secure web browser housed in the MyCompany UE. For example, identity tools may include passwords, tokens, public keys, and / or private keys.

[0011] In embodiments, monitoring and controlling the movement of digital data includes reviewing the informational content of the data and controlling the movement of the data in response to the reviewed content. Reviewing the content may include identifying textual, image, audio, and / or video components of the data and processing these components to determine their respective informational content. Controlling the movement of data in response to the data content may include labeling and characterizing the data content, controlling access to the data, reviewing the data, such as through passwords, constraining the data to meet policy constraints, and / or optionally obfuscating the data in response to assessments of data confidentiality and permission from users associated with the data.

[0012] Monitoring and controlling data movement may include monitoring user behavior in operation and use of the MyCompany UE to determine User Key Performance Indicators (U-KPIs), which characterize user behavior when interacting with the MyCompany UE and MyCompany digital resources and using U-KPIs to control data movement. Optionally, monitoring user behavior includes recording and storing at least a portion of communication sessions participated in by the user using the MyCompany UE.

[0013] Optionally, monitoring data movement may include identifying groups of communication entities, including users, company resources and / or websites or other communication entities inside or outside MyCompany, to detect and act (optionally in real time) preemptively address network risks that MyCompany may be exposed to.

[0014] This invention provides summary information to introduce, in a simplified form, a series of concepts further described in the detailed embodiments below. This summary is not intended to identify key or essential features of the claimed subject matter, nor is it intended to limit the scope of the claimed subject matter. Attached Figure Description

[0015] Non-limiting examples of embodiments of the present invention are described below with reference to the accompanying figures listed after this paragraph. Identical features appearing in more than one figure are generally labeled using the same labels in all the figures in which they appear. Labels indicating icons representing given features of embodiments of the invention in the figures may be used to refer to the given feature. The dimensions of the features shown in the figures are chosen for ease of presentation and clarity and are not necessarily shown to scale.

[0016] Figure 1 The illustration schematically depicts a MyCompany UE according to an embodiment of the present disclosure, the MyCompany UE being configured with CyberSafeCISE and SWB to provide network security to an enterprise referred to as MyCompany; Figure 2A-2C A flowchart of a procedure according to an embodiment of the present disclosure is shown, through which... Figure 1 The SWB shown can participate in a handshake with the CyberSafe center to obtain a token for accessing MyCompany resources; Figure 2D-2E A flowchart of a CyberSafe method for protecting and using a User ID (U-ID) and a User Equipment ID (UE-ID) to access MyCompany resources, according to an embodiment of the present disclosure, is shown. Figure 3 A flowchart illustrating a method for controlling the creation of passwords (optionally referred to as dynamic password filtering) according to an embodiment of the present disclosure is shown. Figure 4 A flowchart of a method (optionally referred to as a scrambler) for obscuring a data stream generated by a user-operated human-machine interface device (such as a keyboard or mouse) according to an embodiment of the present disclosure is shown. Figure 5A A multi-plane diagram with user, resource, and website graphs, according to an embodiment of the present disclosure, is illustrated schematically, which facilitates visualization and processing of relationships between entities related to the activities of an enterprise. Figure 5B The illustration schematically depicts an active group of interactive entities that facilitates the identification and interception of cyber threats, according to embodiments of the present disclosure. Figure 5A The collection of entities displayed in the middle; Figure 6AA flowchart is shown of a method (optionally referred to as Resource Confidentiality Labelling (RECON)) for generating a digital signature based on a confidentiality level assigned to materials included in a resource, according to embodiments of the present disclosure; and Figure 6B A flowchart of RECON, which operates to review and control the movement of resources according to an embodiment of this disclosure, is shown. Detailed Implementation

[0017] In this discussion, unless otherwise stated, adjectives (such as “substantially” and “approximately”) modifying one or more features of embodiments of this disclosure are to be understood as meaning that the condition or feature is limited to an acceptable tolerance range for operation of the embodiment of the intended application. Where general terms in this disclosure are illustrated by reference to example instances or lists of example instances, the one or more instances mentioned are non-limiting example instances as general terms, and the general terms are not intended to be limited to the one or more specific example instances mentioned. The phrase “in an embodiment,” whether or not associated with permissive content (such as “may,” “optionally,” or “for example”), is used to introduce an example for consideration but is not necessarily a required configuration of a possible embodiment of this disclosure. Unless otherwise indicated, the word “or” in this description and claims is to be considered inclusive rather than exclusive and indicates at least one item or any combination of more than one item among their associated items. Although the features and actions of the flowcharts shown in the accompanying drawings and discussed in the specification are presented and discussed in a manner that is generally in the order specified by the block numbers in the accompanying drawings, the actions presented in the blocks may be performed simultaneously or at different times in an order not specified by the block numbers.

[0018] Figure 1A CyberSafe system 50 according to an embodiment of this disclosure is schematically illustrated. The CyberSafe system 50 operates to provide secure communication for a communication network of an enterprise 20 (also referred to as MyCompany 20 or simply MyCompany) and MyCompany users 10 using that communication network. MyCompany may have cloud-based digital resources 22, premises 24 housing premise servers (not shown) for storing and processing MyCompany's local premises digital resources 28, and WPUE 30 for MyCompany users 10 to access, use, and process cloud-based and local premises resources for MyCompany business. MyCompany may allow users 10 to access MyCompany resources from various locations using any of various types of BYOD 32 when in a remote location. It is assumed that MyCompany users 10 can use their respective BYOD 32 for personal activities, and that MyCompany users may be permitted to use WPUE 30 for personal activities when in a local location, according to permissions defined by MyCompany policies. Personal activities may include web browsing, social networking, uploading and downloading materials via the cloud infrastructure of communication node 41 and website 40. As schematically indicated by the double-headed dashed line 43, the MyCompany network may be required to support communication between any combination of MyCompany local location digital resources 28, cloud-based digital resources 22, local location users 10 using WPUE 30 installed in MyCompany location 24, and remote location users 10 using BYOD 32 at various remote location locations.

[0019] According to embodiments of this disclosure, CyberSafe 50 includes an optional cloud-based CyberSafe processing and data center 52 and a software architecture 60 that operates to provide network protection for MyCompany communication and digital resources in each of a plurality of MyCompany UEs, BYOD 32, and / or WPUE 30 used by MyCompany user 10 to access and use MyCompany resources. CyberSafe center 52 includes and / or has access to cloud-based and / or bare-metal processing and storage resources required to enable and support the functionality provided by the center to CyberSafe 50 and CyberSafe components.

[0020] In this embodiment, center 52 includes a user management module U-Mng 52.1, a user equipment management module UE-Mng 52.2, and a policy engine Pol-Eng 52.3. U-Mng 52.1 includes software supporting the functions provided by center 52 for identifying MyCompany users and enabling them to access and use MyCompany resources. U-Mng 52.1 includes a database with data records and software supporting functions using data and metadata, the data records including data identifying and describing MyCompany users. UE-Mng 52.2 includes software supporting the functions provided by center 52 for identifying MyCompany user equipment (UE) and facilitating MyCompany users' use of the UE. UE-Mng 52.2 includes a database with UE data records, the UE data records including data identifying and characterizing the software and / or hardware of the UE. Pol-Eng 52.3 includes software supporting the functions provided by center 52 for implementing MyCompany security policies. Pol-Eng 52.3 includes a repository of MyCompany policy projects and software for accessing and using policy projects, which include policy rules, guidelines, and / or practices.

[0021] For example, Figure 1 The CyberSafe software architecture 60 is schematically illustrated. The CyberSafe software architecture 60 configures MyCompany UE 33 to protect MyCompany's stationary and / or mobile digital resources and to provide network security access to these resources for users 10 who can use MyCompany UE 33. MyCompany UE 33 can be either BYOD or WPUE.

[0022] Architecture 60 includes a CyberSafe isolated environment (CISE62) isolated from the surrounding software 35 residing in UE 33, and includes an SWB 64 residing in CISE 62. In embodiments, SWB 64 may include a browser extension (EXT) that performs tasks involving registering UE 33 to MyCompany CyberSafe and mediating connections and access from UE 33 to MyCompany resources and / or monitoring interactions between UE 33 and resources. The surrounding software 35 may typically include data and applications not intended for MyCompany business. For example, the surrounding software 35 may include a browser, an office application suite, a clipboard, a family photo album, a photo album, and WhatsApp. CISE 62 may also include an application set 65, which may optionally be imported from the surrounding software 35 and wrapped by CyberSafe and optionally containerized to associate the cybersecurity features required by CyberSafe and / or MyCompany policy features with the applications. In this embodiment, CISE includes an ensemble of shared security services 66, which can be accessed for use by SWB 64 and via SWB 64 for use by applications in ensemble 65. Shared security services 66 may optionally include a secure clipboard and a secure encrypted file system.

[0023] CISE 62 provides an isolated security domain bounded by a substantially contiguous security perimeter, which is generated and supported by security applications, features, and functions packaged by SWB 64, shared security services 66, and packaged applications 65. According to embodiments, CISE 62 can be configured to provide network security and isolation using and complying with standard methods such as PCI DSS (Payment Card Industry Data Security Standard), HIPAA (Health Insurance Portability and Accountability Act), and / or SOC2 (American Institute of Certified Public Accountants Service Organization Control). Optionally, CISE 62 is isolated from surrounding software at the network level. In embodiments, CISE 62 includes a Trusted Platform Module (TPM) 71, which operates to generate and store cryptographic keys and optionally provides integrity measurements to support the root of trust for UE 33 when interacting with MyCompany. In an embodiment, CISE includes at least one watchdog 72 configured to monitor and / or perform integrity tests on SWB 64 and / or components of SWB (such as EXT 64.1).

[0024] In embodiments providing isolation and security, SWB 64 is configured to monitor and control the entry and exit of data into and out of CISE 62, as well as between applications within CyberSafe-packaged applications, shared security services 66, and / or SWB 64. SWB 64 is advantageously configured by CyberSafe to enforce CyberSafe and / or MyCompany security policies related to access to MyCompany data and data movement within and out of CISE. The isolation and control of data movement and access, along with the enforcement of policies, provides enhanced protection against network breaches and security against potential data leakage from and / or into MyCompany resources arising from and via communications with and through the MyCompany UE.

[0025] In this embodiment, monitoring the inflow and outflow of data includes monitoring communications supported by SWB 64, storing and processing data included in the monitored communications, and making the data available to the CyberSafe center and MyCompany IT. In this embodiment, outgoing communications are encrypted by SWBb before being sent from the CyberSafe isolated environment CISE 62 (…). Figure 1 Outgoing communications are monitored, and incoming communications are monitored after they are decrypted by SWB 64. As a result, user browsing is essentially fully visible to CyberSafe and MyCompany, and can be processed locally or remotely.

[0026] Monitoring can be substantially continuous, random, or periodic. Random monitoring involves monitoring communications for a limited duration, starting at a randomly determined start time, optionally based on a predetermined probability function or in response to a "trigger" event, such as an event deemed abnormal and requiring attention. Periodic monitoring involves continuously monitoring communications during monitoring periods with periodic start times. Monitored communications can be reflected by SWB 64 to destinations in the CyberSafe Center and / or MyCompany for storage and / or processing, or can be filtered for data of interest before being transmitted to destinations in the CyberSafe Center and / or MyCompany for storage and / or processing. Configuring how SWB 64 responds to the characteristics and constraints of monitored communications can be determined based on CyberSafe and / or MyCompany policies. Such policies can specify how data processing is shared between the local SWB and the CyberSafe Center.

[0027] In an embodiment, SWB 64 can be a standalone application including CyberSafe features and / or functionality, or an existing web browser such as Google Chrome, Microsoft Edge, Apple Safari, Mozilla Firefox, Opera, or Brave, modified and provided with additional CyberSafe features and / or functionality through changes to and / or additions to the browser code and / or integration with CyberSafe extensions. These features and functionality can be incorporated into an existing browser, and the browser can be converted into a CyberSafe SWB by: using operating system hooks to interface with the existing browser's input and output; patching the browser's raw binary content; building dedicated extensions on top of the browser's API and / or SDK; and / or dynamically modifying the browser's memory while the browser is operational.

[0028] For example, features and / or functions (generally referred to as functions below) may include at least one or any combination of functions that enable SWB 64 to perform: cooperate with MyCompany IDP to authenticate and authorize user 10 to access CISE 62 and MyCompany resources; acquire data characterizing websites accessed by MyCompany users, which can be used to classify network risks associated with the websites; acquire data characterizing browser extensions that may compromise the security features of SWB 64; acquire data that can be processed to determine the possible behaviors and uses of MyCompany resources by MyCompany users as a group and / or individuals; monitor the engagement of MyCompany users with MyCompany resources, and control such engagement to enforce CyberSafe and / or MyCompany security constraints.

[0029] In an embodiment, enforcing CyberSafe and / or MyCompany security constraints includes requiring all communication between UE 33 and the MyCompany resource to propagate via SWB 64 and the CyberSafe tunnel connecting the SWB to the resource, and enforcing CyberSafe and / or MyCompany permissions to the resource. Optionally, enforcing security constraints includes identifying anomalies in communication between UE 33 and the company resource, and operating to eliminate or mitigate damage from the identified anomalies, and generating an alert upon their occurrence.

[0030] According to an embodiment, Figures 2A to 2EThe presented flowchart illustrates the elements of a program executed by the CyberSafe system and SWBs (such as CyberSafe system 50 and SWB 64), demonstrating and illustrating the functionality of the CyberSafe system and SWBs. This discussion assumes that the CyberSafe system provides cybersecurity services to a given MyCompany enterprise, which has a user ID (…). Multiple users identified by ) Assume that the user can access and use the device identified by the user's device ID ( The user equipment is identified by the SWB browser ID (B-IDb), and CyberSafe has configured the UE with CISE and the CyberSafe browser SWBb identified by the SWB browser ID (B-IDb). .

[0031] Figure 2A-2C A flowchart 100 of the procedure is shown, through which a given user Un of user equipment UEe contacts CyberSafe Security Center 52, requests authorization to access and use CISE in UEe, and causes resident SWBb in CISE to issue a security token for accessing MyCompany resources.

[0032] In block 102, user Un operates UEe to check in at CyberSafe Security Center 52 and submits a request for a security token. This request includes an extended ID, which optionally includes: a user ID, U-IDn; a user equipment ID, UE-IDe; and / or an SWBb ID, B-IDb, identifying the SWB installed in UEe. U-IDn may include a username, password, and / or data that associates the user with UEe, SWBb, and / or MyCompany, such as the date the user first registered or was registered as a MyCompany user. UE-IDe may include any suitable identifier, such as a MAC (Media Access) address, UUID (Universally Unique Identifier), or IMSI (International Mobile Subscriber Identity), and / or information that associates UEe with user Un, SWBb, and / or MyCompany. B-IDb may include a browser user agent string, any suitable identifier assigned to SWBb by CyberSafe, and / or information that associates SWBb with UEe, Un, and / or MyCompany.

[0033] Note that a given user Un can be associated with more than one UEe and / or more than one SWBb, and the user ID U-IDn can include data identifying the association. Similarly, a given user UEe can be associated with more than one Un and / or more than one SWBb, and a given SWBb can be associated with more than one Un and / or more than one UEe, and the corresponding IDs, UE-IDe and B-IDb, can include data mapping the association. Any combination of one or more of U-IDn, UE-IDe, and / or B-IDb can include the time of day (ToD) of at least one of each previously checked in on CyberSafe.

[0034] Optionally, in block 104, CyberSafe Security Center 52 Authentication Extension ID. The Authentication Extension ID may include multi-factor (optionally three-factor) authentication of the participating user Un and determine the association and / or consistency of ToD between any combination of two or more of U-IDn, UE-IDe, or B-IDb.

[0035] In decision block 106, if the extended ID is not OK, the center proceeds to block 142, denies the requested token, and optionally sends a rejection alert to the CyberSafe center. Alternatively, if the extended ID is OK, the center optionally proceeds to decision block 108 to decide whether to run an integrity test on the SWBb software. The decision to run or not run the integrity test may depend on the MyCompany and / or CyberSafe testing strategy. This strategy may depend on when the CyberSafe center runs the last integrity test on SWBb and / or UEe, the user profile characterizing user Un's browsing behavior and internet usage patterns, and / or the characteristics of the cyberattack landscape. For example, MyCompany may have a strategy where the delay between integrity tests is not less than or greater than certain lower and upper bounds. The decision may depend on whether user Un browses dangerous websites listed in the list of dangerous websites at a frequency greater than a predetermined frequency, or whether the user tends to be lax in updating passwords or patching applications. The cyberattack landscape may include the frequency and / or severity of cyberattacks recently experienced by MyCompany or other enterprises, and / or the types of cyberattacks encountered. Optionally, if the decision in decision block 108 is to skip the integrity test, the center proceeds to block 140 and issues the desired token. If the decision in block 108 is to perform the integrity test, the center can proceed to block 110 and retrieve at least one software integrity test result from a database included in or accessible by the center. The set “SIT”, where It can be used to determine the integrity of SWBb software. An exemplary SIT may include at least one or any combination of the following: = CRT (Query Response Test); = BAT (Behavioral Proof Test); = AV (Antivirus Check); = EDR (Endpoint Detection and Response); = BDS (Binary Digital Signature); = JSON feature detection; .

[0036] In block 112, the CyberSafe center determines the weight vector WIT, which includes each weight This weight Tests were provided For determining the appropriate level of integrity of the SWBb software. In the embodiment, given of It is a function of the following: The type of UEe hardware, such as whether the UEe is a mobile device, tablet, or desktop computer, may limit what type of given software can be executed on the UEe. ; Sensitivity, given The true positive rate; Specificity, given The true negative rate; The nuisance rating provides a metric for testing the inconvenience caused to the user's UEe (User Experience). Past performance in the test; and / or The current cyberattack context indicates the prevalence and severity of different cyberattack types.

[0037] In block 114, the CyberSafe center selects its corresponding weights as greater than the median weights. Integrity test In response to their respective weights Run the test on SWBb software The choice, for example, where the greater weight This indicates a greater correlation.

[0038] In block 116, in response to the selected test For each returned integrity metric, the CyberSafe center determines the value of the integrity quality metric QoI(e,b) of the SWBb software in UEe. In an embodiment, QoI(e,b) is determined by weights corresponding to their respective values. Weighted The average of the provided integrity metrics. Optionally, in decision block 118, CyberSafe center 52 determines whether the QoI value is satisfactory. If the QoI is unsatisfactory, the center proceeds to block 142 and denies the issuance of a token, and optionally sends an alert. On the other hand, if the QoI is satisfactory, the center proceeds to decision block 120 to determine whether to run surrounding software environment tests on UEe.

[0039] Software environment testing is the testing that determines the extent to which the surrounding software in the UEe has been compromised by network corruption or is not adequately protected against network corruption, if any. The decision to perform environment testing on the UEe can be based on many of the same considerations weighted in the decision to perform integrity testing. For example, the decision may depend on MyCompany and / or CyberSafe policies and factors such as the UEe hardware, such as whether the UEe is a mobile phone or a laptop, the time elapsed since the last environment test was run on the UEe, the user Un's browsing behavior patterns, and / or the characteristics of the network attack landscape.

[0040] Optionally, if the decision in decision block 120 is to skip the software environment test, the CyberSafe center can proceed to block 140 and issue the desired token. Alternatively, if the decision is to perform environment testing, the center can optionally proceed to block 122 and retrieve from the database at least one network attack vulnerability feature to be determined as present or absent. The set of ",in . This can include static and / or dynamic vulnerability features. Static vulnerability features are characteristics of code and / or data elements included in the surrounding software of the UEe, which are considered to make the surrounding software and / or digital resources not included in the surrounding software (such as CyberSafe and / or MyCompany resources) vulnerable to cyberattacks. Dynamic vulnerability features are temporary vulnerability features, such as whether the UEe is connected to public Wi-Fi or a dangerous website; these vulnerability features characterize the current use of the UEe. (Example...) It may include at least one or any combination of more than one vulnerability feature, the presence or absence of which can be determined optionally in response to the following query: = AV (Anti-Virus) / EDR (Endpoint Detection and Response) are installed. ; = Firewall installed and enabled ; = Update the OS (operating system) to the latest version ; = Update the application to the latest version ; = Authentication is required to access UEe ; = Dangerous software default ; = Are you using public Wi-Fi? ; = UEe connects to a VPN (Virtual Private Network) ; = Security level of the connected network ; = Security misconfiguration ; Cross-site scripting attack ; = Unstable power supply ; .

[0041] Optionally, in block 124, the CyberSafe center scans the software environment surrounding the UEe to detect each The existence of and determination of the risk vector , Including each Network attack risk estimate ,in Identify a given vulnerability Risk estimates typically depend on the type of vulnerability and the cyberattack landscape. For example, determining the risk estimate for a given public Wi-Fi network might depend on the Wi-Fi's physical location, the current traffic carried by the Wi-Fi at the time the estimate is made, and the recent history of cyberattacks attempted via the Wi-Fi. The risk associated with a patch might be a function of the type of patch requested or installed.

[0042] In block 126, CyberSafe can scan the software surrounding UEe to identify damaged components within the surrounding software. set ,in .

[0043] In block 128, CyberSafe can retrieve user profiles from the CyberSafe and / or MyCompany databases. User profile This can be used to characterize the behavioral features of user Un when interacting with MyCompany and / or non-MyCompany digital resources. In an embodiment, Including key performance indicators for users A set of key performance indicator (KPI) values ,in And including user risk components Value User Network Risk Profile ,in . Values ​​may include at least one or any combination of the following: user keyboard typing pattern; user mouse activity pattern; user response time to digital resource actions, use of the packaged application; use of shared security services; data patterns used by the user during the session, including data typed locally in the SWB; uploaded and downloaded files, filenames; interruptions to the use of surrounding software; and / or hover time at a specific webpage. The values ​​of the components may include risk estimates, optionally from... The component value is derived from any combination of at least one of the following: careless password management; careless access control; reckless clicking on actionable content; lack of sensitivity to phishing bait; or risk assessment of user abuse of MyCompany resources.

[0044] In block 130, CyberSafe processes... , , And / or provide a set of values ​​for security metrics provided by software (optionally referred to as wrapping software or simply wrapping) to determine the quality of protection for protecting SWBb from network damage. The wrapper can include any of various anti-injection and / or anti-exploitation software. As an illustrative example, the wrapper may run additional security checks and install additional security controls, such as EDR (Endpoint Detection and Response), to allow highly privileged users access to MyCompany resources. Additionally, some capabilities that affect the system's vulnerability to cyberattacks may be restricted or disabled by the wrapper if the user is visiting an unknown website or a website with low security reputation and therefore high risk. In embodiments, the neural network is configured to support a combination of... , , and / or The input feature vector of the component features is processed to determine the protection quality.

[0045] Optionally, in block 132, if the CyberSafe center determines that the packet protection is beneficial, the center proceeds to block 140 and issues the requested token. Alternatively, if the packet protection is not beneficial, the center may proceed to block 134 to determine whether to modify the packet protection to improve protection. If the center decides not to modify it, the center may proceed to block 142, deny the token, and issue an alert. Alternatively, if the decision is to modify the packet, the center proceeds to block 136, modifies the packet, and optionally proceeds to decision block 138 to determine whether the modification has resulted in a sufficient improvement in network protection. If the improvement is insufficient, the CyberSafe center proceeds to block 142 and denies the token.

[0046] The process illustrated in flowchart 100 assumes in block 102 that users Un and UEe may have been "registered" by CyberSafe as MyCompany users with extended IDs, which include at least one ID or any combination of more than one ID selected from U-ID, UE-ID and / or B-ID.

[0047] Flowchart 150 illustrates a process according to an embodiment of this disclosure, through which CyberSafe can operate to register unregistered user Un and unregistered user equipment UEe, and initiate them as corresponding memberships of MyCompany user and MyCompany user equipment, which are associated with data that can be used to provide an extended ID and request a security token for accessing MyCompany resources. It is assumed that user Un has a user management U-Mng 52.1 submitted to CyberSafe center 52 ( Figure 1 The identifier data, such as the user ID (U-IDn) and user password, is stored in the Un data record of the U-Mng database. It is also assumed that the UEe has submitted user equipment management data to the center 52, U-Mng 52.1 (…). Figure 1 And the identification data, such as the User Equipment ID (UE-IDe), is stored in the UEe data record in the UE-Mng database.

[0048] In block 151, user Un bootstraps UEe, assuming UEe has an instance of SWBb (SWB 64) installed. Figure 1 CISE, which includes the extended EXTb (an instance of EXT 64.1), also has at least one watchdog installed: Wdog72, Wdogb, and TPM 71 (see...). Figure 1 (The icon represents the CISE feature being installed). During bootstrapping, in block 153, the watchdog Wdogb optionally operates to review the integrity and proper operation of SWBb and EXTb. In an embodiment, SWBb may be configured to operate to check the integrity and operation of Wdogb and EXTb, and EXTb may be configured to operate to perform integrity and operation checks on the watchdog Wdogb and SWBb. For example, integrity and operation tests may include any one or any combination of more than one integrity test discussed relative to flowchart 100. In an embodiment, if the integrity check fails, EXTb may abandon registration and issue an alert to the user for remedial action to correct the failure. In decision block 155, EXTb optionally determines whether Un and / or UEe are registered with CyberSafe, and if so, abandons the registration process.

[0049] On the other hand, if the extended EXTb determines that Un and / or UEe are not registered, EXTb may optionally proceed to block 157 and generate a registration request, as indicated in block 159. EXTb may optionally transmit the registration request to TPM via propagation through SWBb and Wdogb. In response to receiving the registration request, in block 161, TPM generates a private / public key pair and, as indicated in block 163, optionally propagates the public key of the key pair to EXTb via Wdogb and SWBb.

[0050] The generation of the registration request and the propagation of the public key to EXTb can be untransparent to the user, and in block 165, the user attempts to log in to CyberSafe by submitting user credentials (including user ID, U-IDn, UE-IDe, and user password) to CyberSafe center 52, where U-Mng 52.1 is managed by the user in the center. Figure 1 The U-Mng receives these credentials for processing. In decision block 167, U-Mng optionally authenticates the credentials based on multi-factor authentication (MFA). If authentication fails, EXTb abandons registration. On the other hand, if authentication succeeds, in block 169, U-Mng generates and provides a user token, optionally User-JWTn (JSON Token), to EXTb for user Un. Optionally, in block 171, EXTb transmits the registration request along with User-JWTn and the public key generated by TPM to the UE management, UE-Mng 52.2 ( Figure 1 ).

[0051] In decision block 173, UE-Mng checks the UE-Mng database to determine if it has a UEe data record, and whether the data in the UEe data record and the data payload in User-JWTn allow UEe to register as MyCompany UE for user Un. If registration is not allowed, registration is abandoned. Alternatively, if registration is allowed, in block 175, UE-Mng stores the public key and any relevant data from User-JWTn in the UEe data record, and in block 177, determines that Un and UEe's registration is successful and ends the registration process.

[0052] Figure 3 E illustrates a diagram according to an embodiment of the present disclosure showing a registered user Un attempting to log in to the MyCompanyCyberSafe system ( Figure 1 And obtain flowchart 180 for accessing MyCompany resources. In block 181, user Un attempts to log in to MyCompany CyberSafe using UEe, and in block 182, U-Mng 52.1 ( Figure 1The UE-Mng authenticates the login request, and if authentication fails, the login is abandoned and the user is notified of the failure. Alternatively, if the login is successful, the UE-Mng provides the EXTb with a time-limited access token, optionally, for example, User-JWTn. In subsequent block 183, the EXTb operates to transmit the login request, including User-JWTn, to CyberSafe Center 52 UE-Mng 52.2, which checks to authenticate the request. If the request does not meet the authentication requirements, for example, if the time limit for User-JWTn has expired, CyberSafe rejects the login in decision block 184 and prevents the user from accessing MyCompany resources. Alternatively, if the request is successful, optionally in block 185, the UE-Mng 52.2 transmits an inquiry to the EXTb, and in block 186, the EXTb optionally transmits an inquiry to the TPM via SWBb and Wdogb. In block 187, the TPM uses the private key of the key pair to encrypt the query, and in block 188, the TPM optionally transmits the encrypted query to UE-Mng via Wdogb, SWBb, and EXTb.

[0053] In block 189, UE-Mng is used in Figure 2D In block 171 of flowchart 150 shown, the stored public key received decrypts the encrypted query and determines whether the decrypted query matches the query sent by UE-Mng to TPM in block 185. In decision block 190, if the sent and decrypted queries do not match, login fails and is rejected. On the other hand, if the queries match, in block 191, UE-Mng generates an Un-UEe-SWBb token, which includes a data payload based on the data and metadata included in the User-JWTn payload and data from UEe data records in the UE-Mng database, and sends the token to EXTb.

[0054] In block 192, EXTb uses the Un-UEe-SWBb token to access Pol-Eng 52.3 ( Figure 1EXTb requests a signed policy from Pol-Eng, which defines policy items related to enabling Un, UEe, and SWBb to interact with MyCompany and MyCompany resources. In block 193, EXTb receives the policy and stores the policy items from the signed policy in at least one or any combination of the claims to the Un-UEe-SWBb token, data records in U-Mng, and / or data records in UE-Mng. In block 194, the procedure illustrated in flowchart 100 is successfully completed, optionally logging into MyCompany CyberSafe after satisfying integrity and software checks, and the Un-UEe-SWBb token can be used to access MyCompany resources.

[0055] In an embodiment, EXTb is configured to repeatedly initiate a review process for the identity of Un, UEe, and / or SWBb, and the integrity of the software included in UEe and / or SWBb, following a successful login as indicated in block 194. Optionally, the review process includes an inquiry response procedure using stored public and private keys, and optionally performs integrity and / or software checks as described with respect to flowchart 100. In an embodiment, the execution of the review process may be periodic, with fixed time intervals, such as every 15 minutes, or in response to an assessment of the security risks of the UE or SWB software or a user profile, as discussed above with respect to flowchart 100. The execution rate of the review process can be determined in other ways, depending on its characteristics. It can be time-varying, determined by a predetermined function, or random, for example, triggered by the detection of software anomalies, abnormal user behavior, and / or events in the environment in which the user is operating.

[0056] In an embodiment, MyCompany and the MyCompany browser SWBb can be configured to implement the feature of an algorithm (optionally referred to as "dynamic password filtering") that is used to identify and review new or modified passwords, or new instances of the same password, generally referred to as new passwords, before MyCompany accepts them for use by user Un. Figure 3 A flowchart 500 illustrating an embodiment of dynamic password filtering is shown. Specific actions or features implemented and / or supported by CyberSafe hardware and / or software components may be referred to as being implemented or performed by dynamic password filtering or method 500.

[0057] According to embodiments of this disclosure, in block 501, as discussed above, the browser SWBb is configured (if not already configured) to provide enhanced user communication visibility by modifying browser code. In block 503, MyCompany determines the set of cipher sets. These cipher sets are beneficial for associating ciphers with different security constraints, and for protecting ciphers used in different contexts. For example, It can include the MyCompany IDP cipher set. This is used for: users based solely on their membership as MyCompany users; each of several different MyCompany departments; each of several different MyCompany User Security License (CLR) levels; each of several different MyCompany Resource Confidentiality (CON) levels characterizing resources to be accessed using a password belonging to that group; each of several different network attack vulnerability assessments for MyCompany User Equipment (UE) software configuration; MyCompany non-SSO (Single Sign-In) passwords; shared passwords; and / or user passwords not used for interacting with MyCompany.

[0058] Optionally, in block 505, MyCompany is for each password group Determine the minimum value of the metric that may require the ciphers belonging to this cipher group to be displayed. And optionally, the maximum number of accounts that can reuse passwords. .

[0059] Minimum value of the cipher set It can be determined as a constant or a variable function based on any one or more of various relevant cybersecurity features, such as at least one metadata feature characterizing a cryptographic group and / or at least one feature of a user profile that classifies a new cipher as belonging to the cryptographic group. For example, at least one metadata feature can be at least one or more of the following common to ciphers belonging to the cryptographic group: MyCompany department, resource confidentiality, CON, level, and / or user license level (CLR). For example, at least one security-related feature of a user profile can be a user profile (such as those discussed above). The password group can be any combination of at least one of the following characteristics: user role, user CLR, and / or the frequency with which the user is expected to use the new password. Note that network security-related metadata characteristics characterizing the password group can also be network security-related user profile characteristics. For example, a password group can be defined for a CLR between a predetermined lower and upper bound. Given a new password for the MyCompany user... It can be a function of the CLR limit and the CLR level value between the limit assigned to the user, where for different values ​​of the assigned CLR level, They have different values.

[0060] Similarly, the maximum reuse of a cipher set can be determined based on at least one or more of the relevant metadata features and / or user profile features. Determine whether it is a constant or a variable function. For ciphers that do not allow reuse, assume... The value of is zero.

[0061] In this embodiment, according to the embodiment, in block 507, the set of cipher sets, their corresponding associated metadata, and and Constants or variable functions can be stored in CyberSafe Center 52, MyCompany SWBb, and / or CISE 62, which are suitable for supporting the review of new passwords generated using SWBb. Figure 1 In the memory of ).

[0062] When a MyCompany user using SWBb constructs a new password, in block 509, center 52 and / or SWBb uses browser visibility to view and intercept the new password in order to review it before accepting it for use. Optionally, the password is intercepted for review before the browser transmits the new password to MyCompany for acceptance. In an embodiment, the password is intercepted for review during the construction of the password. Optionally, in block 511, center 52 and / or SWBb categorizes the password to determine the password group to which the new password belongs. According to blocks 513-519, MyCompany Center 52 and / or SWBb, individually or collaboratively, review the password to determine whether the new password meets MyCompany policy standards.

[0063] In decision block 513, the new cipher is reviewed to determine whether it has already been, or is expected to be, rejected upon acceptance due to its reuse exceeding that of the established ciphersets. Related If a password is determined to be overused or expected to be overused, dynamic password filtering proceeds to block 521 to reject the password and alert the user to provide an alternative new password. Alternatively, if a new password is determined not to be overused or expected not to be overused, dynamic password filtering proceeds to decision block 515 to determine if the new password has been leaked. Any of various databases listing passwords believed to have been leaked can be searched to determine if the new password has been leaked. In an embodiment, if a metric of the distance between the new password and another password known to be used or already used (optionally referred to as the edit distance) is less than a predetermined distance, the new password can be considered leaked. The edit distance can be determined based on any of various edit distances, such as, for example, Levenshtein distance, Hamming distance, and / or cosine distance. If it is determined in decision block 515 that the new password has been leaked, dynamic password filtering proceeds to block 521 to reject the password and alert the user to reject it.

[0064] On the other hand, if it is determined that the new password has not been leaked, dynamic password filtering can proceed to decision block 517 to determine whether the new password passes the test if its password strength is greater than or equal to [a certain threshold]. Perform characterization. If the new password strength is less than... If the password strength is determined to be greater than or equal to the specified value, then dynamic password filtering continues to block 521 to reject the password and send an alert to the user. In block 519, the dynamic password filter accepts the new password and notifies the user of acceptance.

[0065] Figure 4 A flowchart 600 illustrating a scenario according to an embodiment of the present disclosure is shown, in which a CyberSafe method (optionally referred to as a data stream scrambler or simply a scrambler) operates to obfuscate a data stream generated by a user-operated human-machine interface (HCI), such as a real or virtual UE keyboard or mouse. In the discussion, specific actions or features implemented and / or supported by CyberSafe hardware and / or software elements may be referred to as being implemented or performed by CyberSafe, the scrambler, or the method 600. For ease of presentation, it is assumed that the HCI is a real keyboard.

[0066] In block 601, according to an embodiment, MyCompany user Un logs into MyCompany and is able to access and interact with MyCompany resources using the MyCompany browser SWBb of UEe. In block 603, optionally, SWBb determines whether the interaction involves or is likely to involve the user engaging with confidentiality-sensitive CON material (also known as confidentiality-sensitive CON features). Confidentiality-sensitive material includes any material that MyCompany considers advantageously required to be restricted from exposure and / or distribution to MyCompany users based on the user security license (CLR) level. For example, CON material may include user passwords, proprietary information such as trade secrets, intellectual property, and / or business strategies. For example, the CON and CLR levels may be determined in response to considerations by MyCompany personnel or by using artificial intelligence (AI), such as machine learning algorithms, such as decision trees or clustering algorithms, or convolutional neural networks (CNNs), educated through supervised and / or unsupervised learning.

[0067] For ease of presentation, for example, it is assumed that CON and CLR levels have values ​​spanning the same numerical range. Further, it is assumed that MyCompany materials with higher confidentiality sensitivity are assigned a higher CON level than materials with lower confidentiality sensitivity. And it is assumed that users assigned a higher CLR level can access materials with a CON level higher than the CON level accessible to users assigned a lower CLR level.

[0068] In embodiments, it can be determined whether a user is engaging with or tends to engage with a CON material based on the material's CON level and / or the user's CLR level, generally referred to as "engaging". For example, if the material has a CON level greater than a predetermined level, it can be determined that the user is engaging with the CON material. If the user has a CLR level greater than a predetermined upper threshold threshold or less than a predetermined lower threshold threshold threshold, it can be determined that the user is engaging with the CON material. Alternatively or additionally, it can be determined that the user is engaging with the CON material based on the difference between the material's CON level and the user's CLR level. For example, if the difference between the user's CLR level and the CON level of the material that the user is allowed to access by the MyCompany policy is less than a predetermined difference, it can be determined that the user is engaging with the CON material. If the user's interaction with MyCompany resources is subject to or tends to be subject to the process flow 100 ( Figure 2A-2CDamage from any of the network risks discussed above can determine that a user is engaging with CON material. In an embodiment, artificial intelligence (AI) can be used to process a feature vector that includes components as choices of CON, CLR, and risk factors mentioned above, to determine when and how to determine that a user is engaging with CON material.

[0069] In decision block 605, if it is determined that the user will not engage or is not inclined to engage the MyCompany CON material, CyberSafe optionally proceeds to block 625 and abandons scrambling. Alternatively, if it is determined that the user intends to engage the CON material, CyberSafe optionally continues to block 607 to invoke the scrambler. In block 609, the scrambler sets a low-level hook for the HCI, which, as indicated above, is assumed to be the actual keyboard of the UEe. Optionally, the low-level hook is set to intercept key scan codes generated by the keyboard microprocessor in response to key presses, or virtual key codes including key codes and key attributes generated by the keyboard driver of the UEe operating system in response to scan codes. Optionally, in block 611, the scrambler determines the refresh rate of the keyboard hooks to maintain the priority of the hooks relative to possible subsequent keyboard hooks that may be set by a network intruder. The refresh rate may depend on the CON and / or CLR levels, and / or regarding flowchart 100 ( Figure 2A-2C Any risk factor discussed.

[0070] In block 613, the scrambler can establish HCI jumps. An HCI jump includes alerting the user to switch from a first HCI to a second HCI where the user can interact with MyCompany resources, optionally repeatedly, optionally periodically, or in response to random prompts. The HCI can be a real, bare-metal, or virtual HCI. For example, the scrambler can prompt the user to switch from typing a new password on a hypothetical real keyboard using the UE (e.g., a laptop or desktop computer) to a smartphone virtual keyboard, or to switch between two or more virtual keyboards presented on a laptop or desktop computer screen, or to switch between multiple screens presented on different UEs. The decision to establish interface jumps and determine the jump pattern that defines the jump frequency and jump sequence between different HCIs can be based on the same considerations as the decision to invoke the scrambler and / or set the hook refresh rate.

[0071] In block 615, the user presses a key on the physical keyboard, and the scrambler captures the key press event via an operation hook, optionally as a virtual key code, including a key code and key attributes. In block 617, optionally, the virtual code is scrambled. The scrambled virtual code includes changing the key code and / or key attributes to provide a virtual code representing a change different from the actual key press. In block 619, if the scrambler did not change the original virtual code in block 617, the scrambler may salt or skip the changed or original, unchanged virtual code. Salting the changed or unchanged virtual code includes adding at least one additional random number virtual code to the virtual code, such that the virtual code is transformed into a plurality of virtual codes, at least one of which is a random number code. Skipping the changed or unchanged virtual code means isolating the code to the extent possible, making it appear as if the key press that generated the code did not occur or was unknown. For a virtual signal sequence corresponding to a key sequence, skipped keys can be replaced by zero or empty virtual code signals, or by the absence of a virtual code signal between two transmitted virtual code signals. The altered, salted, or skipped virtual code that replaces the original virtual code can be referred to as scrambled code.

[0072] In an embodiment, optionally, in block 621, the scrambler blocks the propagation of the original, unchanged virtual code to the destination application of the original virtual code and transmits the scrambled virtual code to the intended fate application for processing. This blocking can be implemented via software or proprietary hardware pre-installed in the activated keyboard. In the subsequent block 623, the destination application descrambles the scrambled virtual code to recover the original virtual code and thereby determine the corresponding original key. In an embodiment, the destination application uses a descrambling key, for example, in the form of a lookup table (LUT), to descramble the scrambled virtual code. In an embodiment, the descrambling key is provided by CyberSafe and / or the scrambler before invoking the scrambler. In block 623, the destination application uses the descrambling key to descramble the scrambled virtual code and recover the original virtual code scrambled from the scrambled virtual code, thereby determining the corresponding original key.

[0073] It should be noted that although the above description assumes that HCI is a keyboard, the practice of embodiments of this disclosure is not limited to keyboards. For example, a scrambler according to embodiments can operate similarly as described above to scramble and obfuscate communications transmitted to a destination application via a mouse or gesture recognition system.

[0074] In an embodiment, CyberSafe leverages the enhanced visibility provided by MyCompany SWB for monitoring user communications and web browsing to obtain data related to profiling MyCompany users, MyCompany resources, and entities with which users communicate and interact (such as websites, smartphones, and the Internet of Things (IoT)). In an embodiment, the profiling data is used to enhance CyberSafe's sensitivity to detect the risk of network damage to MyCompany resources and / or leakage of MyCompany data, optionally arising from or as a result of phishing attacks that may occur due to user web browsing activity. In an embodiment, the increased sensitivity is used to optionally provide real-time, dynamic protection against phishing intrusions during user website browsing activity.

[0075] In this embodiment, the depiction data may be represented by a multi-plane graph, which may optionally include a user plane with a MyCompany user graph, a resource plane with a MyCompany resource graph, and a conversational plane with a graph of conversational entities with which MyCompany users can communicate and interact. This graph can be, or be used as, an attack surface. Conversational entities may include, for example, computers, mobile devices such as smartphones, wearable devices such as smartwatches, routers, Internet of Things (IoT) devices, security cameras, medical devices, and websites. For ease of presentation, conversational entities are assumed to be websites, and the conversational plane is referred to as the website plane.

[0076] Figure 5A Features of a multi-plane diagram 450 are schematically shown and illustrated, the multi-plane diagram 450 including a user plane 460 with a user diagram 461, a resource plane 470 with a resource diagram 471, and a website plane with a website diagram 481.

[0077] User graph 461 includes user nodes 462 and user edges 464. User nodes represent different MyCompany users Un. User edges represent interactions between users. Each user node is associated with a set of features considered to be included in a user feature vector, which identifies and characterizes the user Un represented by that node. The user feature vector of a given user Un may be and / or wholly or partially included as described above regarding flowchart 100 ( Figure 2A-2C The user profiles discussed And optional additional user representation features, such as those related to flowchart 500 ( Figure 3 The features discussed herein. User feature vectors may also include features that identify and characterize the specific UEe and SWBb that user Un uses to browse and / or communicate.

[0078] For example, features that identify a user's feature vector may include features that identify about The characteristics discussed may include user metadata, which, in addition to user ID (U-IDn) for user Un, includes the MyCompany department to which a given user Un belongs, various metrics of the user's position within MyCompany (such as title and role), and / or the user's permission level (CLR), which determines which MyCompany resources the user is permitted to access. Characteristic representations may include features indicating a user's social interactions with other MyCompany users, such as influence scores, network concentration, and / or gatekeeper indexes. (See above reference...) The characterization features discussed may include key user performance indicators. The set of values And including user network risk components Value User Network Risk Profile .

[0079] User edge 464 can not only indicate and identify which other users a given user Un interacts with, but also indicate and identify the type and intensity of the interaction. For example, user edge 464 connecting a given user Un to another user can be symmetric or directed, indicating symmetric or unidirectional interaction between Un and the other user, respectively. Additionally or alternatively, edges can be used to characterize the frequency and / or type of interaction. One type of interaction can be, for example, social interaction, or an exchange of verbal or email messages involving one or more of a specific class of data (such as development data, financial data, marketing data, and / or management data). Note that, although in Figure 5A A pair of nodes 462 is shown as being connected by only one edge, but a pair of nodes can be connected by multiple edges, each of which represents a relation distinct from the relations represented by the other edges. The data that identifies and characterizes a particular user edge can be considered as features included in the user edge data record (optionally referred to as the user edge feature vector) associated with the user edge.

[0080] Resource graph 470 includes resource nodes 472 and resource edges 474. Resource nodes represent resources. set Different MyCompany resources are represented by resource edges 474, and each resource node is associated with a set of features considered as components of a resource feature vector, which contains data identifying the resource represented by the node and data characterizing that resource. As in the case of user nodes and edges, a pair of resources can be connected by more than one resource edge.

[0081] Resource identification data may include metadata such as resource ID, the date the resource was created, the last update date, and / or the resource author. Characterization data may include a type of data communication medium, such as text, images, audio, and / or mixed media data included in the resource, and subject categories, such as software, financial, marketing, and / or human resources (HR) materials included in the resource. Resource characterization data may also include MyCompany user access to the resource, the rate at which resources or data are downloaded from the resource, a list of which MyCompany users accessed the resource, the confidentiality (CON) level of the materials included in the resource, and / or the level of protection the resource enjoys against network tampering.

[0082] Resource edges 474 between resource nodes 472 can indicate symmetric or asymmetric relationships and, for example, can represent commonalities in metadata, such as content, author, and / or reliability metrics shared by the nodes, and / or the number of times a user accesses a resource represented by one node in a pair of nodes, resulting in the user accessing a resource represented by the other node in the pair. Features that include data identifying and / or characterizing a particular resource edge can be considered as features included in the resource edge feature vector.

[0083] Website graph 480 includes website node 482 and website edge 484. Website node 482 represents the website. set In this context, different websites are represented by website edges (484), indicating the relationships between them. Each website node is associated with a set of features that identify a specific website. It characterizes the website and its interactions with other websites and MyCompany users. These features are considered components of the website's feature vector.

[0084] Website characterization features may include website cyber risk metrics that represent the cyber risks MyCompany may be exposed to by browsing the website. set Website cyber risk metrics may include website reputation, a list of any of the various "cyber-dangerous" website blacklists, such as phishing and malware blacklists, and / or a list of websites known to have distributed malware. Risk metrics may also include metrics for excessive pop-ups and / or added, excessive or unsolicited redirects, suspicious links, unusual URLs, and / or surprising and / or poor-quality design features. Website edges can represent the frequency of redirects between websites represented by nodes and / or between nodes, the commonality of shared topics among websites, the frequency of data transfers between nodes, and / or cyber risks shared or potentially generated by two websites.

[0085] The feature data (optionally referred to as graph data) associated with and represented by the nodes and edges of layers 460, 470 and 480 of the multiplanar graph 450 can be stored in any suitable memory that provides access to the graph data to support the operation of CyberSafe, MyCompany, MyCompany Central and / or Browser SWB in protecting MyCompany resources from cyber risks.

[0086] According to an embodiment, when a user optionally accesses a website using the browser SWBb, the graph data is used to protect the user Un and MyCompany from phishing risks.

[0087] For example, according to an embodiment, when a given user Un logs into MyCompany using the MyCompany browser SWBb to perform user activities, the browser can determine and monitor user actions performed by the given user using the browser. In this embodiment, while monitoring when the given user communicates directly or indirectly with one or more other users represented by node 462, one or more company resources represented by node 472, and / or one or more websites represented by node 482, the browser generates an activity group. This activity group lists the given user Un and the given users, other users, resources, and websites with whom they interact directly or indirectly, generally referred to as interaction entities.

[0088] An activity group can be represented by nodes representing interacting entities, planar edges connecting nodes in the same plane of the multi-planar graph 450, and plane edges (represented by dashed lines) connecting nodes from different planes. If the corresponding nodes of two interacting entities in the multi-planar graph 450 are connected by an edge, they are considered to interact directly. If the corresponding representative nodes of two interacting entities are connected by multiple edges, and none of these edges connects the two nodes directly, the two interacting entities are considered to interact indirectly. An activity group represented by nodes and edges in the multi-planar graph 450 can be called an activity map.

[0089] Figure 5B An exemplary schematic activity map (AM-1) is illustrated. This activity map (AM-1) is generated by the browser SWBb in response to monitoring the activity of user Un, represented by node 4621 in the multi-plane graph 450, and detecting that the user has visited and directly interacted with the MyCompany resource, represented by resource node 4721 in the resource plane 470, and the website, represented by website node 4821 in the website plane 480. Figure 5BIn the diagram, the interaction between user 4621 and resource 4721 is represented by plane edges 462-721 in the multi-layer graph 450, and the interaction between user 4621 and website 4821 is represented by plane edges 462-821. For ease of reference, nodes representing interactive entities in the activity group represented by the activity map AM-1 are shown, and these nodes are patterned with bar patterns.

[0090] According to an embodiment, for the purpose of detecting potential risks of phishing attacks and data leaks, SWBb can be configured to include users indicated by data in the corresponding user feature vectors and user edge feature vectors of their user graph 464 in the activity group and corresponding activity map generated for user 4621, to interact directly and / or forcefully with user 4621. Therefore, as by Figure 5B As indicated by the patterned nodes in the site plane 480, AM-1 includes user nodes 4622-4626. Similarly, the browser SWBb can be configured to include, in addition to the site 4821 with which user 4621 directly interacts, a selection of sites in the activity map that are directly and / or indirectly strongly connected to a given site, as indicated by graph data in the site feature vectors of site edges. Therefore, as indicated by the patterned nodes in the site plane 480, AM-1 includes site nodes 4822-4826.

[0091] According to an embodiment, in order to determine the risk of phishing data loss of user 4621's browsing activity modeled by the activity map AM-1, the browser SWBb generates an activity map feature vector for the activity map. Optionally, the activity map feature vector includes concatenations of features from feature vectors associated with user, resource, website, and relationship represented by nodes and edges included in the activity map AM-1.

[0092] The activity map feature vector may also include time-related dynamic interaction features of the interactive entities represented in the activity map AM-1. The dynamic interaction features of an activity group are based on data generated by the interactive entities in the activity group during the group's activity period, characterizing the entity's activity. In response to detecting anomalies in the behavior or configuration of interactive entities in an activity group monitored by the SWB, MyCompany SWB and / or CyberSafe Center can generate dynamic interaction features to be included in the activity map feature vector of the activity group. For example, SWB and / or CyberSafe can be configured to perform real-time image processing on web pages presented to users in the activity group to identify network risk anomalies in the images and generate dynamic interaction features in response to such anomalies. In response to detecting changes in variables characterizing interactive entities exceeding a predetermined upper limit for such changes, the browser and / or center can generate dynamic interaction features. For example, the browser and / or center can generate dynamic interaction features responsible for reckless clicks on actionable content, unusual hover times at specific web pages, and / or displaying excessive pop-ups or prompts to download software, or websites that cause excessive slowdown of the SWB.

[0093] In an embodiment, the activity map feature vector is processed by artificial intelligence (AI) (optionally in real time), which is configured through supervised and / or unsupervised training to provide the probability that interactive entities of an activity group, modeled by an activity map (such as AM-1), will cause damage due to phishing. In an embodiment, the AI ​​includes a deep neural network. Optionally, the DNN includes a graph convolutional neural network (GNN). Optionally, the GNN includes at least one or any combination of more than one of graph convolutional neural networks (GCN), graph attention networks (GAT), and / or graph recurrent neural networks (GRNN). Optionally, the CyberSafe center and / or SWB are configured to generate a probabilistic heatmap in response to the probabilities provided by the AI ​​for the activity group, indicating the contribution made by the interactive entities of the activity group to the probability of network damage to MyCompany due to phishing.

[0094] In embodiments, CyberSafe can perform (optionally in real time) actions to prevent or mitigate network damage indicated by AI probabilities. For example, for Figure 5B As shown in the AM-1 instance, CyberSafe can shut down user 4621's browsing session, prevent user from communicating with other users in the activity group, prevent user 4621 from uploading or downloading materials to or from one or more of websites 4821-4822 and / or resources 4721, and / or reconfigure materials on web pages generated by SWBb.

[0095] In an embodiment, to mitigate or prevent network damage in real time, CyberSafe and / or SWBb can be configured to display a heat map generated for AM-1 to user 4621, visually alerting the user to the probability and responsibility for potential network damage determined by AI. The displayed heat map can also be configured to indicate which interaction entities and / or (one or more) relationships modeled in the probabilistic heat map of the activity group can be optimally handled to prevent damage. Optionally, CyberSafe and / or SWBb provides the user with a selection of proposed corrective actions to prevent damage. Proposed corrective actions may include any combination of at least one or more of the following: isolating interaction entities, restricting information transfer to and from specific entities, and reconfiguring relationships between entities and / or interaction entities. Corrective actions and optimally handled entities and relationships are optionally presented in a table attached to the heat map.

[0096] In an embodiment, in response to the probabilities provided by the processed activity map feature vectors, CyberSafe can log graph data to the CyberSafe database. For example, if the probability heatmap indicates that a particular website 4821–4824 is responsible for a high probability of risk, CyberSafe may downgrade that website's reputation. If user 4621's activity is indicated as being excessively responsible for the probability of network risk, MyCompany may change permissions or lower the CLR level granted to that user.

[0097] In this embodiment, the accumulated graph data and heatmaps can be used to generate materials to educate users, make them aware of phishing attacks, and test their ability to avoid such attacks. For example, the materials could include virtual or real-world phishing attack scenarios, each accompanied by a choice of possible actions from which the user can select the optimal action to prevent damage caused by the attack scenario. A user's proficiency in avoiding phishing attacks can be determined by measuring the frequency with which they choose the optimal action. By practicing responding to these scenarios, users' proficiency in dealing with phishing attacks can be improved.

[0098] It should be noted that although the above description relates to cyber risks arising from phishing, the practice of embodiments of this disclosure is not limited to phishing. The methods according to embodiments of this disclosure, with appropriate modifications, are applicable to identifying and preventing various cyber risks, and can be used, for example, to identify and monitor cyber risks arising from malicious scripts, Trojans, and injections of insider threats.

[0099] According to embodiments of this disclosure, CyberSafe, MyCompany, and / or SWBb can, through their own operation or cooperation, mark MyCompany resources with a confidentiality (CON) level that can be used to control access to and movement of the resources. In embodiments, marking includes generating a CON digital signature based on the resource CON fingerprint and / or CON quantile vector according to a resource confidentiality marking process, optionally as follows: Figure 6A As described in flowchart 650 shown. This process can be referred to as the RECON process or simply RECON. Actions performed by any software and / or hardware components of CyberSafe, MyCompany, and / or SWBb through the CON annotation process can be referred to as being performed by RECON. Figure 6B The flowchart 670 shown illustrates the use of the CON digital signature according to an embodiment.

[0100] In block 651, RECON receives a given resource for labeling, and in block 652, scans the resource for potential network risk material. In decision block 653, if the resource does not contain risk material, RECON can proceed to block 654.

[0101] In block 654, RECON scans a given resource to identify confidentiality-sensitive features (CON features) in the resource and other resources accessible via hyperlinks included in the given resource. Modern digital resources are often complex resources that may include text, images, audio, and / or video data themselves and / or via hyperlinks to other resources. References to CON features are considered general references to CON features, which may be based on and / or include text, images, audio, and / or video data. The CON features of a given resource may reside in the given resource and / or in hyperlinked resources accessed via hyperlinks from the given resource.

[0102] Optionally, in block 655, RECON assigns a CON level to each identified CON feature, and in block 656, determines the feature CON metadata grouping. According to an embodiment, the metadata grouping includes a timestamp at the time the data grouping is assembled, the CON level of each CON feature identified in a given resource, the location of the CON feature within the resource, and the class of the data in the resource and its associated data. In block 657, RECON assembles a resource CON fingerprint, which includes all or selected CON metadata groups. The CON fingerprint can be configured as a feature vector that includes linked (optionally in the order they appear in the resource) metadata groups.

[0103] Optionally, in block 658, RECON generates a CON quantile vector for the resource, the CON quantile vector including the CON quantile values ​​of the set of quantiles of the distribution of CON values ​​assigned to the CON features identified in the resource. In block 659, RECON generates a digital signature based on the resource's CON fingerprint and the CON quantile vector. In block 660, RECON embeds or attaches the digital signature to the resource.

[0104] If decision block 653 determines that a given resource contains network risk material, RECON optionally proceeds to block 662 and operates to remove the material. In block 664, if RECON successfully removes the material, RECON returns to block 654 to process the resource, and in block 660, provides the resource with a CON fingerprint and allows the MyCompany user to use the resource. On the other hand, if removal is unsuccessful, RECON proceeds to block 666, disallows the use of the resource, and generates an alert notifying of this disallowance.

[0105] exist Figure 6B In block 671 of flowchart 670 shown, user Un using MyCompany SWBb attempts to interact with an optional MyCompany resource, where interaction with the resource includes any user action that puts the resource into motion, such as downloading, uploading, modifying, and / or transferring it to another user. In decision block 672, the browser SWBb operates to examine the resource and determine whether the resource is a confidentiality sensitive (CON) resource.

[0106] If the resource is a CON resource in decision block 672, RECON proceeds to block 673 to decrypt the digital signature associated with the resource, and optionally in block 674, checks the decrypted CON quantile vector, also known as the CON Q vector or simply the Q vector, against the expected Q vector for the resource. In decision block 675, if the decrypted Q vector matches the expected Q vector, RECON may check the user permission level (CLR) in block 676 to determine if the user is authorized to access the resource. Checking the user CLR may optionally include determining whether the CLR is greater than or equal to a threshold quantile value in the Q vector. For example, checking the CLR may include checking the CLR against a threshold CON quantile value, for which... Figure 6A 80% of the CON level allocated in block 655 is less than this threshold quantile value.

[0107] Optionally, in decision block 677, if the CLR level is not equal to or greater than the threshold quantile value, RECON can proceed to block 683, and the user's interaction with the resource is denied, and an alert is sent to the user and / or MyCompany to notify of the denial. On the other hand, if the CLR is equal to or greater than the threshold quantile value in decision block 677, RECON can proceed to block 678, and the CON fingerprint decrypted based on the signature is compared (…). Figure 6A The comparison (blocks 654-657) determines whether it matches the expected CON fingerprint. The comparison optionally includes comparing values ​​included in the CON metadata group determined for the CON features included in the decrypted fingerprint to determine whether these values ​​match values ​​included in the corresponding CON metadata group in the expected CON fingerprint. In decision block 679, if the comparison is successful and the decrypted and expected fingerprints match, RECON optionally proceeds to block 680 to allow the user to interact with the resource.

[0108] In decision blocks 672, 675, and 679, if the requirements in the block are not met, RECON may optionally continue to block 681, according to... Figure 6A The annotation procedure 650 shown processes the resource to determine whether to provide a CON digital signature for the resource. In decision block 682, if the annotation procedure fails and the resource is not provided with a digital signature, RECON proceeds to block 683 to deny the user's interaction with the resource. On the other hand, if the annotation is successful, RECON returns to block 673 to determine whether to grant the user permission to interact with the resource.

[0109] In the description and claims of this application, the verbs “comprising,” “including,” and “having,” and each of their verbal variations, are used to indicate one or more objects of the verb, and are not necessarily a complete list of components, elements, or parts of one or more subjects of the verb.

[0110] The description of embodiments of the invention in this application is provided by way of example and is not intended to limit the scope of the invention. The described embodiments include various features, and not all features are claimed in all embodiments of the invention. Some embodiments utilize only some of the features or possible combinations of these features. Variations of the described embodiments of the invention, as well as embodiments of the invention including different combinations of the features indicated in the described embodiments, will occur to those skilled in the art. The scope of the invention is defined only by the claims.

Claims

1. A method for authenticating the identity of a user equipment (UE), the user equipment having a browser that operates to browse and communicate with other entities, the method comprising: The UE is provided with a Trusted Platform Module (TPM), which operates to generate a public / private key pair; The browser is configured to generate a request for registration to access protected resources controlled by an entity that enables UEs registered with the entity to access the resources; In response to the request, the TPM is operated to generate a public / private key pair; Provide the entity with the UE identity, public key, and registration request to register the UE with the entity; as well as The UE's identity is authenticated to the entity using a public key and a private key.

2. The method of claim 1, wherein configuring the browser to generate the registration request includes providing the browser with an extension configured to generate the registration request.

3. The method of claim 2, further comprising configuring and using the extension to provide the entity with the UE identity, the public key, and the registration request to register the UE with the entity.

4. The method of claim 2, wherein using the public key and private key includes configuring the entity and TPM to participate in public key query response authentication, wherein in the public key query response authentication, the entity generates a query, the TPM encrypts the query using the private key, and the entity decrypts the encryption using the public key.

5. The method of claim 4, further comprising configuring a browser extension to receive the query from the entity.

6. The method of claim 5, and using the browser extension to forward the received query to the TPM via the browser.

7. The method of claim 6, and providing the UE with a watchdog to monitor the operation of the browser and extensions.

8. The method of claim 7, wherein the watchdog is used to receive an inquiry from the browser extension and forward the inquiry to the TPM.

9. The method of claim 8, further comprising configuring the TPM to forward encrypted queries to the entity via the watchdog.

10. The method of claim 9, wherein the watchdog is configured to receive an encrypted query from the PM and forward the encrypted query to the entity via the browser.

11. The method of claim 10, wherein the browser is configured to receive the encrypted query from the watchdog and forward the encrypted query to the entity via an extension.

12. A UE comprising software configured to perform the method of claim 1.

13. A method for reviewing a new password constructed by a user using a browser, for granting the user access to protected resources of an enterprise, the method comprising: Configure the browser to provide visibility of communications participated in by the user; Generate a set of cipher sets, each of which is associated with a set of at least one cipher constraint that a cipher used to access a protected resource must satisfy; Determine the cipher group within the set of cipher groups to which the new cipher belongs; as well as Before an enterprise accepts the new password for use, it reviews whether the new password conforms to the security constraints in the set of security constraints associated with the password group to which the new password belongs.

14. The method of claim 13, wherein a compliance review is performed before the password is transmitted to the enterprise for acceptance and use.

15. The method of claim 13, wherein a compliance check is performed during the formation of the password in the browser.

16. The method of claim 13, wherein the set of cryptographic groups comprises a cryptographic group defined for at least one cryptographic group security-related feature or any combination of more than one cryptographic group security-related feature.

17. The method of claim 16, wherein the at least one cryptographic group security-related feature or any combination of more than one cryptographic group security-related feature is selected from: user membership as an enterprise user; enterprise department; user role; a range of multiple enterprise user security license (CLR) levels; a range of enterprise resource confidentiality (CON) levels; a range of network attack vulnerability assessments of enterprise user devices; a range of network attack vulnerability assessments of software configurations; enterprise non-SSO (single sign-in) passwords; shared passwords; and / or user passwords not used for interaction with the enterprise.

18. The method of claim 16, wherein at least one security constraint includes a password security constraint that specifies a minimum value for a password strength metric and / or a maximum number of accounts whose passwords can be reused.

19. The method of claim 18, wherein the minimum value of the cryptographic strength metric of the new cipher is a function of at least one cryptographic security-related feature or any combination of more than one cryptographic security-related feature.

20. The method of claim 18, wherein the maximum number of accounts for the new password is a function of at least one password security-related feature or any combination of more than one password security-related feature.

21. The method of claim 18, wherein the minimum value of the password strength metric of the new password and / or the maximum number of accounts is a function of at least one security-related feature of the user profile.

22. The method of claim 21, wherein at least one security-related user profile feature includes at least one or any combination of more than one of the following: user role, user CLR, and / or the frequency at which the user is expected to use the new password.

23. A method for obfuscating a data stream generated by a user-operated human-machine interface (HCI), the method comprising: Set up low-level hooks to intercept user input events of the HCI or logic code corresponding to input events generated by the HCI driver, wherein the user input events or the logic code generate elements of the data stream; Determine whether the data stream generated by the user input event includes confidential material that makes ambiguity necessary; as well as If the data stream is determined to include confidential and sensitive material that necessitates obfuscation, then scrambling and / or salting is performed, or an input event or logic code corresponding to the input event is skipped, which generates elements of the data stream to obfuscate the data stream.

24. The method of claim 23, further comprising setting a refresh rate for the hook to maintain the priority of the hook.

25. The method of claim 24, further comprising creating an HCI jump, thereby prompting the user to switch to a different HCI to generate a portion of the data stream.

26. The method of claim 25, wherein the user is periodically prompted to switch.

27. The method of claim 25, wherein the user is prompted to switch in response to a random incident.

28. The method of claim 23, wherein the HCI is a keyboard and the input event is a key press.

29. The method of claim 28, wherein the logic code includes key scanning code.

30. The method of claim 28, wherein the logic code includes key virtual code.

31. A method for detecting the risk of network damage to an enterprise, the method comprising: Entities related to enterprise activities are represented as nodes in the graph, and the relationships between entities are represented as edges between nodes, where related entities include enterprise users, enterprise resources, and interlocutor entities with which users and / or resources communicate. Determine the feature vectors of the relevant entities that identify and represent entities, as well as the feature vectors of the edges that identify and represent relationships; Identify the activity group that includes the selection of interaction-related entities; The activity group is represented as an activity map, which includes nodes representing related interactive entities and edges representing the relationships between interactive entities; as well as The activity map is processed using a graph neural network (GNN) to identify cyberattacks that expose the enterprise to.