Browser System for Enterprises
The integration of a policy engine within a web browser system addresses the challenges of controlling and securing enterprise web browsers, enhancing security and user productivity through efficient policy enforcement.
Patent Information
- Application Number
- JP2023568582
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-05-10
- Filing Date
- 2022-05-10
- Publication Date
- 2025-06-24
- Estimated Expiration
- 2042-05-10
AI Technical Summary
Existing solutions for controlling web browsers in enterprises are costly, complex, and lack visibility into the internal operations of web browsers, often hindering users' ability to perform work tasks efficiently.
A web browser system that integrates a browser rendering engine and a policy engine, allowing for the implementation and enforcement of policies controlling various aspects of the web browser, data, and connected devices, with user authentication and policy verification before executing predefined operations.
This solution provides enhanced control and security over web browser operations within enterprises, improving user productivity while ensuring compliance and security through efficient policy enforcement.
Smart Images

Figure 0007698063000001 
Figure 0007698063000002 
Figure 0007698063000003
Abstract
Description
Technical Field
[0001] The present invention relates to a browser system for enterprises.
Background Art
[0002] Web browsers are one of the most widely used computer software applications. Organizations, including for-profit businesses and government agencies, are increasingly relying on the use of web browsers to operate for their benefit. Organizations that desire to control web browsers, such as auditing the use of web browsers and preventing the download of malware or the transmission of confidential information outside the organization, typically have no choice but to take various measures outside the web browser, for example, on the computer hosting the web browser and on the network infrastructure with which the web browser communicates. Unfortunately, such measures are often costly and complex to configure and manage, lack visibility into all aspects of the internal operation of the web browser, may prevent users of the web browser from efficiently achieving work tasks, and are very often blocked attempts to avoid such measures.
Summary of the Invention
[0003] In one aspect of the present invention, a web browser includes a browser rendering engine configured to transmit and receive data via a computer network, and a policy engine configured to implement one or more policies for controlling any aspect of the web browser, the data, the computer hosting the web browser, and devices accessible to the computer. The web browser is configured as an executable file created by compiling computer software instructions for implementing the browser rendering engine and the policy engine. The web browser is configured to authenticate a user of the web browser and verify one or more policies before being permitted to execute one or more predefined operations.
[0004] In another aspect of the present invention, each of the policies includes one or more policy conditions and one or more policy enforcement actions to be executed when the policy conditions are met.
[0005] In another aspect of the present invention, the web browser is configured to receive the policy from an external source, the policy being encrypted for decryption using a decryption key uniquely associated with an ID (identity) associated with a user of the web browser, the decryption key being provided to the web browser after the user is authenticated.
[0006] In another aspect of the present invention, the web browser is configured to receive browser settings associated with the authenticated user from the source, the browser settings being encrypted for decryption using the decryption key.
[0007] In another aspect of the present invention, the web browser is configured to at least partially evaluate any of the policies applied to the data in parallel with receiving the data.
[0008] In another aspect of the present invention, the web browser is configured to at least partially evaluate any of the policies applied to the data while receiving the data and while providing any portion of the data to the browser rendering engine.
[0009] In another aspect of the present invention, any of the policies includes policy conditions related to a category associated with a website accessed by the web browser.
[0010] In another aspect of the present invention, any of the policies includes policy conditions related to a risk level associated with a website accessed by the web browser.
[0011] In another aspect of the present invention, any of the policies includes policy conditions related to any characteristic of the computer hosting the web browser.
[0012] In another aspect of the present invention, any of the policies includes policy conditions related to any characteristic of the ID of the user of the web browser.
[0013] In another aspect of the present invention, any of the policies includes policy conditions related to any characteristic of the ID of the network accessible to the web browser.
[0014] In another aspect of the present invention, any of the policies includes policy conditions related to the source of the uniform resource locator (URL) provided to the web browser.
[0015] In another aspect of the present invention, any of the policies includes a policy enforcement action that requires performing any of data loss prevention (DLP) technology, antivirus technology, or malware countermeasure technology on the data.
[0016] In another aspect of the present invention, any of the policies includes a policy enforcement action that requires changing or manipulating the data before rendering the data or providing the data to the user.
[0017] In another aspect of the present invention, any of the policies includes a policy enforcement action that requires converting the data from a first format to a second format that removes at least a portion of the data, and then converting the converted data back to the first format, before rendering the data or providing the data to the user.
[0018] In another aspect of the present invention, any of the policies includes a policy enforcement action that requires controlling the interaction between a client-side user and a website.
[0019] In another aspect of the present invention, any of the policies includes a policy enforcement action that requires hiding a browser tab closed by the user and presenting the hidden browser tab when the user attempts to access a website or other content associated with the hidden browser tab the next time.
[0020] In another aspect of the present invention, any of the policies includes a policy enforcement action that requires disabling a predefined application programming interface (API) of the web browser.
[0021] In another aspect of the present invention, any of the policies includes a policy enforcement action that requires disabling, hiding, or masking any of the predefined elements of a web page.
[0022] In another aspect of the present invention, the web browser further includes an auditor configured to record any action attempted or performed by the user during use of the web browser.
[0023] In another aspect of the present invention, the web browser further includes an auditor configured to record any action the web browser attempts or performs when the web browser is used by the user.
[0024] In another aspect of the present invention, the web browser further includes an auditor configured to record any detectable network activity of the web browser.
[0025] In another aspect of the present invention, the web browser is specifically configured to operate in one or more target applications.
[0026] In another aspect of the present invention, the policy is specifically adapted for use in the one or more target applications.
[0027] In another aspect of the present invention, any of the policies is defined and enforced using robotic process automation (RPA) technology.
[0028] The web browser is configured to implement a plurality of different profiles separated from each other, and each of the profiles has specific data such as policies, cookies, caches, local storage, etc. The different profiles are associated with any of different simultaneous display browser tabs, different simultaneous execution processes, and different simultaneous execution browser instances.
Brief Description of the Drawings
[0029] Aspects of the present invention will be more fully understood and appreciated by reading the following detailed description in conjunction with the accompanying drawings.
[0030]
Figure 1
Figure 2
Figure 3A
Figure 3B
Figure 3C
Figure 3D
Figure 3E
Figure 3F
Figure 3G
Figure 3H
Figure 3I
Figure 3J
Figure 3K
Figure 3L
Figure 4A
Figure 4B
Figure 4C
Figure 5A
Figure 5B
Figure 6
Figure 7A
Figure 7B
Figure 7C
Figure 7D
Figure 8A
Figure 8B
Figure 9A
Figure 9B
Figure 9C
Figure 10A
Figure 10B
Figure 11
Figure 12A
Figure 12B
Figure 12C
Figure 13
DETAILED DESCRIPTION OF THE INVENTION
[0031] Referring now to FIG. 1, this figure is a simplified conceptual diagram of a browser system for enterprises constructed and operating in accordance with an embodiment of the present invention. In FIG. 1, a web browser 100 is configured to incorporate functions of a conventional web browser such as a web browser based on the Google (registered trademark) Chromium (registered trademark) architecture, except for and / or in addition to the functions described separately herein, for example, functions of sending and receiving data via a computer network and rendering data such as web pages, and is composed of a browser rendering engine 101. The web browser 100 includes, for example, a policy engine 102 configured to implement a policy 104 for controlling any aspect of the web browser 100, such as the browser rendering engine 101, its user interface, JavaScript (registered trademark) interpreter, extensions, networking settings, data persistence, but not limited thereto. For example, the policy engine 102 may be configured to implement the policy 104 by enabling or disabling extensions, controlling extension permissions, controlling local client caches and cookies, controlling user actions such as copy, paste, print, file saving, taking screenshots, etc., and controlling communication between the web browser 100 and any device such as peripheral devices accessible to the computer hosting the web browser 100. The policy 104 is related to various types of information such as, for example, device posture related to the computing device hosting or interacting with the web browser 100, identification information of the computer user interacting with the web browser 100, web pages and other data accessed or provided by the web browser 100, networking information at both the local computer network of the web browser 100 and the location of the external computer network accessible to the web browser 100, and the actions of the computer user when using the web browser 100, but not limited thereto.For example, policy 104 may be configured to depend on antivirus software or other types of software or operating system processes on the computing device hosting web browser 100, the presence, absence, or status of specific registry data and certificates, and whether the network access of web browser 100 is via a mobile, WIFI, or wired connection, or from which network domain or address.
[0032] The web browser 100 is configured to provide the policy engine 102 with any information necessary to evaluate the policy 104. Some examples of such information necessary to evaluate the policy 104 and actions that may be performed by the policy engine 102 to implement the policy 104 include the following. In one example, the policy engine 102 disables a particular browser application programming interface (API) to defend against known exploits when the web browser 100 accesses a website having a reputation score below a predefined minimum score, and such a reputation score may be determined according to the prior art. In another example, the policy engine 102 reviews particular content on the web page by applying a predefined regular expression to the document object model (DOM) of the searched web page to find personally identifiable information (PII) and then hides or masks such information. In another example, when the web browser 100 is configured to monitor the use of a user interface sharing function, the policy engine 102 reports a particular event, such as when the user performs the action of "sharing a document" in Google (TM) Docs (TM), to an analytics database or a security operations center (SOC), and may similarly report even if Google (TM) Docs (TM) does not provide an application programming interface (API) for such an action. In another example, the web browser 100 is configured to monitor a code execution engine 106 integrated into the web browser 100 to execute JavaScript (TM) code or other software instructions, and the policy engine 102 reports abnormal behavior specified by the policy 104, such as poor performance characteristics and attempts at buffer overflows. In another example, the web browser 100 is configured to detect a particular type of upload event or download event that the policy engine 102 reports according to the policy 104.
[0033] The web browser 100 may be hosted by any computing device such as a computer 108 connected to a computer network 110 which may be a corporate intranet that provides access to one or more other networks 112 such as the Internet. A copy of the web browser 100 may be installed on a plurality of computing devices for use by individuals associated with an organization such as company employees or contractors, company-owned computing devices, or non-company-owned computing devices, and is configured to be operated as described herein by a system administrator and / or other authorized parties associated with the organization to enforce policies set by the organization.
[0034] The web browser 100 is preferably configured to require authentication of each user of the web browser 100, for example, each time the web browser 100 is executed, and / or periodically at predefined time intervals, etc., and / or before the web browser 100 performs one or more predefined operations that require re-authentication of the user, before the web browser 100 is permitted to perform one or more predefined operations. The web browser 100 is also preferably configured to verify one or more signed and / or encrypted policies 104 before the web browser 100 is permitted to perform one or more predefined operations.
[0035] The management console 114 is provided for a system administrator and / or other authorized parties to define the policy 104 and provide the policy 104 to the web browser 100. The management console 114 may be hosted by any computing device such as a computer 116 that communicates directly with the web browser 100 via the computer network 110 or indirectly via the network 112.
[0036] In one embodiment of the present invention, one or more instances of the web browser 100 are configured to operate with one or more target applications, such as WhatsApp (registered trademark), Salesforce (registered trademark), or other applications. Such configuration may be completed via the management console 114 by providing the uniform resource locator (URL), icon, and executable file name of the target application to the specially configured web browser 100. The management console 114 provides an installation file 118 that includes the specially configured web browser 100 and the above elements according to the prior art, and then the installation file 118 is deployed and installed on the computing device according to the prior art. In this embodiment, each specially configured web browser 100 includes all the functions of the web browser 100 described herein, but may have user interface elements specifically adapted for use with its target application, and / or may restrict access to specific target application functions, such as by blocking file sharing configured for the web browser 100 to operate specifically with WhatsApp (registered trademark), and / or may have policies specifically adapted for use with the target application.
[0037] In one embodiment of the present invention, the web browser 100 includes an auditor 120 configured to record and / or report specific data and / or metadata related to the user, website, application, networking, use of JavaScript (registered trademark) and APIs, HTML and DOM information, policy-related information, and enforcement activities, as will be described in more detail hereinbelow.
[0038] The web browser 100 is preferably configured as an executable file created according to the prior art by compiling computer software instructions for implementing any of the functions of a conventional web browser and any of the functions of the web browser 100 described herein (e.g., but not limited to, the policy engine 102, the policy 104, and the auditor 120), including any other things described in this specification that make up the web browser 100.
[0039] Referring now to FIG. 2, this figure is a simplified flowchart showing an exemplary operational method of the system of FIG. 1 operating in accordance with an embodiment of the present invention. In the method of FIG. 2, an organizational system administrator uses a management console, such as the management console 114 of FIG. 1, to define one or more policies for controlling a web browser, such as the web browser 100 of FIG. 1, provided by the organization for the benefit of the organization, such as employees or contractors of the organization (step 200). Next, the policy is encrypted for later decryption using a decryption key uniquely associated with the organization (step 202). The encrypted policy is stored in one or more data storage devices accessible to the web browsers of the policy organization, such as by providing it to a cloud-based storage service (step 204). After a user of the web browser is authenticated and identified as acting on behalf of the organization (step 206), the user's web browser receives the organization's decryption key (step 208). The user's web browser receives the encrypted policies from the storage location (step 210), decrypts these policies using the organization's decryption key (step 212), and enforces the policies (step 214).
[0040] Referring now to FIGS. 3A - 3L, these figures are simplified conceptual diagrams of exemplary policy setting screens that may be provided by a management console 114 for defining policy 104 of FIG. 1, constructed and operating in accordance with embodiments of the present invention. Policy 104 includes a policy condition and an associated policy enforcement action that is executed when the associated policy condition is met. In FIG. 3A, screen 300 shows various types of information based on the source location of web browser 100 that can be specified for policy conditions associated with policy 104, such as ID information associated with the user of web browser 100, information associated with the configuration or other characteristics of the computing device hosting web browser 100, information regarding the computer network accessible by web browser 100, the current geographical location of web browser 100, and the current date and time of web browser 100. FIG. 3B shows a subsidiary screen 302 of screen 300, in which the necessary ID - related information can be specified for policy 104, for example, by identifying user information, group information, role information, and custom information requirements, including ID - related information that can be determined using, for example, a Security Assertion Markup Language (SAML) query, according to the prior art. FIG. 3C shows a subsidiary screen 304 of screen 300, in which the necessary device information can be specified for policy 104, for example, by identifying the type of operating system hosting web browser 100 and any other device - related information that can be determined using, for example, a Windows (registered trademark) Management Instrumentation (WMI) query, according to the prior art. FIG. 3D shows an example of a method for exposing a WMI query surface as an extension. FIG. 3E shows a subsidiary screen 306 of screen 300, in which the necessary network information can be specified for policy 104, for example, by identifying valid and invalid IP address information, WiFi type, and any other network - related information that can be determined according to the prior art.
[0041] In FIG. 3F, the screen 308 shows information regarding applications with which the web browser 100 communicates, URLs accessed by the web browser 100, all of which can be determined according to the prior art, as well as various types of information associated with the destination of information and queries transmitted from the web browser 100 that can be specified for the policy 104, such as website category information, website reputation information, network information, location information, etc. Examples of such information include names, IP addresses, and URLs of one or more destinations, such as the specification of URL patterns using regular expressions and wildcards. URL context information may also be specified. For example, the policy 104 may be configured to block access to unknown URLs or IP addresses while permitting the web browser 100 to access salesforce.com, and the policy 104 may be configured to permit the web browser 100 to access unknown destinations redirected by salesforce.com. Another URL context may be defined as follows. For example, when a user clicks on a link in an email using an external email application, the first URL accessed in the browser tab is not one entered by the user using the keyboard, and then anti-phishing measures may be taken. Examples of categories of the destination website may include "Business", "Bandwidth Consumption", "Risk", "Unknown", "Personal / Private", "Social Network", "Legal Liability", etc. The management console 114 may be used to define the destination IP address and address range, website URL, regular expression, selection of software as a service (SaaS) application, and category of the website, or the web browser 100 may be referred to a third-party website category provider such as a backend service providing threat intelligence and WebRoot (registered trademark), Cyren (registered trademark), or Google (registered trademark) Risk API, and the category of the website may be defined at the level of the full URL, the level of the domain name, or any level in between.The reputation of a website may be determined by querying a third-party website reputation provider or by applying predefined heuristics to analyze the behavior of the website according to the prior art. Examples of destination network information include its IP address and subnet.
[0042] FIG. 3G shows a screen 310 for associating source information and destination information representing policy conditions of a policy with an audit profile that defines a policy enforcement action to be executed when the specified policy conditions are met and an audit action to be executed in relation to the defined policy. FIG. 3H shows a screen 312 for defining a data loss prevention (DLP) profile that shows a policy enforcement action to be executed when a file upload is performed. If a credit card number is scanned in the file and a credit card number is found in the file, the upload is blocked. FIG. 3I shows a screen 314 for defining a policy enforcement action to be executed when a file upload or file download is performed based on the type of the file. FIG. 3J shows a screen 316 for defining a file download protection profile that shows a policy enforcement action to be executed when a file download is performed. In the file download protection profile, multiple types of malware countermeasure scans are performed on the downloaded file.
[0043] In one embodiment, policy conditions and enforcement actions are defined using conventional robotic process automation (RPA) technology. In one embodiment, policy conditions and enforcement actions are obtained from a third-party vendor in the form of an RPA module and optionally modified using the management console 114 (FIG. 1), and the RPA module includes policy conditions, policy enforcement actions, or both. FIG. 3K shows a screen 318 listing various types of RPA modules for selection. In one embodiment, policy conditions and / or enforcement actions are defined using a scripting language such as JavaScript®, an example of which is shown in FIG. 3L.
[0044] In addition to the types of information (e.g., device posture, ID, URL category, networking information, computer user behavior) that can be used to define policy conditions, examples of such policy conditions include - a given result of a JavaScript® function, and - detection of a data download event or upload event, and - the source of the URL provided to the web browser (e.g., input of the URL into the browser's address bar, selection of the URL from a bookmark, click of a link from an external application, redirect from an accessed web page).
[0045] Examples of policy enforcement actions include - masking specific content on a given website (e.g., masking PII when accessing salesforce.com), and - disabling the screen capture function of the current website if the current website provides confidential data of a predefined type, and - blocking access to the "Share" button of Microsoft PowerPoint® on office365.com, and - Adding a watermark of the current username to a specific web page (e.g., gmail.com) or a given document, and - Adding a red border when accessing a website that meets predefined security criteria (e.g., having predefined characteristics associated with a suspicious website), and - Blocking the message forwarding function of web.whataspp.com, and - Masking credit card numbers and providing an "unmask" button that allows the display of the masked information, and - Redirecting outbound HTTP requests to an intermediate proxy service that controls how the recipient of the HTTP request replies and what to reply, and - Reducing the connection speed, for example, by requesting low-quality content from a video stream, and - Changing the security permissions of the current browser session or a specific browser tab by launching a specific browser process with low OS permissions when accessing an unknown website, for example, and - Automatically locking a specific website using a protection screen that requests additional authentication not required on the website and / or locking when entering or exiting a specific browser tab, and - Automatically loading a specific website, such as a corporate email website, when the browser is running, and - Instead of closing the browser tab closed by the user, hiding it and showing the hidden tab when the user attempts to access the website or other associated content associated with the hidden tab the next time.
[0046] Policies may be defined and applied to protect confidential data. For example, it may be triggered by detecting attempts to copy, cut, paste, save, or print data, or by detecting specific web page elements, or by accessing a specific website, or by detecting attempts to send data to a website via an HTML form. Confidential data may be identified using a pre-defined list of data types and formats such as credit card number format or social security number format, or by using a pre-defined regular expression. For example, confidential data may be protected according to the prior art by masking, editing, or hiding the confidential data. The protection of confidential data may be performed by a web browser, a web browser extension, or an RPA module, or may be performed on a remote computer.
[0047] The policy may be defined and applied if an attempt to upload or download a file or other data is detected. In one example, an attempt to download or upload may be permitted without taking any action. In another example, the attempt to download or upload may be blocked and a message indicating that the attempt to download or upload has been blocked may be displayed. In another example, one or more scans of a known type of the target file, such as a scan to detect malware and prevent the disclosure of confidential data, may be performed, and actions after one or more scans of a known type may be performed if related conditions are met, such as file isolation with the file stored at a local or remote location, deletion of the file, etc. The scan may be performed by a web browser, a browser extension, or an RPA module or on a remote computer. If the file is encrypted, a visual prompt may be provided to allow the user to enter a decryption key or password so that the file can be decrypted before being scanned. In one embodiment, the policy related to an attempt to upload or download a file or other data is, if possible, evaluated partially or entirely in parallel with the execution of the upload or download. For example, while a web page is being searched, the searched portion of this web page, such as HTML, JavaScript® code, a style sheet, may be provided to the browser rendering engine 101 (FIG. 1), and the policy engine 102 evaluates the policy conditions of the policy associated with this web page search to determine whether it is necessary to block or modify either this web page or any of its elements before the browser rendering engine 101 displays this rendered web page.
[0048] The policy may be defined to control the storage location and storage method of the downloaded file. For example, the downloaded file may be stored in the local file system or a predefined remote location. The downloaded file may be encrypted using known encryption techniques before being stored, for example, based on the ID of the user who downloads it, thus preventing other users of the same web browser from decrypting the file. The downloaded file may be subjected to one or more conversions to other file formats, for example, converting from JPEG to PNG and then back to JPEG to remove potentially malicious parts before rendering the file or providing it to the user.
[0049] Referring now to FIGS. 4A - 4C, these figures are exemplary code snippets showing various ways used in implementing a policy that can be applied by the policy engine 102 to enforce the policy 104 of FIG. 1, constructed and operating in accordance with an embodiment of the present invention. FIG. 4A shows a code snippet illustrating a policy matching operation using rules, matchers, and a built - in cache. The code accepts a policy object and a browser context object that provides current browser context information. The browser context object preferably comprises fields and values indicating information related to the current browser context, such as the top - level URL of the currently accessed website (e.g., Dropbox.com), the current URL of the request (e.g., CDN.Internal.Dropbox.com), the user ID, the tab ID of the associated browser tab, the browser version, the source IP address of the request, device information, ID information, etc. FIG. 4B shows a code snippet illustrating website category matching. FIG. 4C shows a code snippet illustrating an upload profile related to a policy applied to an uploaded file, for example, by scanning the uploaded file for malware or performing data loss prevention (DLP) techniques.
[0050] Referring now to FIG. 5A, this figure is a simplified conceptual diagram of a cloud integration method constructed and operating in accordance with an embodiment of the present invention. In FIG. 5A, a web browser 500 that may be hosted by a computing device such as a mobile phone is configured as described above herein with reference to the web browser 100 of FIG. 1, but the policy enforcement function of the policy engine 102 that enforces policy 104 is executed by both the web browser 500 and a computer server 502 such as a cloud-based server that communicates with the web browser 500 via a computer network 504 such as the Internet. Network requests to the cloud may be implemented synchronously (e.g., as a blocking HTTP call) if required to enforce a policy (e.g., to classify a URL), asynchronously (e.g., as a non-blocking HTTP call that permits the normal flow of the web browser 500 to continue to execute using a callback that applies the policy result after the policy result is returned), or via the web socket protocol.
[0051] Referring now to FIG. 5B, this figure is a simplified flow diagram showing a browser login method constructed and operating in accordance with an embodiment of the present invention. In FIG. 5B, for example, a web browser 510 configured as described above herein with reference to the web browser 100 of FIG. 1 initiates a single sign-on (SSO) that interacts with a silent single sign-on (SSO) or identity provider (IdP) 512 in step #1, and the IdP 512 is configured to provide a user authentication service to the user of the web browser 510. In step #1, user authentication information such as a user login name known to the IdP 512 is provided to the IdP 512. In step #2, after authenticating the user authentication information, the IdP 512 provides a JSON Web Token (JWT) to the web browser 510, and the JWT contains information for identifying an IdP tenant known to the IdP 512 because it is associated with the provided user authentication information. For example, a tenant is a company or other organization associated with the user. In step #3, the web browser 510 sends the JWT to the cloud server 516 and requests a decryption key uniquely associated with the tenant from a key management service 514 hosted, for example, by the cloud server 516. The cloud server 516 verifies the JWT and identifies the user and tenant. In step #4, after verifying the JWT and identifying the tenant and user, the key management service 514 provides the tenant decryption key to the web browser 510. In step #5, the web browser 510 requests a policy defined for the tenant and preferably encrypted from a policy storage service 518. In step #6, the web browser 510 decrypts the encrypted policy using the decryption key for implementation. In one embodiment, the cloud server 516 stores browser settings associated with the authenticated user, such as, but not limited to, passwords, credit cards, user profile settings, bookmarks, and provides these browser settings to the web browser 510 in an encrypted form for decryption preferably using the tenant decryption key by the web browser 510.
[0052] Referring now to FIG. 6, this figure is a simplified flow diagram showing a method for establishing a private browsing session constructed and operating in accordance with an embodiment of the present invention. FIG. 6 shows a URL filtering policy being implemented in a non-blocking manner. In step #1, a web browser 600 configured as described above herein with reference to the web browser 100 of FIG. 1 attempts to access a website via a computer network 602 such as the Internet. In step #2, while the web browser 600 is receiving a response from the website, the web browser 600 instructs a policy engine 604 configured as described above herein with reference to the policy engine 102 of FIG. 1 to determine whether there is a policy indicating to establish a private browsing session for the accessed website. For example, in the following cases, the following private indicators are used to indicate the following websites: - If the category of the website is classified as "personal email" or "medical provider", - If the website is not a business-related website and such information is provided by a third-party website category provider or is provided in a pre-defined list of all websites and applications used by an organization that provides the policy implemented by the web browser 600, - A website whose IP address is not associated with an organization, - A website accessed by a device not belonging to an organization, - The private indicator is basically an audit verdict applicable to any combination of the proposed rules.
[0053] Any policy may be marked with an indicator that indicates establishing a private browsing session when the policy conditions are met. In step #3, after the policy engine 604 determines that the accessed website is a private website, the web browser 600 displays a visual indication that the accessed website is a private website, displays information retrieved from the private website, and applies security controls indicated by the policy engine 602 without storing any information related to access to the private website or interaction with the private website in the data lake 606 or the like.
[0054] Referring now to FIG. 7A, this figure is a simplified flow diagram showing a method of defining and distributing a policy such as policy 104 of FIG. 1, constructed and operating in accordance with an embodiment of the present invention. In step #1, for example, an authorized system administrator uses the management console 700 to define various policies, including policy conditions to be evaluated and policy enforcement actions to be executed when the policy conditions are met, in, for example, the policy engine 102 of FIG. 1. The policy may be defined using the screens described above with reference to FIGS. 3A - 3L. In one embodiment, the management console 700 encrypts and signs the policy definition in a particular way specific to a given installation of, for example, the web browser 704, or specific to a particular ID of an organization and individuals associated with the organization, and the web browser 704 is configured as described above herein with reference to the web browser 100 of FIG. 1. In step #2, the management console 700 provides the policy definition to a data store 702 accessible to the web browser 704 via a computer network or the like. In step #3, the web browser 704 periodically and asynchronously retrieves the applicable policy definition from the data store 702. In step #4, the retrieved policy definition is decrypted and made available to the policy engine of the web browser 704 configured as described above herein with reference to the policy engine 102 of FIG. 1. In step #5, the retrieved policy definition is checked and enforced.
[0055] An example for explaining the enforcement of the policy definition is shown with further reference to FIGS. 7B-7D. In FIG. 7B, a web page retrieved by the web browser 704 shows a telephone number. Before the web browser 704 displays the web page, the policy definition shown in FIG. 7C is evaluated and enforced, and then the web browser 704 displays a web page including the masked telephone number as shown in FIG. 7D.
[0056] Here, referring to FIG. 8A, this figure is a simplified conceptual diagram of an exemplary auditor settings screen that may be provided by the management console 114 to configure, for example, the auditor 120 of FIG. 1, which is constructed and operates according to an embodiment of the present invention. In FIG. 8A, the screen 800 shows various types of information that can be specified for auditing web navigation events, file download events, file upload events, clipboard events such as copy / cut and paste, print events, etc., and for executing RPA automation operations. As a more detailed example of what data and / or metadata can be specified for recording during auditing, - Network traffic, such as HTTP requests and responses, - User activities such as mouse input, keystroke input, scroll, copy, screenshot, activation of extensions, print, file save, etc.; navigation including opening a new tab, such as navigation when the user clicks on a link within an application external to the web browser, such as a link within an email; and redirects, - Satisfied policy conditions, - Executed policy enforcement actions, - JavaScript® and API calls, such as the use of the Web Audio API in JavaScript®, - HTML and DOM level data, such as PII data, hidden HTML elements, presence of password fields, - The RPA module to be executed and / or specific actions that occur during the execution of the RPA module, for example, masking all PII fields, allowing the user to unmask the PII fields, and the unmasking actions initiated by the user are identified for auditing, an RPA module used in salesforce.com - The sharing, viewing, and / or use of log files and / or the content of log files, and - Regular screenshots or other recordings of browser activities.
[0057] Screen 800 may be used to identify that personally identifiable information is anonymized when auditing events.
[0058] Additionally or alternatively, the auditing may be implemented via the policy definitions described above in this specification, and the identified auditing actions are executed or prevented based on meeting the identified policy conditions. For example, the auditing of events related to private websites may be prevented by the policy definition.
[0059] Referring now to FIG. 8B, this figure is a simplified conceptual diagram of an exemplary audit reporting system constructed and operating in accordance with an embodiment of the present invention. FIG. 8B shows a web browser 810 configured as described above herein with reference to the web browser 100 of FIG. 1, and the audit function described above herein with reference to FIG. 8A, with the audited information being transmitted by the web browser 810 to a computer server 812. The computer server 812 comprises an audit data manager 814 that routes audit information, based on pre-defined policies, to one or more destinations, such as a tenant data store 816, a customer data store 818, and / or a customer SOC or Security Information and Event Management (SIEM) provider 820. The tenant data store 816 may contain data from multiple tenants, and tenant-specific keys or software partitions are used to access tenant-specific data. Additionally or alternatively, customer-specific or tenant-specific data may be transmitted to a data store defined and controlled by the customer or tenant, such as the customer data store 818 and / or the customer SOC / SIEM 820.
[0060] Referring now to FIG. 9A, this figure is a simplified flow diagram showing a method of enforcing the use of a web browser by using an ID provider, constructed and operating in accordance with an embodiment of the present invention. In FIG. 9A, a given employee is required by the employer to use a web browser 900 when accessing a particular website 902, such as salesforce.com, on behalf of the employer, and the web browser 900 is configured as described above herein with reference to the web browser 100 of FIG. 1. The website 902 is configured to redirect the employee to an ID provider (IdP) 904. In step #1, the employee attempts to access the website 902 using a web browser 906 that is not configured like the web browser 900. The website 902 redirects the web browser 906 to the IdP 904, and the IdP 904 is configured to redirect the employee to a verification web page 908 after authenticating the employee according to the prior art. In step #2, after authenticating the employee, the IdP 904 redirects the web browser 906 to the verification web page 908, and the verification web page 908 is configured to determine whether the employee is accessing the verification web page 908 using the web browser 900. In step #3, the verification web page 908 determines that the employee is not accessing the verification web page 908 using the web browser 900 by determining, for example, that information received from the web browser 906 by the verification web page 908, such as one or more header information, certificates, JSON Web Tokens (JWTs), information for identifying the employee, does not match pre-defined information that configures the verification web page 908 and indicates that the employee is using the web browser 900. In step #4, the verification web page 908 attempts to launch the web browser 900 and redirect the web browser 900 to the website 902. Alternatively, the verification web page 908 provides a link for downloading the web browser 900, or a message instructing the user to download the web browser 900.If it is determined in step #3 that the verification web page 908 is being accessed by the employee using the web browser 900, the verification web page 908 redirects the web browser 900 to the website 902, e.g., salesforce.com, using the signed SAML assertion and requests access to the website 902.
[0061] Referring now to FIG. 9B, this figure is a simplified flow diagram showing a method of enforcing the use of a web browser by using a password vault, constructed and operating in accordance with an embodiment of the present invention. In FIG. 9B, a given employee is required by the employer to use a web browser 910 when accessing a particular website 912, such as salesforce.com, on behalf of the employer, and the web browser 910 is configured as described above herein with reference to the web browser 100 of FIG. 1 and is additionally configured as follows. When the employee attempts to access the website 912 using the web browser 910, the employee enters invalid login authentication information into the login form provided by the website 912. When the employee attempts to send the invalid login authentication information to the website 912, the web browser 910 uses the invalid login authentication information to access and decrypt the valid login authentication information stored in a password vault 914 previously encrypted and configured in the web browser 910. For example, both the invalid login authentication information and the valid login authentication information are provided in advance to the management console 114 of FIG. 1, and then the management console 114 encrypts the valid login authentication information and provides the encrypted valid login authentication information to the web browser 910. Next, the web browser 910 sends the valid login authentication information to the website 912 instead of the invalid login authentication information. In this embodiment, if the employee attempts to access the website 912 using a web browser 916 not configured like the web browser 910 and enters invalid login authentication information, the access attempt fails.
[0062] Referring now to FIG. 9C, this figure is a simplified flowchart showing a method of implementing the use of a web browser by using network tunneling, constructed and operating in accordance with an embodiment of the present invention. In FIG. 9C, a given employee is required by the employer to use a web browser configured as described above herein with reference to the web browser 100 of FIG. 1 and additionally configured as follows. At step 920, a website, such as salesforce.com, is configured to permit incoming communications from the employee only if the communications are received from a predefined IP address such as 3.3.3.3. At step 922, the employee attempts to communicate with the website from a computer having an IP address of 2.2.2.2 using the web browser. At step 924, the web browser tunnels the communication to an IP address 3.3.3.3, which is a proxy server configured to authenticate the employee and / or the web browser, for example, in accordance with the prior art. At step 926, the proxy server tunnels the communication to the website. At step 928, the website receives the communication and authenticates the employee in accordance with the prior art. At step 930, the website further determines that the communication was sent from the IP address 3.3.3.3 and permits access to the employee.
[0063] Referring now to FIGS. 10A and 10B, these figures are exemplary code snippets showing various ways of extending web browser extension access, constructed and operating in accordance with embodiments of the present invention. FIG. 10A shows a code snippet showing a method of exposing the PathExists function to a JavaScript®-based extension. FIG. 10B shows a code snippet showing a method of exposing clipboard operations to a JavaScript®-based extension.
[0064] Referring now to FIG. 11, this figure is an exemplary code snippet showing a method of configuring a proxy used in an embodiment of the present invention. FIG. 11 shows a method of dynamically setting proxy settings using the Proxy Auto Configuration (PAC) function.
[0065] Referring now to FIG. 12A, this figure is a simplified flow diagram showing a method of using a web browser in a Virtual Private Network (VPN) constructed and operating in accordance with an embodiment of the present invention. FIG. 12A shows a web browser 1200 hosted by a computer 1202, the web browser 1200 being configured as described above herein with reference to the web browser 100 of FIG. 1, and the web browser 1200 including a policy engine 1204 configured as described above herein with reference to the policy engine 102 of FIG. 1. In step #1, the web browser 1200 detects an attempt by a user to access an application on a computer network 1206 using the web browser 1200. In step #2, the policy engine 1204 determines, according to a predefined policy, that the application is an "internal" application, i.e., an application that does not have an inbound Internet connection from outside the enterprise network or cloud boundary, and activates a VPN 1208 that can be a VPN incorporated in the web browser 1200, a VPN installed on the computer 1202, or any other VPN accessible to the web browser 1200. In step #3, communication between the web browser 1200 and the computer network 1206 is established via the VPN 1208 according to conventional VPN technology. In step #4, the web browser 1200 terminates the VPN connection, for example, when it detects the closing of a web browser tab associated with the VPN session, or when it is configured to terminate the VPN connection upon the termination of the web browser 1200.
[0066] Referring now to FIG. 12B, this figure is a simplified flow diagram showing a method of using a web browser with a cloud connector, constructed and operating in accordance with an embodiment of the present invention. FIG. 12B is configured as described above with reference to FIG. 12A, but requests to access an internal application are routed to cloud connector 1210, and this routing may be implicit proxy, explicit proxy, or IP-based routing, for example, at a fixed IP address. The request may include additional authentication header information outside or inside the Secure Sockets Layer (SSL) stream. Cloud connector 1210 may be configured to decrypt the SSL stream, for example, if the request is an SSL request. Additionally or alternatively, if the web browser 1200 controls the request header, additional headers may be added outside the SSL stream to enable cloud connector 1210 to route traffic without opening the SSL stream. Next, cloud connector 1210 routes the access request to the target application. If there is a firewall 1212 between cloud connector 1210 and the target application, an incoming port is opened within firewall 1212 to receive incoming traffic from the target application.
[0067] Referring now to FIG. 12C, this figure is a simplified flow diagram showing a method of using a web browser with a cloud connector constructed and operating in accordance with an embodiment of the present invention. FIG. 12C is configured as described above with reference to FIG. 12B, except that an application connector 1214, which may be configured as a TCP server, is shown accessing the target application instead of opening an inbound port within the firewall 1212 for the cloud connector 1210 to directly receive inbound communications from the target application. The application connector 1214 opens an outbound connection to the cloud connector 1210, and server - to - server authentication may be used. The cloud connector 1210 is configured to determine which user requests require routing to the application connector 1214 or other application connectors. The cloud connector 1210 preferably has a multi - tenant function that supports multiple tenants being connected simultaneously. For example, if tenants A and B are connected to the same cloud connector 1210 from different networks, the cloud connector 1210 can determine which tenant it is based on JWT tokens, headers, and other identifiable information and route the traffic of each tenant to the appropriate destination application connector.
[0068] Referring now to FIG. 13, this figure is a simplified diagram showing isolation boundaries and multi-profile support constructed and operating in accordance with one embodiment of the present invention. In FIG. 13, the web browser as configured hereinabove described with reference to the web browser 100 of FIG. 1 is additionally configured to implement a plurality of profiles separated from each other, and each profile has unique data including policies, cookies, caches, local storage, and other stateful data that other profiles cannot access. The data of each profile is preferably encrypted using any encryption technique and can be accessed from within its associated profile. Access to different profiles and associated data is preferably managed by any of the policy mechanisms described hereinabove. Different profiles may be associated with different concurrent browser tabs, concurrent processes, and / or concurrent browser instances, and visual indicators may be displayed to permit the user to know which profile is currently being accessed. Examples of various types of profiles include 1. For example, a public profile that may be associated with an anonymous user ID, where access to critical applications is not permitted, and 2. A workspace profile associated with a user logged into the browser using a corporate ID, where a policy that controls the user's access to critical applications is enforced and the user's actions are audited, and 3. For example, a private profile that may be associated with a user when accessing a private website, where the user is permitted to perform private browsing with anti-tracking and privacy features turned on, and where the user's actions are not audited, and 4. A workspace anonymous profile associated with a user logged in to a browser configured to perform anonymous browsing for research or law enforcement purposes, etc., using an enterprise ID, and include.
[0069] Any aspect of the invention described herein may be implemented in computer hardware and / or computer software embodied on a non-transitory computer-readable medium according to the prior art, the computer hardware including one or more computer processors, computer memory, I / O devices, and network interfaces that interoperate according to the prior art.
[0070] As used herein, it should be understood that the terms "processor" or "device" are intended to include any processing device, such as, for example, those including a CPU (Central Processing Unit) and / or other processing circuitry. It should also be understood that the terms "processor" or "device" refer to multiple processing devices, and that various elements associated with a processing device may be shared by other processing devices.
[0071] As used herein, the term "memory" is intended to include memory associated with a processor or CPU, such as, for example, RAM, ROM, fixed memory devices (e.g., hard drives), removable memory devices (e.g., floppy disks), flash memory, etc. Such memory may be considered a computer-readable storage medium in some cases.
[0072] Furthermore, as used herein, the phrase "input / output device" or "I / O device" is intended to include, for example, one or more input devices (e.g., keyboard, mouse, scanner, etc.) for inputting data to a processing unit, and / or one or more output devices (e.g., speaker, display, printer, etc.) for presenting results associated with the processing unit.
[0073] Embodiments of the present invention may include a system, a method, and / or a computer program product. The computer program product may include a computer-readable storage medium having computer-readable program instructions that cause a processor to execute aspects of the present invention.
[0074] The computer-readable storage medium can be a tangible device that can hold and store instructions for use by an instruction execution device. The computer-readable storage medium may be, for example, but is not limited to, an electronic storage device, a magnetic storage device, an optical storage device, an electromagnetic storage device, a semiconductor storage device, or any suitable combination of the foregoing. A non-exhaustive list of more specific examples of the computer-readable storage medium includes a portable computer diskette, a hard disk, a random access memory (RAM), a read-only memory (ROM), an erasable programmable read-only memory (EPROM or Flash memory), a static random access memory (SRAM), a portable compact disc read-only memory (CD-ROM), a digital versatile disc (DVD), a memory stick, a floppy disk, a mechanically encoded device such as a punch card or raised structures in a groove having instructions recorded thereon, and any suitable combination of the foregoing. The computer-readable storage medium should not be construed as being a transient signal per se, such as a radio wave or other freely propagating electromagnetic wave, an electromagnetic wave propagating through a waveguide or other transmission medium (e.g., an optical pulse passing through an optical fiber cable), or an electrical signal transmitted through a wire.
[0075] The computer-readable program instructions described herein can be downloaded from a computer-readable storage medium to respective computing / processing devices, or can be downloaded from an external computer or an external storage device via a network, such as, for example, the Internet, a local area network, a wide area network, and / or a wireless network. The network may include copper transmission cables, optical transmission fibers, wireless transmission, routers, firewalls, switches, gateway computers, and / or edge servers. A network adapter card or network interface within each computing / processing device receives the computer-readable program instructions from the network and transfers the computer-readable program instructions for storage in a computer-readable storage medium within each respective computing / processing device.
[0076] The computer-readable program instructions for carrying out the operations of the present invention may be source code or object code written in any combination of one or more programming languages, including assembler instructions, instruction set architecture (ISA) instructions, machine instructions, machine-dependent instructions, microcode, firmware instructions, state-setting data, or object-oriented programming languages such as Java (registered trademark), Smalltalk, C++, and conventional procedural programming languages such as the "C" programming language or similar programming languages. The computer-readable program instructions may be executed entirely on the user's computer, partly on the user's computer as a stand-alone software package, partly on the user's computer and partly on a remote computer, or entirely on a remote computer or server. In the latter scenario, the remote computer may be connected to the user's computer via any type of network, including a local area network (LAN) or a wide area network (WAN), or the connection may be made to an external computer (e.g., via the Internet using an Internet service provider). In some embodiments, to carry out aspects of the present invention, an electronic circuit, including, for example, a programmable logic circuit, a field programmable gate array (FPGA), or a programmable logic array (PLA), may utilize the state information of the computer-readable program instructions to execute the computer-readable program instructions to customize the electronic circuit.
[0077] Aspects of the present invention are described herein with reference to flowchart illustrations and / or block diagrams of methods, apparatus (systems), and computer program products according to embodiments of the invention. It will be understood that each block of the flowchart illustrations and / or block diagrams, and combinations of blocks in the flowchart illustrations and / or block diagrams, can be implemented by computer-readable program instructions.
[0078] These computer-readable program instructions may be provided to a processor of a general purpose computer, special purpose computer, or other programmable data processing apparatus to produce a machine, such that the instructions executed via the processor of the computer or other programmable data processing apparatus create means for implementing the functions / acts specified in the flowchart and / or block diagram block or blocks. These computer-readable program instructions may be stored in a computer-readable storage medium that can direct a computer, programmable data processing apparatus, and / or other devices to function in a particular manner, such that the computer-readable storage medium containing the instructions comprises a manufacture including instructions for implementing the function / act mode specified in the flowchart and / or block diagram block or blocks.
[0079] The computer-readable program instructions may be loaded onto a computer, other programmable data processing apparatus, or other device to cause a series of operational steps to be performed on the computer, other programmable apparatus, or other device to produce a computer-implemented process, such that the instructions which execute on the computer, other programmable apparatus, or other device implement the functions / operations specified in the flowchart and / or block diagram block or blocks.
[0080] The flowcharts and block diagrams in the drawings illustrate the architecture, functionality, and operation of possible implementations of systems, methods, and computer program products according to various embodiments of the present invention. In this regard, each block in the flowchart or block diagram may represent a module, segment, or portion of computer instructions, which includes one or more executable computer instructions for performing a specified logical function. In some alternative implementations, the functions noted in the blocks may be performed out of the order noted in the drawings. For example, depending on the relevant functions, two blocks shown in succession may in fact be executed substantially concurrently, or the blocks may sometimes be executed in the reverse order. It should also be noted that each block of the block diagrams and flowcharts, and combinations of these blocks, can be implemented by a dedicated hardware-based system and / or a dedicated software-based system that performs the specified functions or operations.
[0081] The description of the various embodiments of the present invention has been presented for purposes of illustration, but is not intended to be exhaustive or limited to the disclosed embodiments. Many modifications and variations will be apparent to those of ordinary skill in the art without departing from the scope and spirit of the embodiments described.
Claims
1. A web browser, comprising: a browser rendering engine configured to transmit and receive data via a computer network; and a policy engine configured to implement one or more policies for controlling any aspect of the web browser, the data, the computer hosting the web browser, and devices accessible to the computer; wherein the web browser is configured as an executable file created by compiling computer software instructions for implementing the browser rendering engine and the policy engine; the web browser is configured to authenticate a user of the web browser and verify one or more policies before allowing the web browser to perform one or more predefined operations; the web browser is configured to receive the policy from an external source, the policy being encrypted for decryption using a decryption key uniquely associated with an ID associated with the user of the web browser before the policy is provided to the web browser, and the decryption key being provided to the web browser after the user is authenticated.
2. The web browser according to claim 1, wherein the web browser is configured to receive browser settings associated with the authenticated user from the source via the computer network, and the browser settings are encrypted for decryption using the decryption key before being transmitted to the web browser via the computer network.
3. The web browser according to claim 1, wherein the web browser is configured to at least partially evaluate any of the policies applied to the data in parallel with receiving the data.
4. The web browser according to claim 1, wherein the web browser is configured to at least partially evaluate any of the policies applied to the data in parallel with receiving the data and in parallel with providing any portion of the data to the browser rendering engine.
5. The web browser according to claim 1, wherein any of the policies includes policy conditions related to a category associated with a website accessed by the web browser.
6. The web browser according to claim 1, wherein any of the policies includes policy conditions related to a risk level associated with a website accessed by the web browser.
7. The web browser according to claim 1, wherein any of the policies includes policy conditions related to any characteristic of the computer hosting the web browser.
8. The web browser according to claim 1, wherein any of the policies includes policy conditions related to any characteristic of the ID of a user of the web browser.
9. The web browser according to claim 1, wherein any of the policies includes policy conditions related to any characteristic of the ID of a network accessible by the web browser.
10. The web browser according to claim 1, wherein any of the policies includes policy conditions related to the source of a Uniform Resource Locator (URL) provided to the web browser.
11. The web browser according to claim 1, wherein any of the policies includes a policy enforcement action that requires performing any one of data loss prevention (DLP) technology, antivirus technology, or malware countermeasure technology on the data.
12. The web browser according to claim 1, wherein any of the policies includes a policy enforcement action that requires changing or manipulating the data before rendering the data or providing the data to the user.
13. The web browser according to claim 1, wherein any of the policies includes a policy enforcement action that requires converting the data from a first format to a second format that removes at least a portion of the data, and then converting the converted data back to the first format before rendering the data or providing the data to the user.
14. The web browser according to claim 1, wherein any of the policies includes a policy enforcement action that requires controlling the interaction between the client-side user and the website.
15. Any of the policies includes a policy enforcement action that hides browser tabs closed by the user and presents the hidden browser tabs when the user attempts to access a website or other content associated with the hidden browser tabs the next time, the web browser according to claim 1.
16. Any of the policies includes a policy enforcement action that requires disabling a pre-defined application programming interface (API) of the web browser, the web browser according to claim 1.
17. Any of the policies includes a policy enforcement action that requires invalidating, hiding, or masking any of the pre-defined elements of a web page, the web browser according to claim 1.
18. The web browser according to claim 1 further includes an auditor configured to record any action attempted or executed by the user during use of the web browser.
19. The web browser according to claim 1 further includes an auditor configured to record any action attempted or executed by the web browser when the web browser is used by the user.
20. The web browser according to claim 1 further includes an auditor configured to record any detectable network activity of the web browser.
21. The web browser according to claim 1 is specifically configured to operate in one or more target applications.
22. The policy is specifically adapted for use in the one or more target applications, the web browser according to claim 21.
23. Any of the policies is defined and enforced using robotic process automation (RPA) technology, the web browser according to claim 1.
24. The web browser is configured to implement a plurality of different profiles separated from each other, Each of the profiles has unique policies, cookies, caches, and local storage, The web browser according to claim 1, wherein the different profiles are associated with any of different simultaneously displayed browser tabs, different simultaneously executed processes, and different simultaneously executed browser instances.
Citation Information
Patent Citations
Information filtering device, information filtering method, method execution program and program storage medium
JP2004110806A
Client-side extensions for use in connection with HTTP proxy policy enforcement
US20070220599A1
Secure container for protecting enterprise data on a mobile device
US20140006347A1
Search result image processing
US20150161177A1
Web browser policy for http-based application
US20170163690A1