Cybersecurity Systems
CyberSafe addresses the vulnerability of communication networks by using a cloud-based security hub and secure web browser to isolate and monitor communications, enforcing policies and providing real-time intervention, thereby enhancing cybersecurity for enterprises with remote workers.
Patent Information
- Application Number
- JP2023565437
- Authority / Receiving Office
- JP · JP
- Patent Type
- Patents
- Current Assignee / Owner
- Priority Date
- 2021-04-22
- Filing Date
- 2022-04-22
- Publication Date
- 2025-08-27
- Estimated Expiration
- 2042-04-22
AI Technical Summary
The increased vulnerability of communication networks and digital resources due to the proliferation of personal devices and cloud-based services has amplified the difficulty in providing cybersecurity, especially for enterprises with remote workers, as these devices act as potential cyberattack nodes, complicating the protection of confidentiality and integrity against cyberattacks.
A cyber-secure communications system, CyberSafe, which includes a cloud-based data and processing security hub and a CyberSafe Secure Web Browser (SWB) configured to isolate and monitor communications, enforce security policies, and provide real-time intervention to protect digital resources by controlling data access and movement, thereby enhancing visibility and security against cyber threats.
CyberSafe provides enhanced protection against cyber damage and data leakage by isolating and monitoring communications, enforcing security policies, and offering real-time intervention, ensuring that user interactions and data access are fully visible and secure, thus mitigating risks associated with personal devices accessing enterprise resources.
Smart Images

Figure 0007730377000009 
Figure 0007730377000010 
Figure 0007730377000011
Abstract
Description
[Technical Field]
[0001] (Related Applications) This application claims the benefit under 35 U.S.C. §119(e) of U.S. Provisional Application No. 63 / 177,998, filed April 22, 2021, the disclosure of which is incorporated herein by reference.
[0002] Embodiments of the present disclosure relate to providing cyber-secure access channels and workspaces for communication networks and digital resources. [Background technology]
[0003] The various computer and communications technologies that power modern communications networks and the Internet encompass a wide variety of virtual and bare-metal network elements (NEs) that support the operation of communications networks and the fixed and / or mobile user equipment (UE) that provides access to those networks. These technologies enable the information technology (IT) and operations technology (OT) that underpin today's society, providing numerous methods, devices, infrastructure, and protocols for controlling industrial equipment, supporting business operations, and generating and disseminating data, voice, and video content over the Internet. Most people around the world have easy access to all kinds of information through the Internet, regardless of their physical location. Today, a large portion of the global community regularly works remotely from their homes, coffee shops, and vacation locations using their personal, bring-your-own-device (BYOD) UEs, such as their personal smartphones, laptops, tablets, and home desktops, with connectivity to their employers and workgroups. Networks have de-hierarchized information consumption and accelerated changes in social infrastructure.
[0004] However, the benefits provided by computer and communications technology are not without their costs. Those same technologies and benefits have greatly increased the difficulty of providing and maintaining legitimate individual and collective rights to confidentiality and of protecting the integrity and security of the same industrial and business operations that technology has made possible against disruption and damage from cyberattacks.
[0005] For example, a cyberattack surface fingerprint characterizes each UE, whether it be a personal, spatially untethered BYOD or an enterprise Workplace User Equipment (WPUE), potentially providing a vulnerability for exploitation by malicious hackers to wreak havoc on the UE and, more frequently, on the entities and systems to which the UE connects. In addition to serving as a person's communications node, each UE, particularly a BYOD, is also a potential cyberattack node for any communications network to which the UE connects. For enterprises that must communicate with clients, workers, and / or associates who have at least partially transitioned to remote work using personal BYOD, vulnerability to cyberattack is amplified by the large number of those remote contacts, the software configurations within each of those contacts' BYODs, and the variety of non-enterprise communications in which those contacts engage using UEs. Providing adequate cyberprotection is increasingly complex with the shift to clouds of enterprise data and storage resources and the proliferation of technologies accessed and used by remote contacts, such as Infrastructure as a Service (IaaS), Platform as a Service (PaaS), and Software as a Service (SaaS). Summary of the Invention
[0006] Aspects of embodiments of the present disclosure relate to providing a cyber-secure communications system, hereinafter also referred to as "CyberSafe," that provides enhanced visibility into communications traffic propagated by the system, provides cyber protection for digital resources of a body of resources, and operates to secure access to the digital resources of the body of resources for authorized users of UEs (BOYDs or WPUEs) associated with the body of resources.
[0007] For ease of presentation, it is assumed that the body of digital resources is owned by a company, optionally referred to as "MyCompany," and that the company employs or engages in tasks with users who are authorized to access the MyCompany resources using UEs associated with the body of resources. The UEs associated with the body of resources are UEs configured in accordance with embodiments of the present disclosure to enable authorized users to access the MyCompany resources. The UEs associated with the body of resources may be referred to as MyCompany UEs, and users authorized to use MyCompany UEs to access the MyCompany resources may be referred to as MyCompany users or simply users.
[0008] A digital resource includes any information in a digital format, at rest or in motion, including, by way of example, electronic documents, images, files, data, databases, and / or software, which refers to executable code and / or data. A digital resource also includes any software and / or hardware that can operate on or be used to generate a digital resource. An active digital resource is a digital resource that is in use and / or in motion and / or in transit between nodes of a communication system. A digital resource at rest is a digital resource that is in storage and not in motion.
[0009] In one embodiment, CyberSafe comprises an optionally cloud-based data and processing security hub, also referred to as the CyberSafe Hub, and a web browser, also referred to as the CyberSafe Secure Web Browser (SWB), configured by or in accordance with CyberSafe and residing in the MyCompany UE's CyberSafe Isolation Secure Environment (CISE). In one embodiment, the CISE operates to isolate software (code and / or data) contained within the SWB and other applications that may reside within the CISE from software within the UE and from software outside the UE that may be used for tasks not associated with MyCompany resources, also referred to as UE ambient software. In one embodiment, the ingress and egress of data into and out of the CISE and between applications in the CISE, respectively, is monitored and controlled by the SWB, which is configured by CyberSafe to enforce CyberSafe and / or MyCompany security policies related to the access and movement of data into and out of the CISE. The separation and control of data movement and access to data, and policy enforcement, operates to provide enhanced protection against cyber damage and security against data leakage from and / or to MyCompany resources that may result from communications with and via MyCompany UE.
[0010] In one embodiment, monitoring data ingress and egress includes monitoring communications supported by the SWB, storing and processing data contained in the monitored communications, and making the data available to the CyberSafe hub and MyCompany IT. In one embodiment, monitoring is performed on communications egressing from the CISE and SWB before the outgoing communications are encrypted by the SWB, and on communications ingressing into the CISE after the incoming communications are decrypted by the SWB. Additionally, user interactions with the SWB may be monitored locally or by the CyberSafe security hub. As a result, communications between the UE and MyCompany and actions of MyCompany users interacting with the UE are substantially fully visible to CyberSafe and MyCompany and may be processed by the SWB, the hub, and / or other trusted components associated with MyCompany.
[0011] According to an embodiment of the present disclosure, when launched from a MyCompany UE by a MyCompany user, the SWB is configured to request permission from the CyberSafe security hub to run from the UE and includes software, optionally referred to as cladding, such as anti-injection and / or anti-exploitation software, that operates to protect the SWB from cyber damage. Upon receiving the request for permission, the CyberSafe hub optionally checks the UE user's identity and examines the integrity of the web browser software and the security posture of the UE. If the user identity is found to be acceptable, the software integrity and / or cladding is intact, and / or the security posture of the UE environment is satisfactory, the security hub may authorize operation of the SWB from the UE and, optionally, issue a security token to the SWB for presentation to access MyCompany resources.
[0012] In one embodiment, a CyberSafe security hub, a CyberSafe SWB, and an identity provider (IDP) that operates to control access to MyCompany's digital resources are configured to cooperate in granting access to MyCompany's digital resources to authorized users of MyCompany UEs. CyberSafe may operate to restrict MyCompany users to use the CyberSafe SWB to access MyCompany resources.
[0013] In one embodiment, CyberSafe configures the SWB to obtain data characterizing websites accessed by MyCompany users of MyCompany UEs and the browsing behavior of MyCompany users and upload the data to the CyberSafe Hub. The CyberSafe Hub and / or SWB process the data to estimate the risk of damage to MyCompany resources (hereinafter also referred to as cyber damage) resulting from access to the websites and / or user browsing behavior that may expose the resources to cyber attacks. The Hub and / or SWB can configure the SWB and / or UE in response to the cyber damage risk estimate to mitigate the risk of cyber damage. Configuring the SWB for medium risk may include configuring the SWB to limit or prevent access to websites and / or to limit functionality of the websites, SWB, UE, and / or user browsing behavior, and / or permissions to transfer data between the SWB or CISE and other applications. Configuring the UE for medium risk may include requiring the user of the UE to update passwords, patching, firewalls, website permissions, and / or disable remote access.
[0014] In one embodiment, CyberSafe obtains data characterizing the browser extension and / or user browsing behavior relative to use of the browser extension, processes the data, and estimates a risk to the cybersecurity of MyCompany resources resulting from downloading the browser extension and modifying the SWB to add functionality provided by the browser extension to the SWB. CyberSafe may configure the SWB and / or browser extension to mitigate risks posed by the browser extension before enabling the browser extension to integrate with the SWB.
[0015] According to one embodiment of the present disclosure, CyberSafe uses a CyberSafe SWB to monitor and obtain data characterizing MyCompany users' use of Cloud Computing as a Service (CCaaS) resources, process the data, and determine normal usage patterns of the service as evidenced by the users. CyberSafe can configure the CyberSafe SWB to monitor CCaaS sessions engaged in by MyCompany users and respond to and identify usage anomalies in normal usage patterns exhibited during the sessions. In response to identifying usage anomalies in CCaaS sessions, the SWB can restrict usage of CCaaS resources in real time during the session. Restricting usage may include preventing real-time data transfer between the CCaaS and the user and / or canceling the session. Upon identifying an anomaly, the SWB can generate an alert and upload data related to the anomaly to a hub for analysis. In one embodiment, CyberSafe configures a MyCompany user's use of a given CCaaS resource based on the given CCaaS resource, the resource's typical CCaaS usage pattern, the user's authorization profile, and / or the particular MyCompany UE the user uses to engage in the CCaaS session, as may be mandated by CyberSafe and / or MyCompany policies, which may change dynamically based on the context of use. According to embodiments of the present disclosure, CyberSafe uses the CyberSafe SWB to provide SSO access to CCaaS that do not natively support single sign-on (SSO) by mimicking the user and password input expected by CCaaS to automatically sign in to CCaaS.
[0016] This Summary is provided to introduce a selection of concepts in a simplified form that are further described below in the Detailed Description. This Summary is not intended to identify key features or essential features of the claimed subject matter, nor is it intended to be used to limit the scope of the claimed subject matter. [Brief explanation of the drawings]
[0017] Non-limiting examples of embodiments of the present invention are described below with reference to the drawings attached hereto, listed following this paragraph. Identical features that appear in multiple figures are generally labeled with the same label in all figures in which they appear. Labels labeling icons representing given features of embodiments of the present invention in the figures may be used to refer to the given feature. Dimensions of features shown in the figures are chosen for convenience and clarity of presentation and are not necessarily shown to scale.
[0018] [Figure 1] 1 illustrates a schematic diagram of a MyCompany UE configured with a CyberSafe CISE and SWB to provide cybersecurity for a company called MyCompany, according to one embodiment of the present disclosure. [Figure 2A] 1 illustrates a flow diagram of a procedure by which the SWB shown in FIG. 1 can engage in a handshake with a CyberSafe hub to obtain a token for use in accessing MyCompany resources, according to one embodiment of the present disclosure. [Figure 2B] 1 illustrates a flow diagram of a procedure by which the SWB shown in FIG. 1 can engage in a handshake with a CyberSafe hub to obtain a token for use in accessing MyCompany resources, according to one embodiment of the present disclosure. [Figure 2C] 1 illustrates a flow diagram of a procedure by which the SWB shown in FIG. 1 can engage in a handshake with a CyberSafe hub to obtain a token for use in accessing MyCompany resources, according to one embodiment of the present disclosure. [Figure 3] 1 illustrates a flow diagram of a procedure by which SWB may be provided with permission to access MyCompany resources, according to one embodiment of the present disclosure. [Figure 4] 10 illustrates a flow diagram of another procedure by which SWB may be provided with permission to access MyCompany resources according to an embodiment of the present disclosure. [Figure 5A] 1 illustrates a flow chart of a procedure by which CyberSafe may obtain and process data to estimate possible cyber-attack risks to MyCompany resources associated with website access and use SWB to control website access for MyCompany users, according to one embodiment of the present disclosure. [Figure 5B] 1 illustrates a flow chart of a procedure by which CyberSafe may obtain and process data to estimate possible cyber-attack risks to MyCompany resources associated with website access and use SWB to control website access for MyCompany users, according to one embodiment of the present disclosure. [Figure 5C] 1 shows a flow diagram illustrating monitoring a sample scenario of a MyCompany user's interaction with a website, according to one embodiment of the present disclosure. [Figure 6A] 1 shows a flow chart illustrating a procedure by which CyberSafe may operate to monitor the use of MyCompany CCaaS resources and provide real-time intervention to provide cybersecurity for MyCompany resources, according to one embodiment of the present disclosure. [Figure 6B] 1 shows a flow chart illustrating a procedure by which CyberSafe may operate to monitor the use of MyCompany CCaaS resources and provide real-time intervention to provide cybersecurity for MyCompany resources, according to one embodiment of the present disclosure. DETAILED DESCRIPTION OF THE INVENTION
[0019] In the discussion, unless otherwise stated, adjectives such as "substantially" and "about" modifying a condition or relationship characteristic of one or more features of an embodiment of the present disclosure are understood to mean that the condition or characteristic is defined within a tolerance allowed for the operation of the embodiment for its intended use. Whenever a general term in this disclosure is indicated by reference to exemplary instances or a list of exemplary instances, the referenced instances are intended to be non-limiting exemplary instances of the general term, and the general term is not intended to be limited to the specific exemplary instances referenced. The phrase "in one embodiment," whether associated with an allowance such as "may," "optionally," or "for example," is used to introduce an example in view, but is not necessarily a required configuration of possible embodiments of the present disclosure. Unless otherwise indicated, the term "or" in the description and claims is considered an inclusive, not exclusive, "or" and indicates any combination of at least one of the items to which it connects, or more than one item.
[0020] 1 schematically illustrates a CyberSafe system 50 that operates to provide cybersecure communications for a communications network for an enterprise 20, also referred to as MyCompany 20 or simply MyCompany, and for MyCompany users 10 using the communications network, in accordance with one embodiment of the present disclosure. MyCompany may have a premises 24 that houses cloud-based digital resources 22, an on-premises server (not shown) for storing and processing MyCompany's on-premises digital resources 28, and a WPUE 30 for use by MyCompany users 10 when on-premises to access, use, and transact on the cloud-based and on-premises resources to conduct MyCompany business. MyCompany may enable users 10 to access MyCompany resources from various locations when off-premises using any of various types of BYOD 32. It is assumed that MyCompany users 10 may use their respective BYOD 32 for personal activities, and that MyCompany users may be authorized to use WPUE 30 for personal activities when on-premises, in accordance with permissions defined by MyCompany policies. Personal activities may include web browsing, social networking, uploading, and downloading materials via the cloud infrastructure of communication nodes 41 and website 40. The MyCompany network may be required to support communications between any of various combinations of MyCompany's on-premise digital resources 28, cloud-based digital resources 22, on-premise users 10 using WPUE 30 installed on MyCompany's premises 24, and off-premise users 10 using BYOD 32 at various off-premise locations, as shown schematically by double-arrowed dashed line 43.
[0021] According to one embodiment of the present disclosure, CyberSafe 50 comprises an optionally cloud-based CyberSafe processing and data hub 52 and a software architecture 60 that operates to cyber-protect MyCompany communications and digital resources on each of a plurality of MyCompany UEs, BYODs 32 and / or WPUEs 30 used by MyCompany users 10 to access and use MyCompany resources. CyberSafe hub 52 comprises and / or has access to cloud-based and / or bare-metal processing and memory resources required to enable and support the functionality that the hub provides to CyberSafe 50 and the CyberSafe components.
[0022] 1 illustrates a CyberSafe software architecture 60 that configures MyCompany UE 33 to protect MyCompany digital resources at rest and / or in operation and to provide cyber-secure access to the resources for users 10 who may be using MyCompany UE 33. MyCompany UE 33 may be a BYOD or WPUE and may be referred to as My-WorkStation 33.
[0023] The architecture 60 comprises a CyberSafe isolation environment CISE 62 isolated from ambient software 35 resident on My-Workstation 33 and including an SWB 64 resident on CISE 62. Ambient software 35 may typically include data and applications not intended for use in conducting MyCompany business. By way of example, ambient software 35 may include a browser, an office suite of applications, a clipboard, a family picture album, a photo album, and WhatsApp. CISE 62 may also include a set of applications 65 optionally imported from ambient software 35, wrapped by CyberSafe, and optionally containerized to associate the applications with cybersecurity features required by CyberSafe and / or MyCompany policy features. In one embodiment, the CISE comprises an ensemble of shared secure services 66 that can be accessed for use by SWB 64 and by applications in set 65 via SWB 64. Shared secure services 66 optionally include a secure clipboard and a secure encrypted file system.
[0024] CISE 62 provides an isolated security domain defined by a substantially continuous security perimeter created and supported by the security applications, features, and functionality of SWB 64, shared secure services 66, and the wrapping of wrapped application 65. According to one embodiment, CISE 62 can be configured to provide cybersecurity and isolation using methods of and compliance with standards such as PCI DSS (Payment Card Industry Data Security Standard), HIPAA (Health Insurance Portability and Accountability Act), and / or SOC2 (Service Organization Controls of the American Institute of Certified Public Accountants). Optionally, CISE 62 is isolated from ambient software at the network level.
[0025] In one embodiment, to provide isolation and security, SWB 64 is configured to monitor and control the ingress and egress of data to and from CISE 62 and between CyberSafe-wrapped applications, shared secure services 66, and / or applications within SWB 64, respectively. SWB 64 is advantageously configured by CyberSafe to enforce CyberSafe and / or MyCompany security policies of access to and movement of data related to data within and to and from the CISE. The isolation and control of data movement and access, and policy enforcement, operates to provide enhanced protection against cyber damage and security against data exfiltration from and / or to MyCompany resources that may result from communications with and via MyCompany UE.
[0026] In one embodiment, monitoring the ingress and egress of data includes monitoring communications supported by SWB 64, storing and processing data contained in the monitored communications, and making the data available to CyberSafe Hub and MyCompanyIT. bMonitoring is performed on communications originating from the CyberSafe isolation environment CISE 62 (FIG. 1) before being encrypted by SWB 64, and on communications arriving at CISE after the incoming communications have been decrypted by SWB 64. As a result, the user's browsing is substantially fully visible to CyberSafe and MyCompany and can be processed locally or remotely. Monitoring may be substantially continuous, probabilistic, or periodic. Probabilistic monitoring involves monitoring communications over a monitoring period of limited duration beginning at a randomly determined start time, optionally according to a predetermined probability function. Periodic monitoring involves continuous monitoring of communications during a monitoring period at periodic start times. Monitored communications may be mirrored by SWB 64 to a destination within CyberSafe Hub and / or MyCompany for storage and / or processing, or may be filtered for data of interest before being sent to a destination within CyberSafe Hub and / or MyCompany for storage and / or processing. The characteristics and constraints that configure how monitored communications are processed by SWB 64 may be determined based on CyberSafe and / or MyCompany policies, which may specify how data processing is shared between the local SWB and the CyberSafe Hub.
[0027] In one embodiment, SWB64 may be a standalone application that includes CyberSafe features and / or functionality, or an existing web browser, such as Google® Chrome, Microsoft® Edge, Apple® Safari, Mozilla® Firefox®, Opera®, or Brave®, that has been modified to provide additional CyberSafe features and / or functionality by changes and / or additions to the browser code and / or by integrating with CyberSafe extensions. The features and functionality may be built into the existing browser, or the browser may be converted to CyberSafeSWB by using operating system hooks to interface with the existing browser's input and output, patching the browser's original binary, building a dedicated extension on top of the browser's API and / or SDK, and / or dynamically modifying the browser's memory while the browser is running.
[0028] By way of example, the features and / or functionalities hereinafter collectively referred to as functionality may include at least one or any combination of functionalities that enable SWB 60 to collaborate with MyCompany IDP to verify and authorize user 10's access to CISE 62 and MyCompany resources; obtain data characterizing websites visited by MyCompany users that may be used to classify cyber risks associated with the websites; obtain data characterizing browser extensions that may impair SWB 64 security features; obtain data that may be processed to determine typical behavior and usage of MyCompany resources by MyCompany users as a group and / or individuals; and monitor MyCompany users' engagement with MyCompany resources and control engagement to enforce CyberSafe and / or MyCompany security restrictions.
[0029] In one embodiment, enforcing CyberSafe and / or MyCompany security constraints includes requiring all communications between UE33 and MyCompany resources to be propagated through SWB64 and a CyberSafe tunnel connecting SWB to the resource, and enforcing CyberSafe and / or MyCompany permissions on the resource. Optionally, enforcing security constraints includes identifying anomalies in communications between UE33 and enterprise resources, and operating to eliminate or remediate damage from the identified anomalies and generate alerts to their occurrence.
[0030] The flow diagrams presented in Figures 2A-6B show elements of procedures performed by a CyberSafe system and an SWB, such as CyberSafe system 50 and SWB 64, which illustrate and illustrate the functionality of the CyberSafe system and SWB, according to one embodiment. This discussion is intended to illustrate how the CyberSafe system can identify and process users' respective user IDs, U-IDs, and n Multiple users U identified by (1≦n≦N) n Assume that we provide cybersecurity services to a given company, MyCompany, with 1≦n≦N. The user has a user equipment ID, UE-ID e Assume that the UE can access and use the user equipment identified by (1≦e≦E), and CyberSafe has configured the UE with a CISE and a CyberSafe browser, SWB, referenced by index b, identified by SWB browser ID, B-IDb, respectively.
[0031] 2A to 2C show user equipment (UE). e A given user U uses n However, contacting the CyberSafe Security Hub e Request permission to access and use CISE within the SWB resident within CISE b 1 shows a flowchart 100 of a procedure for having a security token issued for access to MyCompany resources.
[0032] In block 102, user U n UE e Sign in to the CyberSafe Security Hub and submit a request for a security token, which includes your user ID, U-ID, n , User Equipment ID, UE-ID e ,UE e Identify the SWB installed in b ID, B-ID b Contains an extended ID containing U-ID n will store information about the user, such as username, password, and / or the date the user was first registered as a MyCompany user. e , SWB b , and / or may include such data associating it with MyCompany. e may be any suitable identifier, such as a MAC (Media Access) address, a UUID (Universal Unique Identifier), or an IMSI (International Mobile Subscriber Identity), and / or a UE e User U n , SWB b B-IDb may contain information relating to the browser user agent string, and / or MyCompany. b Any suitable identifier that assigns the SWB b UE e , U n , and / or may include information relating to MyCompany.
[0033] For a given user U n is multiple UEs e and / or multiple SWBs b may be associated with a user ID U-ID n Note that the UE may comprise data identifying the association. Similarly, the UE may e is multiple U n and / or multiple SWBsb may be associated with a given SWB b is multiple U n and / or multiple UEs e and each ID, UE-ID e , and B-ID b may comprise data mapping the association. n ,UE e , and / or SWB b Any combination of one or more of may include a time of day (ToD) for each of at least one previous signature to CyberSafe.
[0034] Optionally, in block 104, the CyberSafe Security Hub authenticates the extended ID. n Involved in three-factor authentication and U-ID n ,UE-ID e , or B-ID b and determining a consistency of the association and / or ToD in at least one of the IDs with at least another of the IDs.
[0035] If the Extended ID is not OK at decision block 106, the Hub proceeds to block 142 and rejects the requested token, optionally sending an alert of the rejection to the CyberSafe Hub. On the other hand, if the Extended ID is OK, the Hub optionally proceeds to decision block 108 and sends an alert to the SWB b Determines whether to perform integrity testing on the software. The decision to perform integrity testing may depend on MyCompany and / or CyberSafe testing policies. The policy may determine whether the CyberSafe Hub is b and / or UE e When was the last integrity test performed on the user U? nThe decision may depend on the user profile, which characterizes browsing behavior and internet usage patterns, and / or on characteristics of the cyber-attack landscape. For example, MyCompany may have a policy that the delay between integrity tests is no shorter than a certain lower delay limit and no longer than an upper delay limit. The decision may be made by the user U. n The cyber-attack landscape may depend on whether the user browses cyber risk websites listed in the list of risk websites more frequently than a predetermined frequency, or whether the user tends to engage in password updates or application patching. The cyber-attack landscape may include the frequency and / or severity of cyber-attacks recently experienced by MyCompany or other companies, and / or what types of cyber-attacks have been encountered. Optionally, if the decision at decision block 108 is to skip the integrity test, the hub proceeds to block 140 and issues the desired token. If the decision is to perform the integrity test, the hub proceeds to block 110 and retrieves at least one software integrity test "sit" from a database that the hub contains or to which the hub has access. i " can be searched for the set "SIT" where SIT={sit i │1≦i≦I} and SWB b An exemplary SIT may include at least one of the following, or any combination of more than one: sit1 = CRT (challenge response test), sit2=BAT (Behavioral Proof Test), sit3=AV (anti-virus check), sit4 = EDR (Endpoint Detection and Response), sit5=BDS (Binary Digital Signature), : sit I
[0036] In block 112, the CyberSafe Hub b Test sit to determine software integrity iEach sit provides an estimate of how appropriate i About weight wit i In one embodiment, a weight vector WIT is determined that includes i About Wit i is the following function: UE e Hardware type, e.g., UE e If is a mobile device, tablet, or desktop, then the given sit i UE types that may be restricted e can be performed on Sensitivity, given sit i true positive rate, Specificity, a given sit i true negative rate, Annoyance rating, test performance is user UE e provide a measure of the inconvenience caused to Past performance on exams, and / or Identify the current cyber-attack context, current prevalence and severity of cyber-attack types.
[0037] In block 114, the CyberSafe Hub b In software, their respective weights wit i Depending on the exam sit i However, for example, the larger weight wit i The weights of each of them are the median weights with i Greater Integrity Test Sit i By selecting
[0038] In block 116, the CyberSafe Hub connects the selected test site i In response to the measure of completeness returned by each of the e SWB in bDetermine the value of the software's QoI(e,b) (Quality of Completeness) measure. In one embodiment, QoI(e,b) is calculated by dividing the respective weights wit i sit weighted by i Optionally, in decision block 118, the CyberSafe Hub determines whether the QoI value is satisfactory. If the QoI is not satisfactory, the Hub proceeds to block 142 and refuses to issue a token and optionally sends an alert. On the other hand, if the QoI is satisfactory, the Hub proceeds to decision block 120 and e Determine whether to perform ambient software environment testing on the
[0039] If there is a software environment test, it is UE e This is a test to determine the extent to which ambient software within a UE is at risk from or inadequately protected against cyber damage. e The decision to perform environmental testing on a UE may be based on many of the same considerations that are weighed when making a decision to perform integrity testing. For example, the decision may be based on MyCompany and / or CyberSafe policies, and the UE e Hardware, e.g., UE e Whether it is a mobile phone or a laptop, the last environmental test is UE e When executed on the user U n This may depend on factors such as browsing behavior patterns and / or characteristics of the cyber attack landscape.
[0040] Optionally, if the decision at decision block 120 is to skip the software environment test, the CyberSafe Hub may proceed to block 140 and issue the desired token. On the other hand, if the decision is to perform the environment test, the Hub may optionally proceed to block 110 and retrieve at least one cyber-attack vulnerability feature hvf from the database, determined as present or absent. e,jWe can search for the set "HVF(e)" where HVF(e)={hvf e,j |1≦j≦J}. HVF(e) may comprise static and / or dynamic vulnerability features. Static vulnerability features are considered to make ambient software and / or digital resources not included in the ambient software, such as CyberSafe and / or MyCompany resources, vulnerable to cyberattacks. e Dynamic vulnerability features are features that are code and / or data elements contained in the surrounding software of the UE. e Temporary vulnerability characteristics, such as whether the UE is connected to a public WiFi or a cyber risk website, e An exemplary HVF(e) may include at least one, or any combination of multiple, vulnerability features, the presence or absence of which may optionally be determined in response to the following query: hvf e,1 = Is AV (anti-virus) / EDR (endpoint detection and response) installed? hvf e,2 Is a firewall installed and enabled? hvf e,3 Is the OS (operating system) patched to the latest version? hvf e,4 =Is the application patched to the latest version? hvf e,5 =UE e Does access to require authentication? hvf e,6 =Is there a risk of software default? hvf e,7 =Is public Wi-Fi being used? hvf e,8 = UE connected to a VPN (Virtual Private Network) e mosquito?, hvf e,9 What is the security level of the connected network? : hvf e,J .
[0041] Optionally, in block 124, the CyberSafe Hub may e Scan the ambient software environment to find out e,j Detect the presence of each HVF e,j Cyber attack risk estimate for HVR e,j Determine a risk vector HVR(e) containing e,j │1≦j≦J)}. Given vulnerability hvf e,j Determining a risk estimate for a vulnerability generally depends on the type of vulnerability and the cyber-attack landscape. For example, determining a risk estimate for a given public Wi-Fi network may depend on the Wi-Fi network's physical location, the current traffic carried by the Wi-Fi network at the time the estimate is made, and the recent history of attempted cyber-attacks over the Wi-Fi network. The risk associated with patching may be a function of the type of patching required or installed.
[0042] In block 126, CyberSafe e Scan ambient software to identify at-risk components in ambient software k A set HCC(e) of e,k |1≦k≦K)}. Then, in block 128, CyberSafe retrieves the risk component ucr from the CyberSafe database. n,r A user profile can be retrieved that characterizes the user's cyber risk profile, optionally including a set UCR(n) of (1≦r≦R), where UCR(n)={ucr n,r │1≦r≦R)}, which means that users U expose CyberSafe and / or MyCompany to cyber attacks. n can be used to characterize the behavioral characteristics of
[0043] At block 130, CyberSafe detects the HVR(e), HCC(e), UCR(n), and / or the attribute SWB b SWB, which represents the cybersecurity measures provided to b The set of cyberclad software attributes CPA(b) is processed to determine whether CPA(b) provides advantageous protection against cyber attacks. b For example, for a user with high privileges to MyCompany resources, CPA(b) may require that additional security checks be performed and additional security controls, such as EDR, be installed in order for the user to be able to access MyCompany resources. Additionally, some capabilities that affect the system's vulnerability to cyber attacks may be restricted or disabled by CPA(b) if the user is accessing an unknown website or a website with a low security reputation (and therefore high risk). In one embodiment, processing is performed by a neural network configured to operate on an input feature vector comprising component features based on components of HVR(e), HCC(e), UCR(n), and / or CPA(b).
[0044] Optionally, in block 132, if the CyberSafe Hub determines that the cladding protection is favorable, the Hub proceeds to block 140 and issues the requested token. On the other hand, if the cladding protection is not favorable, the Hub may proceed to block 134 and decide whether to modify the cladding protection to improve protection. If the Hub decides not to modify, the Hub may proceed to block 142 and reject the token and issue an alert. On the other hand, if the decision is to modify the cladding, the Hub proceeds to block 136 and modifies the cladding and optionally proceeds to decision block 138 to determine whether the modification has resulted in a sufficient improvement in cyber protection. If the improvement is not sufficient, the CyberSafe Hub proceeds to block 142 and rejects the token.
[0045] FIG. 3 illustrates the SWB(n,e) in accordance with one embodiment of the present disclosure. b UE having e User U who runs n 18 shows a flow diagram of a procedure 180 by which SWB(n,e) can be provided with permission to access a given MyCompany resource. b The parenthetical reference (n,e) in b The configuration of n and a given user equipment UE e and given SWB b , and for a given UE, e However, there are multiple SWBs, each configured for a different MyCompany user. b It also shows that it can host
[0046] In block 185, CyberSafe configures the UE to access a given MyCompany resource, e.g., cloud-based resource 22 or on-premise resource 28 (FIG. 1). e User U who operates n The MyCompany IDP (Identity Provider) and CyberSafe Hub 52 are configured to work together in authenticating and authorizing users.
[0047] In block 186, user U n returns SWB(n,e) with a request to access a given MyCompany resource. b The UE submits the identity B-IDb and notifies the request to the CyberSafe Hub via the tunnel (Figure 1). e SWB(n,e) b In decision block 187, the given MyCompany resource optionally operates SWB(e) according to the CyberSafe procedure 100 illustrated in FIGS. 2A-2C. b has a CyberSafe security token issued by the CyberSafe Hub.
[0048] SWB(n,e) b If SWB(n,e) does not possess a CyberSafe security token, the given MyCompany resource proceeds to block 194, denies the requested access, and issues an alert. b If n includes a CyberSafe security token, then optionally in block 188, the MyCompany resource SWB(n,e) b to MyCompany's IDP. Optionally, in block 189, the IDP redirects user U n If at decision block 190 it is determined that the multi-factor check is not OK, proceed to block 194 and deny the requested access.
[0049] On the other hand, if the MFA identity check is OK, then in block 191 the given MyCompany resource is SWB(n,e) b Double-check the request submitted by SWB(n,e) b whether you notified the CyberSafe Hub of your request and n is authorized to access the given MyCompany resource. In decision block 192, the hub validates the request and, if authorization is confirmed, optionally in block 193, grants the requested access to the given MyCompany resource.
[0050] FIG. 4 illustrates the SWB(n,e) in accordance with one embodiment of the present disclosure. b UE having e User U who operates n 2 shows a flow diagram of another procedure, procedure 200, by which a user can be provided with permission to access a given MyCompany resource.
[0051] In block 202, CyberSafe optionally instantiates a proxy server to provide access to MyCompany resources, and in block 204 configures MyCompany's IDP to allow access to MyCompany resources only from the proxy and configures SWB(n,e) to require access from the proxy. b Configure.
[0052] In block 206, user U n is SWB(n,e) b , and requests access to a given MyCompany resource, SWB(n,e) b connects to the CyberSafe Security Hub and requests access. In block 208, the Security Hub sends the proxy's IP address and the password for access to the proxy service to SWB(n,e). b Optionally, in block 210, SWB(n,e) b requests access to a given MyCompany resource through a proxy using the proxy address and password. Upon receiving the request, the IDP associated with MyCompany optionally performs a multi-factor authentication (MFA) check on the request. The multi-factor check is performed by the user U. n In addition to the multi-factor check on SWB(n,e), the method optionally includes a check on whether the request was received from the IP address of a proxy. If, at decision block 214, the source address is the IP address of a proxy and the authentication factors associated with the user identity are verified, then at block 216, access to the given MyCompany resource is granted. On the other hand, if MFA fails, then at block 218, access is denied and SWB(n,e) is returned. b will alert you to the denial.
[0053] 5A and 5B show that CyberSafe provides high visibility monitoring of MyCompany user browsing activity, and n2 shows a flow diagram of a procedure 250 that operates to protect MyCompany resources from cyber damage resulting from the browsing behavior of
[0054] In block 252, CyberSafe configures the browser SWB to monitor MyCompany user communications and capture data characterizing user browsing activity and the websites the user visits. b Optionally, in block 254, the browser SWB b is the set of users U={U n MyCompany user U from │(1≦n≦N)} n By monitoring the browsing of the user, we can obtain the set of websites visited by the user, WS={ws w │(1≦w≦W)} each website "ws w " captures data that can be used to characterize users' browsing behavior and the websites they visit.
[0055] In one embodiment, monitoring browsing activity includes monitoring SWB b via user U n and website ws w and monitoring communications between the SWB and the CyberSafe Hub, storing and processing data contained in the monitored communications, and making the data available for local analysis by applications within the CyberSafe Hub and MyCompany IT and / or CISE. b For communications originating from the CyberSafe Isolation Environment CISE62 (Figure 1) and / or SWB64 (Figure 1) before being encrypted by the b The monitoring is performed on communications arriving at the CISE after being decrypted by CyberSafe and MyCompany. As a result, user views are substantially fully visible to CyberSafe and MyCompany and available for local processing and security analysis. Monitoring may be continuous, probabilistic, or periodic. Continuous monitoring is performed on communications arriving at the CISE after being decrypted by CyberSafe and MyCompany. As a result, user views are substantially fully visible to CyberSafe and MyCompany and available for local processing and security analysis. n and website ws w SWB between bThe monitoring method includes substantially continuous monitoring of communications for the duration of the session involved via the SWB. Stochastic monitoring includes monitoring communications over a monitoring period of limited duration beginning at a randomly determined start time, optionally according to a predetermined probability function. Periodic monitoring includes continuous monitoring of communications during a monitoring period at periodic start times. Monitored communications may be mirrored to a destination within the CyberSafe Hub and / or MyCompany, or may be filtered for data of interest before being sent to a destination within the CyberSafe Hub and / or MyCompany. The monitored communications may be monitored via the SWB. b The characteristics and constraints that configure how the data is processed by may be determined in response to CyberSafe and / or MyCompany policies.
[0056] In block 256, the retrieved data may be uploaded to the CyberSafe Hub 52 (FIG. 1). Optionally, in block 258, the CyberSafe Hub processes the uploaded data to communicate with MyCompany users and the website ws when the users access the website. w behavioral profile indicators wpi that can be used to characterize or characterize normal interactions with w,p Optionally, the hub determines a set WPI(w) of websites ws w For each MyCompany user U, we generate WPI(w). n The profile indicator wpi of the user-specific WPI(w) determined for a given user is called the user-specific WPI(w). w,p characterizes the typical website behavior of a given user when the given user accesses the website. In one embodiment, the hub generates a WPI(w) called group WPI(w), which collectively characterizes the typical website behavior for the group of MyCompany users. The profile indicators wpi of the group WPI(w) w,poptionally, a user-specific profile indicator wpi determined for each individual member of the MyCompany user's group w,p The average of the two can be weighted.
[0057] An exemplary user-specific WPI(w) and / or group WPI(w) may include profile indicators wpi w,p The present invention may include at least one of the following, or any combination of multiple of the following: wpi w,1 = average frequency of access, wpi w,2 = average time spent on the website, wpi w,3 = the amount of data transferred to download the web pages associated with the website, wpi w,4 = the number and types of web page resources downloaded from the website; wpi w,5 = APIs used by websites, such as HTML5 and DOM APIs, wpi w,6 = number and type of links going out of the website, wpi w,7 = Information the website requests from the user (name, gender, location, credit card, ...), wpi w,8 = website content type (news, social networks, sports, banking, porn, gambling, ...), wpi w,9 =allow, : wpi w,P . Note that some of the profile indicators above may be composite profile indicators that include multiple related indicators. For example, wpi w,3 The number and type of resources generally includes multiple different resources bundled with a website page.
[0058] Optionally, in block 260, the uploaded data is processed and posted to the website ws w Website vulnerability characteristics WVF w,v Set of WVF w Determine where WVF(w)={wvf w,v │(1≦v≦V)}, which is the w As a result of connecting to SWB b and / or SWB b This could make MyCompany resources accessed by the profile indicator wpi vulnerable to cyber damage. w,p For example, for a given website ws w Profile indicator wpi w,p An abnormal value of wpi may indicate a website's attack surface that is at increased vulnerability to and risk of damage from cyber attacks. w,p The measure of vulnerability associated with a given profile indicator WPI of a website w,p The value of wpi w,p Average value of
number
number
number
number
[0059] An exemplary WVF(w) is a set of vulnerability features wvf w,v In the list, the corresponding website profile wpi w,v The vulnerability characteristics that are considered to depend on the deviation of from the mean of
number
number
number
number
[0060] In block 262, the CyberSafe Hub 52 optionally generates a website vulnerability risk feature vector WVFR(w)={wvfr w,v │1≦v≦V)}, where wvfr w,v , vulnerability wvf w,v In one embodiment, CyberSafe can use a neural network to assign risk levels to vulnerabilities. Optionally, CyberSafe can use a heuristic classification to assign risk levels to vulnerabilities.
[0061] Optionally, in block 264, the CyberSafe Hub 52 processes the uploaded data to generate a n Regarding optional risk component ucr n,r Determine a user profile that characterizes the cyber risk profile of the user, comprising a set UCR(n)=(1≦r≦R), where UCR(n)={ucr n,r │(1≦r≦R)} exposes CyberSafe and / or MyCompany to cyberattacks. n can be used to characterize the behavioral characteristics of the risk component ucr n,r Optionally, determining a set of browsing behavior characteristics includes determining, for each determined browsing characteristic, whether the behavior characteristic is associated with SWB. b and / or estimating the degree of risk of exposing MyCompany resources.
[0062] An example UCR(n) is a profile indicator ucr n,r The present invention may include at least one of the following, or any combination of multiple of the following: ucr n,1 = Risks from careless password management, ucr n,2 = Risk from careless permission management, ucr n,3 = Estimate of the risk from recklessly clicking on actionable content, ucr n,4 = Estimated risk from insensitivity to fishing baits, ucr n,5 =Risk estimate for highly privileged users on MyCompany resources, : ucr n,R .
[0063] In block 266, user U n is SWB b Using the website ws w Attempt to connect to SWB b optionally notifies CyberSafe Hub 52 of the attempt. In response to the notification, the Hub optionally processes WVFR(w) and UCR(n) in block 268 to provide a Security Risk Indicator (SRI) value that provides an estimate of the risk of cyber damage that may result from the connection. Then, in block 270, the Hub or SWB b inspect the website to monitor changes to the website and / or user n and website ws w A real-time security risk indicator (RSRI) can be determined that is responsive to a current virtual model of the interaction with the
[0064] To determine RSRI, please visit the website w To examine the vulnerability characteristics of WVF(w), w,v, and therefore, determining whether there is a change in the risk feature vector WVFR(w) that produces a statistically significant difference between the SRI and the RSRI. b The web page is w Optionally, the web browser SWB may download the web page and bundled resources to a secure sandbox within the CISE and check the behavior of the web page and bundled resources to determine whether the web page and resources are benign before rendering the web page from the website. b may cause cyber damage, n a user U when interacting with an emulation of a website to determine the probability that the user U will click on executable content presented by the website; n For example, SWB b Run the experiment in the sandbox and run it on the website ws w Whether the emulation of generates phishing bait, and if so, U based on UCR(n) n You can decide whether your avatar clicks on the fishing bait or not.
[0065] In one embodiment, the values of SRI and / or RSRI may be determined by a neural network operating on input feature vectors having components that are from or based on any combination of at least one or more of the sets WVF(w), WVFR(w), and / or UCR(n). Optionally, the values of SRI and / or RSRI may be determined by a neural network operating on input feature vectors having components that are from or based on any combination of at least one or more of the sets WVF(w), WVFR(w), and / or UCR(n). w and / or U n is determined based on a heuristic model.
[0066] At decision block 272, the CyberSafe Browser SWB bcan determine whether the security risk indicator SRI is greater than a predetermined maximum upper limit SRI-UB or whether RSRI is greater than a predetermined maximum allowable upper limit SRI-UB. If none of the risk indicators are greater than their respective upper limits, SWB b goes to block 282 and visits the website ws w allows access to the user U n and website ws w The device may be operable to monitor interactions with the device.
[0067] On the other hand, if either SRI or RSRI is greater than its respective upper limit, SWB b proceeds to decision block 274 and user U n and website ws w Interactions with and / or websites w SWB to support functionality b You can decide whether to modify the configuration of the browser SWB b If the browser decides not to modify, it proceeds to block 280 and w You can prevent access to the device and alert the CyberSafe Hub of the denial.
[0068] On the other hand, SWB b If user U decides to modify in decision block 274, the browser optionally proceeds to block 276 and n Modify your browser configuration for and / or access the website w Modify the functionality of . For example, user U n SWB for b Modifying the configuration of U n website ws w This may include preventing users from clicking on certain executable content that displays on websites. w Modifying the SWB may include changing website permissions and / or disabling website links. Following modification, the browser SWB bmay proceed to decision block 278 to determine whether the modification was successful in reducing the SRI and / or RSRI to an acceptable value. If the modification was successful at block 282, the browser SWB b is user U n WS w If the connection is unsuccessful, the browser proceeds to block 280 and w U to n Prevent access to
[0069] According to one embodiment, user U n and website ws w Monitoring interactions with the user includes intervening in user activity to prevent violations of security policies as illustrated by the example scenario provided by 290 in the flow diagram shown in FIG. 5C.
[0070] In one embodiment, a procedure similar to that of step 250 is performed by CyberSafe to check for browser extensions that MyCompany may wish to access and download. b accumulates data about each of a set of extensions that MyCompany's users attest to an interest in. The data may be used to determine vulnerability characteristics and vulnerability risk estimates that are used to determine whether and how to modify the extension and / or users who interact with the extension, and whether to allow the extension to be downloaded and integrated with the browser SWB.
[0071] 6A and 6B show that CyberSafe provides high visibility monitoring of MyCompany users of cloud computing and provides a set of MyCompany cloud computing resources My-CCaaS={My-CCaaS s │(1≦s≦S)} MyCompany cloud computing resource My-CCaaS s3 shows a flow diagram of a procedure 300 that operates to protect MyCompany resources from cyber damage resulting from MyCompany users' access to and use of cloud computing resources My-CCaaS. s can be, for example, Infrastructure as a Service (IaaS) resources, Platform as a Service (PaaS) resources, or Software as a Service (SaaS).
[0072] In block 302, CyberSafe monitors the cloud computing activity of MyCompany users and records the MyCompany user cloud computing activity and the My-CCaaS that the user visits. s Browser SWB to obtain data characterizing the resource b Optionally, in block 304, the browser SWB b monitors MyCompany's use of cloud computing resources My-CCaaS and monitors the usage of the resources by a given user U n and My-CCaaS s Session (CCSESS n,s ) about SWB b Optionally, stores data for a set of key performance indicators (KPIs) CCaaS-KPI(n,s), UE-KPI(n,s), U-KPI(n,s), and data for a set of session metadata components SMETA(n,s).
[0073] CCaaS-KPI(n,s) is the session CCSESS n,s My-CCaaS sThe UE-KPI(n,s,e) may include values of KPIs that can be used to characterize the operation of the session CCaaS-KPI(n,s). The CCaaS-KPI(n,s) may include, by way of example, KPIs that provide values for at least one of, or any combination of, CPU usage, memory usage, bandwidth usage, response time to a user request, throughput, latency, request error rate, resources accessed, permission changes, and / or network requests. The UE-KPI(n,s,e) may include values of KPIs that provide values for at least one of, or any combination of, CPU usage, memory usage, bandwidth usage, response time to a user request, throughput, latency, request error rate, resources accessed, permission changes, and / or network requests. n,s CCaaS s To interact with the user U n User equipment (UE) used by e The U-KPI(n,s,e) KPIs include values of KPIs that can be used to characterize the operation of the session. The UE-KPI(n,s,e) KPIs can include, by way of example, KPIs that provide values for at least one or any combination of a plurality of: CPU usage, memory usage, thread count, task execution time, security controls of the UE, historical data associated with the particular UE, a risk score of the UE, and / or throughput. The U-KPI(n,s) can be used to characterize the operation of the session CCSESS. n,s User U n U-KPI(n,s) may include values of KPIs that can be used to characterize the actions of the user during the session. U-KPI(n,s) may include, by way of example, KPIs that provide values for at least one or any combination of the following: user keyboard typing patterns, user mouse activity patterns, usage of wrapped apps, usage of shared secure services, data patterns used by the user during the session including data typed locally in SWB, uploaded and downloaded files, file names, and / or interruptions using ambient software. SMETA(n,s) may optionally include values of KPIs that provide values for ... at least one or any combination of the following: user keyboard typing patterns, user mouse activity patterns, usage of wrapped apps, usage of shared secure services, data patterns used by the user during the session including data typed locally in SWB, uploaded and downloaded files, file names, and / or interruptions using ambient software. n,s SMETA(n,s) contains indexing and descriptive data for the session ID (U-ID) n ,UE-ID e , B-ID b), session ToD (time of day), session duration, identity of uploaded data and files, identity and data of downloaded files, and / or websites visited and duration of website visits, or any combination of more.
[0074] Optionally, in block 306, the browser SWB b uploads the set CCaaS-KPI(n,s), UE-KPI(n,s), U-KPI(n,s), and / or SMETA(n,s) to the CyberSafe Security Hub 52 (FIG. 1). Then, in block 308, the browser SWB b and / or the CyberSafe Hub processes the data provided by CCaaS-KPI(n,s), UE-KPI(n,s), U-KPI(n,s), and / or SMETA(n,s) to determine expected values for the components of the set. The expected values are provided to the user U. n and My-CCaaS s About Session CCSESS n,s For multiple instances of and / or collectively multiple My-CCaaS s Session CCSESS n,s and MyCompany User U n In one embodiment, for a given user MyCompany, user U n The expected value for CCSESS n,s Determine the user-specific normal behavior pattern for the group MyCompany, and the expected value for the group MyCompany is CCSESS s Determine the group's normal behavior pattern for the session.
[0075] Optionally, CyberSafe Hub and / or Browser SWB bThe user-specific normal behavior patterns and group normal behavior patterns determined by the CyberSafe Hub are stored in a memory, such as a cloud-based memory associated with the CyberSafe Hub, or in a SWB, such as the memory of a secure encrypted file system of a shared secure service 66 in the CISE 62 (FIG. 1). b is stored in a memory associated with
[0076] Optionally, in block 310, SWB b and / or the CyberSafe Hub processes the data provided by CCaaS-KPI(n,s), UE-KPI(n,s), U-KPI(n,s), and / or SMETA(n,s) to provide My-CCaaS s MyCompany users who use My-CCaaS and / or My-CCaaS s Optionally, at block 312, the CyberSafe Hub and / or SWB b In response to determined cyber vulnerabilities, SWB b and / or My-CCaaS s Modify the features of My-CCaaS s Moderate risk of cyber damage during the session. For example, My-CCaaS s Modification of the SWB may include disallowing access to certain resources, preventing permission changes, and / or restricting network requests. b Modifications to My-CCaaS to prevent the uploading and / or downloading of certain files and / or data s SWB to limit session duration b The method may include configuring:
[0077] Optionally, at block 314, for a given UE, e In a given browser SWB b A specific user U n’ is a specific My-CCaaS s’Request and be granted access to and use of My-CCaaS s’ The "current" session with CCSESS n’,s’ At block 316, a given SWB b is the current session CCSESS n’,s’ monitors, accumulates data on CCaaS-KPI(n',s'), UE-KPI(n',s',e'), U-KPI(n',s'), SMETA(n',s'), processes it locally, and uploads it to add to the already accumulated data for the current session, optionally for a given SWB b Other than SWB b By My-CCaaS s Enforce MyCompany and / or CyberSafe policies and / or detect the occurrence of anomalous events due to processing from previous sessions with
[0078] In one embodiment, an anomalous event is an event that violates normal behavior or violates MyCompany and / or CyberSafe policies. By way of example, a violation of normal patterns may be b Optionally, the conditions for determining an event is a violation of normal behavior and / or policy may be user-dependent and / or configured by My-CCaaS. sFor example, for an inexperienced MyCompany user, the definition of infringement may be less permissive than for an experienced MyCompany user, resulting in a KPI coefficient that is smaller than for an experienced MyCompany user. Enforcing CyberSafe and / or MyCompany policies may involve, by way of example, preventing a MyCompany user from uploading, downloading, and / or modifying certain MyCompany files or data, or from accessing websites and / or MyCompany resources. Preventing may also include intercepting draft communications created by a MyCompany user before the user manages to send the communication from the user UE. Enforcing policies may involve changing permissions or modifying the current session CCSESS. n,s This may involve canceling the UE's ...
[0079] At block 318, a given SWB b If no abnormal event is detected by b continues to decision block 328 and determines whether the session CCSESS n’,s’ If the session has not ended, the given SWB b can return to block 316 and continue monitoring the session. If the session has ended, the given SWB b If an abnormal event is detected, then the process proceeds to block 330 and ends monitoring. On the other hand, if an abnormal event is detected, then optionally, at decision block 320, the given SWB b determines whether an abnormal event warrants a response based on the CyberSafe Hub 52 (FIG. 1) and / or MyCompany policies. If a response is not warranted, the given SWB b continues to decision block 328 and determines whether the session CCSESS n’,s’If the session has not ended, the process returns to block 316 to continue monitoring the session. On the other hand, if a response is warranted, the given SWB b The SWB may proceed to block 322 and make a response. The response may include enforcing MyCompany and / or CyberSafe policies and taking the actions described in the previous paragraph. If the response is not cancellation and is deemed sufficient under MyCompany and / or CyberSafe policies, the SWB may cancel the given SWB. b continues to decision block 328 and determines whether the session CCSESS n’,s’ If the session has not ended, the process returns to block 316 to continue monitoring the session. On the other hand, if the abnormal response is insufficient or includes a cancellation, the given SWB b proceeds to block 326 and the session CCSESS n’,s’ Exit.
[0080] In the above description, various actions are performed using the CyberSafe Hub 52 and CyberSafe Browser SWB. b It should be noted that the CyberSafe Hub 52 and the CyberSafe Browser SWB 64 are described as being performed by one or the other of the CyberSafe Hub 52 and the CyberSafe Browser SWB 64. However, in accordance with an embodiment of the present disclosure, b Actions performed by one of the two may be performed by the other, or the CyberSafe Hub 52 and the browser SWB b may be performed by cooperating with each other.
[0081] In the specification and claims of this application, the verbs "comprise," "include," and "have," and their conjugations, are used to indicate that the subject(s) of the verb are not necessarily an exhaustive list of components, elements, or parts of the subject(s) of the verb.
[0082] The descriptions of embodiments of the present invention in this application are provided by way of example and are not intended to limit the scope of the present invention. The described embodiments comprise different features, not all of which are required in all embodiments of the present invention. Some embodiments utilize only some of the features or possible combinations of the features. Variations of the described embodiments of the present invention, and embodiments of the present invention including different combinations of the features described in the described embodiments, will occur to those skilled in the art. The scope of the present invention is limited only by the claims.
Claims
1. 1. A communications system for providing secure access to digital resources of a group of digital resources accessible via a communications network, comprising: a data processing hub accessible via an IP (Internet Protocol) address; and a plurality of user equipment (UE) devices usable for communication via said communications network, each UE configured to have a secure isolation environment isolated from ambient software within said UE and including a secure web browser (SWB), said hub and secure isolation environment configured such that digital resources in motion and at rest within the secure isolation environment are visible to said hub, said SWB obtaining security tokens for accessing one or more digital resources of an enterprise; Before the SWB obtains the security token, the hub is operative to examine ambient software included in the UE; examining the ambient software included in the UE includes determining a risk estimate for static vulnerability characteristics and / or dynamic vulnerability characteristics that characterize a current use of the UE; Communication system.
2. The communication system of claim 1 , wherein the secure isolated environment includes at least one software application wrapped to conform to security constraints defined by a security policy of the communication system.
3. The communication system of claim 2 , wherein the secure isolated environment includes at least one secure service application usable by the SWB and the at least one wrapped application.
4. The communication system of claim 3 , wherein the at least one secure service application includes a secure clipboard and a secure encrypted file system.
5. The communication system of claim 2 , wherein communication between applications within the secure isolated environment is via a secure encrypted communication channel.
6. The communication system of claim 2 , wherein communication between the SWB and applications in the secure isolated environment is via a secure encrypted communication channel.
7. The communication system of claim 1 , wherein communications sent from the SWB are visible to the hub before the SWB encrypts the communications.
8. The communication system of claim 1 , wherein a communication entering the SWB is visible to the hub after the SWB decodes the communication.
9. The communication system of claim 1 , wherein the SWB in a UE monitors communications of a user of the UE to obtain data characterizing the browsing behavior of the user and the websites the user visits.
10. The communication system of claim 9 , wherein the hub and / or the SWB processes the obtained data to determine typical patterns of the user's interaction with websites accessed by the user.
11. The communication system of claim 10 , wherein the hub and / or the SWB processes the acquired data to determine a risk of cyber damage to digital resources of the group of resources resulting from the user accessing the website.
12. The communication system of claim 11 , wherein the hub and / or the SWB configures a web browsing security policy to protect group resources in response to the determined risk.
13. The communication system of claim 12 , wherein the SWB monitors communications between the SWB and websites accessed by the SWB to enforce the web browsing security policy.
14. 13. The communication system of claim 12, wherein enforcing the web browsing security policy includes using the SWB to monitor the user's browsing behavior and identify anomalies in the browsing behavior in response to determined normal browsing behavior.
15. The communication system of claim 14 , wherein the anomaly comprises a violation of the determined normal browsing behavior and / or the web browsing security policy.
16. 2. The communication system of claim 1, wherein the hub is operative to examine software contained in the SWB before the SWB operates to request access to a resource of the group of resources.
17. 17. The communication system of claim 16, wherein examining the software includes performing a software integrity test on the software.
18. The communication system of claim 1 , further comprising determining a quality of integrity (QoI) of the ambient software.
Citation Information
Patent Citations
Vulnerability detection method, device and system
CN110489970A
Security management system, relay device, and program
JP2007272396A
User and Device Authentication in Enterprise Systems
JP2016526201A
A secure container platform for resource access and placement on unmanaged, non-secure devices
JP2018521431A
Communication system, control device, gateway, communication control method, and program
JP2019083478A