US2012158953A1PendingUtilityA1

Systems and methods for monitoring and mitigating information leaks

Assignee: BARNES RICHARD LEEPriority: Dec 21, 2010Filed: Apr 11, 2011Published: Jun 21, 2012
Est. expiryDec 21, 2030(~4.4 yrs left)· nominal 20-yr term from priority
H04L 63/04H04L 63/1433G06F 21/60
41
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems and methods are disclosed for determining whether a third party observer could determine that an organization has an intent with respect to subject matter based on the organization's web activity. The determination that there is a risk of information leaks to the third party observer can be completed by analyzing the entropy of web usage information destined for the third party observer's servers. Systems and methods are also disclosed for mitigating the risk of information leaks by obscuring the organization's web activity. The web activity can be obscured by selecting candidate actions that can be used to generate neutralizing web traffic from the organization's network which will obscure an intent the organization has with respect to a particular subject matter. For example, the candidate actions can identify specific queries, links, or actions that the organization can take to neutralize their web activity to a less remarkable point in the search space.

Claims

exact text as granted — not AI-modified
1 . A method for determining whether a third party observer could determine that an organization has an intent with respect to subject matter, the method comprising:
 collecting data in transit between the group of users and Internet-connected elements associated with a plurality of third party observers;   extracting metadata from the collected data;   processing the extracted metadata to identify information each of the plurality of third party observers has received from the organization; and   determining, based on the processed extracted metadata, that at least one of the third party observers has received sufficient information from the organization to determine that the organization has an intent with respect to a particular subject matter.   
     
     
         2 . The method of  claim 1 , wherein the data in transit is collected from a position in the network where network communications are consolidated. 
     
     
         3 . The method of  claim 1 , further comprising:
 incrementing a value of a counter of a plurality of counters based on the extracted metadata, wherein each of the plurality of counters is associated with each of the plurality of third party observers, and wherein the determination that the at least one third party observer has received sufficient information to determine that the organization has an intent with respect to a particular subject matter is based on the relative values of the plurality of counters.   
     
     
         4 . The method of  claim 1 , further comprising:
 determining, based on the extracted metadata, what information the at least one third party observer has acquired about the group of users.   
     
     
         5 . The method of  claim 1 , further comprising:
 identifying the at least one third party observer based on the extracted metadata.   
     
     
         6 . The method of  claim 1 , further comprising:
 generating an entropy graph based on the extracted metadata, wherein the determination that the at least one third party observer has received sufficient information to determine that the organization has an intent with respect to a particular subject matter is based on peaks in the entropy graph.   
     
     
         7 . The method of  claim 1 , wherein the determination that the at least one third party observer has received sufficient information to determine that the organization has an intent with respect to a particular subject matter is based on distance metrics that are calculated with respect to the extracted metadata. 
     
     
         8 . The method of  claim 1 , wherein the extracted metadata includes at least one of HTTP cookies, HTML meta tags, the times at which application transactions occur, URLs that are accessed, IP addresses, and MAC addresses. 
     
     
         9 . A system for determining whether a third party observer could determine that an organization has an intent with respect to subject matter, the system comprising:
 metadata extracting circuitry configured to:
 collect data in transit between the group of users and Internet-connected elements associated with a plurality of third party observers, and 
 a extract metadata from the collected data; and 
   privacy analyzing circuitry configured to:
 processing the extracted metadata to identify information each of the plurality of third party observers has received from the organization; and 
 determine, based on the processed extracted metadata, that at least one of the third party observers has received sufficient information from the organization to determine that the organization has an intent with respect to a particular subject matter. 
   
     
     
         10 . The system of  claim 9 , wherein the metadata extractor is positioned within the network at a point where network communications are consolidated. 
     
     
         11 . The system of  claim 9 , wherein the privacy analyzing circuitry is further configured to:
 maintain a plurality of counters associated with each of the plurality of third party observers, and   increment a value of a respective counter of the plurality of counters based on the extracted metadata, wherein the determination that the at least one third party observer has received sufficient information to determine that the organization has an intent with respect to a particular subject matter is based on the relative values of the plurality of counters.   
     
     
         12 . The system of  claim 9 , wherein the privacy analyzing circuitry is further configured to determine, based on the extracted metadata, what information the at least one third party observer has acquired about the group of users. 
     
     
         13 . The system of  claim 9 , wherein the privacy analyzing circuitry is further configured to identify the at least one third party observer based on the extracted metadata. 
     
     
         14 . The system of  claim 9 , wherein the privacy analyzing circuitry is further configured to generate an entropy graph based on the extracted metadata, wherein the determination that the at least one third party observer has received sufficient information to determine that the organization has an intent with respect to a particular subject matter is based on peaks in the entropy graph. 
     
     
         15 . The system of  claim 9 , wherein the determination that the at least one third party observer has received sufficient information to determine that the organization has an intent with respect to a particular subject matter is based on distance metrics that are calculated with respect to the extracted metadata. 
     
     
         16 . The system of  claim 9 , wherein the extracted metadata includes at least one of HTTP cookies, HTML meta tags, the times at which application transactions occur, URLs that are accessed, IP addresses, and MAC addresses. 
     
     
         17 . A computer readable medium storing computer executable instructions, which, when executed by a processor, cause the processor to carryout a method for determining whether a third party observer could determine that an organization has an intent with respect to subject matter, the computer readable medium comprising:
 collecting data in transit between the group of users and Internet-connected elements associated with a plurality of third party observers;   extracting metadata from the collected data;   processing the extracted metadata to identify information each of the plurality of third party observers has received from the organization; and   determining, based on the processed extracted metadata, that at least one of the third party observers has received sufficient information from the organization to determine that the organization has an intent with respect to a particular subject matter.   
     
     
         18 . A method for obscuring an existence of an intent of an organization with respect to subject matter, the method comprising:
 generating an organization's similarity matrix based on the organization's web usage information;   providing a desired similarity matrix that meets an obfuscation constraint;   generating a distance matrix based on the organization's similarity matrix and the desired similarity matrix;   selecting a candidate action from a plurality of candidate actions based on the distance matrix, wherein the selected candidate action includes web behaviors that would make the organization's similarity matrix more similar the desired similarity matrix;   modifying the organization's similarity matrix based on the candidate action; and   determining whether the modified organization's similarity matrix meets the obfuscation constraint.   
     
     
         19 . The method of  claim 18 , further comprising iterating the selecting the candidate action and modifying the organization's similarity matrix until the modified organization's similarity matrix meets the obfuscation constraint. 
     
     
         20 . The method of  claim 18 , further comprising iterating the selecting the candidate action and modifying the organization's similarity matrix until the number of iterations reaches a maximum number of iterations. 
     
     
         21 . The method of  claim 18 , wherein the candidate action is selected based on a gradient descent calculation on the distance matrix. 
     
     
         22 . The method of  claim 18 , further comprising:
 generating neutralizing web activity based on the selected candidate action.   
     
     
         23 . The method of  claim 22 , wherein the candidate action includes a website and a behavior to perform on the website and the generated web activity is based on the performance of the behavior. 
     
     
         24 . The method of  claim 22 , wherein the web activity is generated with a spoofed address associated with a user in the organization. 
     
     
         25 . The method of  claim 18 , wherein the obfuscation constraint sets a maximum similarity index value for the organization's similarity matrix. 
     
     
         26 . A system for obscuring an existence of an intent of an organization with respect to subject matter, the system comprising:
 obfuscating circuitry configured to:
 generate an organization's similarity matrix based on the organization's web usage information; 
 provide a desired similarity matrix that meets a obfuscation constraint; 
 generate a distance matrix based on the organization's similarity matrix and the desired similarity matrix; 
 select a candidate action from a plurality of candidate actions based on the distance matrix, wherein the selected candidate action includes web behaviors that would make the organization's similarity matrix more similar the desired similarity matrix; 
 modify the organization's similarity matrix based on the candidate action; and 
   determine whether the modified organization's similarity matrix meets the obfuscation constraint.   
     
     
         27 . The system of  claim 26 , wherein the obfuscating circuitry is further configured to iterate the selecting the candidate action and modifying the organization's similarity matrix until the modified organization's similarity matrix meets the obfuscation constraint. 
     
     
         28 . The system of  claim 26 , wherein the obfuscating circuitry is further configured to iterate the selecting the candidate action and modifying the organization's similarity matrix until the number of iterations reaches a maximum number of iterations. 
     
     
         29 . The system of  claim 26 , wherein the candidate action is selected based on a gradient descent calculation on the distance matrix. 
     
     
         30 . The system of  claim 26 , wherein the obfuscating circuitry is further configured to generate neutralizing web activity based on the selected candidate action. 
     
     
         31 . The system of  claim 30 , wherein the candidate action includes a website and a behavior to perform on the website and the generated web activity is based on the performance of the behavior. 
     
     
         32 . The system of  claim 30 , wherein the web activity is generated with a spoofed address associated with a user in the organization. 
     
     
         33 . The system of  claim 26 , wherein the obfuscation constraint sets a maximum similarity index value for the organization's similarity matrix. 
     
     
         34 . A computer readable medium storing computer executable instructions, which, when executed by a processor, cause the processor to carryout a method for obscuring an existence of an intent of an organization with respect to subject matter, the computer readable medium comprising:
 generating an organization's similarity matrix based on the organization's web usage information;   providing a desired similarity matrix that meets a obfuscation constraint;   generating a distance matrix based on the organization's similarity matrix and the desired similarity matrix;   selecting a candidate action from a plurality of candidate actions based on the distance matrix, wherein the selected candidate action includes web behaviors that would make the organization's similarity matrix more similar the desired similarity matrix;   modifying the organization's similarity matrix based on the candidate action; and   determining whether the modified organization's similarity matrix meets the obfuscation constraint.

Join the waitlist — get patent alerts

Track US2012158953A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.