US2022156399A1PendingUtilityA1
Chain of custody for enterprise documents
Est. expiryApr 13, 2038(~11.7 yrs left)· nominal 20-yr term from priority
G06F 16/122H04L 63/205H04L 9/3231H04L 9/3228H04L 2463/082H04L 63/0861H04L 9/3271H04L 63/20H04L 9/3265H04L 63/0807H04L 63/1441G06F 16/93H04L 63/0838G06F 16/285H04L 63/1416H04L 63/083G06F 21/64G06N 5/046H04L 41/22H04L 63/101G06N 3/0675G06N 20/00G06F 16/137H04L 63/102H04L 9/3226H04L 63/1408G06F 21/45G06N 5/048G06F 21/6218H04L 63/08H04L 9/3213H04L 63/1433H04L 63/1425H04L 41/20G06F 21/577G06F 2221/034H04L 9/0891H04L 9/16H04L 9/50
78
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A ledger stores chain of custody information for files throughout an enterprise network. By identifying files with a homologous identifier such as a fuzzy hash that permits piecewise evaluation of similarity, the ledger can be used to track a chain of custody over a sequence of changes in content, ownership, and file properties. The ledger can be used, e.g., to evaluate trustworthiness of a file the first time it is encountered by an endpoint, or to apply enterprise policies based on trust.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A computer program product comprising computer executable code embodied in a non-transitory computer readable medium that, when executing on one or more computing devices, performs the steps of:
storing a file on an endpoint generating a first fuzzy hash for the file, the first fuzzy hash providing a file identifier for the file based on a piecewise segment of the file; requesting, based on the first fuzzy hash, chain of custody information including at least a first user and a version for the file from a ledger that stores chain of custody information for files of an enterprise network; receiving a modification to the file from a second user of the file at an endpoint; generating a second fuzzy hash for the file in response to a security event detected on the endpoint and related to a use of the file; and transmitting the second fuzzy hash to the ledger for inclusion in a chain of custody stored in the ledger for the file, wherein data in the chain of custody includes indicia for the first user associated with the first fuzzy hash and indicia for the second user associated with the second fuzzy hash.
2 . The computer program product of claim 1 , wherein the security event includes a potential compromise detected for the endpoint.
3 . The computer program product of claim 1 , wherein the security event includes data leakage detected for the endpoint.
4 . The computer program product of claim 1 , wherein the ledger is stored in a database hosted at a threat management facility for the enterprise network.
5 . A method comprising:
receiving a file at an endpoint; receiving a modification to the file from a user of the file at the endpoint; generating a fuzzy hash for the file in response to a security event on the endpoint; and transmitting the fuzzy hash to a ledger for inclusion in a chain of custody for the file stored in the ledger, wherein data in the chain of custody includes indicia for one or more users associated with the file and one or more corresponding fuzzy hashes associated with one or more corresponding versions of the file.
6 . The method of claim 5 , further comprising requesting, based on a second fuzzy hash for the file, chain of custody information from the ledger including at least a previous user and a version for the file.
7 . The method of claim 5 , wherein the fuzzy hash provides a file identifier for the file based on a piecewise segment of the file.
8 . The method of claim 5 , wherein the ledger includes a remote ledger storing chain of custody information for files in an enterprise network associated with the endpoint.
9 . The method of claim 5 , wherein the security event is related to use of the file on the endpoint.
10 . The method of claim 5 , wherein the security event relates to storage of the file on the endpoint.
11 . The method of claim 5 , wherein the security event includes a potential compromise detected for the endpoint.
12 . The method of claim 5 , wherein the security event includes data leakage detected for the endpoint.
13 . The method of claim 5 , wherein the file includes a document selected from a group consisting of a word processing document, a spreadsheet, an image, an audio file, and a video file.
14 . The method of claim 5 , wherein the ledger is stored in one or more of a database hosted at a threat management facility for an enterprise network, and a cloud resource remotely accessible from the enterprise network.
15 . The method of claim 5 , wherein chain of custody information includes an author and one or more users associated with a number of versions of the file.
16 . The method of claim 5 , wherein chain of custody information includes at least one item that is cryptographically signed for authentication using a certificate from a trust authority.
17 . The method of claim 5 , further comprising receiving a modification to the file at the endpoint, generating a second fuzzy hash for the file, and transmitting the second fuzzy hash to the ledger for inclusion in a chain of custody for the file.
18 . The method of claim 5 , further comprising applying an enterprise policy from a threat management facility to block or allow access to the file at the endpoint in response to the fuzzy hash.
19 . The method of claim 18 , wherein applying the enterprise policy includes controlling a transmittal of the file through an enterprise network managed by the threat management facility.
20 . A system comprising:
a plurality of endpoints storing a plurality of documents; an enterprise network interconnecting the plurality of endpoints; and a server coupled in a communicating relationship with the enterprise network, the server hosting a threat management facility, and the server storing a ledger with a chain of custody for each of the plurality of documents, the chain of custody for each one of the plurality of documents including one or more fuzzy hashes, each associated with users of the one of the plurality of documents and contents of the one of the plurality of documents, the server configured to respond to an information request containing a first fuzzy hash by matching the first fuzzy hash to one or more of the fuzzy hashes stored in the ledger and providing chain of custody information including a first user for the one of the plurality of documents to a requestor for at least one of the plurality of documents corresponding to the one or more of the fuzzy hashes, the server further configured to respond to an security request containing a second fuzzy hash generated in response to a security event on one of the endpoints by initiating a remedial action relating to a corresponding on of the plurality of documents with the threat management facility.Join the waitlist — get patent alerts
Track US2022156399A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.