×

System and method of protecting client computers

  • US 10,223,530 B2
  • Filed: 11/13/2013
  • Issued: 03/05/2019
  • Est. Priority Date: 11/13/2013
  • Status: Active Grant
First Claim
Patent Images

1. A method of providing security for a plurality of client computers, the method comprising:

  • receiving, by a threat response computer, an event report identifying possible malware on a first client computer;

    receiving, by the threat response computer, a first set of data from a detection program running on the first client computer, said data reflecting the state of the first client computer by including at least one of registry entries, files, mutexes, open connections, or processes running on the first client computer;

    automatically analyzing the first set of data based on a set of known actual indications of compromise (IOCs) related to the possible malware, said actual IOCs containing data that identify changes to a computer that has been infected with malware comprising changed or added files, changed or added registry entries, mutexes, processes, or open connections;

    receiving a second set of data from a second client computer;

    updating the set of known actual IOCs with information that may be used to identify when malware has been executed on the first client computer, wherein updating the set of known actual IOCs comprises analyzing the second set of data and re-weighting the known actual IOCs found in both the first set of data and the second set of data;

    automatically re-analyzing the first set of data based on the update;

    performing at least one of presenting the re-analysis to a user; and

    configuring a firewall in response to the re-analysis indicating that the first client has been infected with malware.

View all claims
  • 5 Assignments
Timeline View
Assignment View
    ×
    ×