PREDICTIVE SCORING MANAGEMENT SYSTEM FOR APPLICATION BEHAVIOR
First Claim
1. A method, comprising:
- receiving, by a server, information regarding known epitypes of malness, where the information includes malness scores and behaviors for the known epitypes of malness;
storing, by the server, the information regarding the known epitypes of malness;
building, by the server, a model based on the information regarding the known epitypes of malness stored by the server;
receiving, by the server, applications from a device for use with the model;
generating, by the server, malness scores for one or more of the applications using the data from the one or more applications in combination with the model; and
allowing one or more of the applications and/or the device to access a network when the malness scores for one or more of the applications is below a first threshold level or blocking one or more of the applications and/or the device from accessing the network when the malness score for one or more of the applications is above a second threshold level, where the first threshold level is less than the second threshold level.
1 Assignment
0 Petitions
Accused Products
Abstract
A system may be provided that comprises one or more servers to: receive information regarding known epitypes of malness, where the information includes malness scores and behaviors for the known epitypes of malness; store the information regarding the known epitypes of malness; generate rules for a model based on the information regarding the known epitypes of malness; input application data from an application on a device into the model; output a malness score from the model based on the application data; and allow the application and/or the device access to a network when the malness scores for the application is below a first threshold level, or block the application and/or the device access to the network when the malness score the application is above a second threshold level, where the first threshold level is less than the second threshold level.
77 Citations
20 Claims
-
1. A method, comprising:
-
receiving, by a server, information regarding known epitypes of malness, where the information includes malness scores and behaviors for the known epitypes of malness; storing, by the server, the information regarding the known epitypes of malness; building, by the server, a model based on the information regarding the known epitypes of malness stored by the server; receiving, by the server, applications from a device for use with the model; generating, by the server, malness scores for one or more of the applications using the data from the one or more applications in combination with the model; and allowing one or more of the applications and/or the device to access a network when the malness scores for one or more of the applications is below a first threshold level or blocking one or more of the applications and/or the device from accessing the network when the malness score for one or more of the applications is above a second threshold level, where the first threshold level is less than the second threshold level. - View Dependent Claims (2, 3, 4, 5, 6, 7)
-
-
8. A system, comprising:
one or more servers to; receive information regarding known epitypes of malness, where the information includes malness scores and behaviors for the known epitypes of malness; store the information regarding the known epitypes of malness; generate rules for a model based on the information regarding the known epitypes of malness; input application data from an application on a device into the model; output a malness score from the model based on the application data; and allow the application and/or the device access to a network when the malness scores for the application is below a first threshold level, or block the application and/or the device access to the network when the malness score the application is above a second threshold level, where the first threshold level is less than the second threshold level. - View Dependent Claims (9, 10, 11, 12, 13, 14)
-
15. A system, comprising:
-
an epitype storage server that receives information regarding known epitypes of malness, where the epitype storage server stores the information regarding known epitypes of malness, where the information includes malness scores and behaviors for the known epitypes of malness; a malness analysis server that builds a model based on the information regarding the known epitypes of malness stored by the epitype storage server; and a scoring engine server that uploads the model, where the scoring engine server receives applications from a list for malness scoring and generates a malness score for each of the applications using the model and data from the applications, where the scoring engine server; allows access to a network for one or more of the applications and/or the device with the one or more applications when the malness scores for one or more of the applications is below a first threshold level, or blocks access to the network for one or more of the applications and/or the device with the one or more applications when the malness score for one or more of the applications is above a second threshold level, where the first threshold level is less than the second threshold level. - View Dependent Claims (16, 17, 18, 19, 20)
-
Specification