Reputation of network address
First Claim
Patent Images
1. A computing system comprising:
- at least one hardware processor; and
at least one application executable on the at least one hardware processor to;
monitor, during a first time period, events associated with a network address to obtain event information;
determine a first reputation score of the network address based on the event information, wherein the first reputation score is associated with the first time period; and
determine a second reputation score of the network address based on the first reputation score, trend information associated with the first reputation score, and a portion of the event information corresponding to a second time period, wherein the second reputation score is associated with the second time period, and wherein the second time period is a portion of the first time period, wherein the trend information includes a slope associated with multiple historical points, wherein the multiple historical points are associated with the first reputation score.
13 Assignments
0 Petitions
Accused Products
Abstract
Example embodiments disclosed herein relate to determining a reputation of a network address. A long-term reputation of the network address is determined. A short-term reputation of the network address is determined based on the long-term reputation and trend information associated with the long-term reputation.
-
Citations
18 Claims
-
1. A computing system comprising:
-
at least one hardware processor; and at least one application executable on the at least one hardware processor to; monitor, during a first time period, events associated with a network address to obtain event information; determine a first reputation score of the network address based on the event information, wherein the first reputation score is associated with the first time period; and determine a second reputation score of the network address based on the first reputation score, trend information associated with the first reputation score, and a portion of the event information corresponding to a second time period, wherein the second reputation score is associated with the second time period, and wherein the second time period is a portion of the first time period, wherein the trend information includes a slope associated with multiple historical points, wherein the multiple historical points are associated with the first reputation score. - View Dependent Claims (2, 3, 4, 5, 6, 7)
-
-
8. A non-transitory machine-readable storage medium storing instructions that, if executed by at least one processor of a device, cause the device to:
-
monitor, during a first time period, one or more events associated with a network address to generate event information; determine a first reputation score of the network address based on the event information, wherein the first reputation score is associated with the first time period; and determine a second reputation score of the network address based on the first reputation score, trend information associated with the first reputation score, and a recent portion of the event information corresponding to a second time period, wherein the trend information includes a slope associated with multiple historical points, wherein the multiple historical points are associated with the first reputation score, wherein the second reputation score is associated with the second time period, and wherein the second time period is a portion of the first time period. - View Dependent Claims (9, 10, 11, 12, 13)
-
-
14. A method comprising:
-
monitoring, during a first time period, one or more events associated with a network address to generate event information; determining a first reputation score of the network address based on the event information, wherein the first reputation score is associated with a first time period; and determining, at a processor, a second reputation score of the network address based on the first reputation score, trend information associated with the first reputation score, and a recent portion of the event information corresponding to a second time period, wherein the second reputation score is associated with the second time period, wherein the second time period is a portion of the first time period, wherein the trend information includes a slope associated with multiple historical points, wherein the multiple historical points are associated with the first reputation score; and
updating the first reputation score based on the second reputation score. - View Dependent Claims (15, 16, 17, 18)
-
Specification