×

Threat detection using URL cache hits

  • US 9,419,989 B2
  • Filed: 12/15/2014
  • Issued: 08/16/2016
  • Est. Priority Date: 12/15/2014
  • Status: Active Grant
First Claim
Patent Images

1. A method comprising:

  • maintaining a uniform resource locator (URL) cache on each of a plurality of devices, the URL cache including a reputation score and a time to live for each of a plurality of URLs;

    updating the URL cache on each of the plurality of devices using reputation scores from a remote threat management facility to add new entries for new URL traffic to the URL cache and using the time to live to expire existing entries from the URL cache;

    monitoring the URL cache of each one of the plurality of devices with the remote threat management facility to detect a variance in one of the URL caches relative to each other one of the URL caches;

    triggering an indication of compromise based on the variance; and

    initiating a remedial action for the device storing the one of the URL caches in response to the indication of compromise.

View all claims
  • 4 Assignments
Timeline View
Assignment View
    ×
    ×