×

Threat detection using reputation data

  • US 9,740,859 B2
  • Filed: 08/12/2016
  • Issued: 08/22/2017
  • Est. Priority Date: 12/15/2014
  • Status: Active Grant
First Claim
Patent Images

1. A method comprising:

  • maintaining reputation data in a memory on each of a plurality of devices, the reputation data for one of the plurality of devices including a reputation score and a time to live for each of a plurality of executables executed by the one of the plurality of devices;

    updating the reputation data on each of the plurality of devices, wherein updating the reputation data includes adding new entries for new executables executed by a respective one of the plurality of devices using reputation scores from a remote threat management facility and wherein updating the reputation data further includes deleting one or more existing entries from the reputation data using the time to live to expire the existing entries from the reputation data;

    monitoring, with the remote threat management facility, each one of the plurality of devices to detect, based on the reputation data on each of the devices, a variance in access to one or more of the plurality of executables relative to access to the one or more of the plurality of executables on each other one of the plurality of devices;

    triggering an indication of compromise based on the variance in access to one or more of the plurality of executables; and

    for the device from the plurality of devices corresponding to the indication of compromise based on the variance in access to one or more of the plurality of executables, initiating a remedial action in response to the indication of compromise.

View all claims
  • 4 Assignments
Timeline View
Assignment View
    ×
    ×