×

Threat detection using a time-based cache of reputation information on an enterprise endpoint

  • US 9,967,264 B2
  • Filed: 09/14/2014
  • Issued: 05/08/2018
  • Est. Priority Date: 09/14/2014
  • Status: Active Grant
First Claim
Patent Images

1. A method comprising:

  • detecting an action at an endpoint;

    transmitting a first indication of compromise from the endpoint to a remote threat management facility, the first indication of compromise including a description of the action, wherein the description of the action includes an identifier of a process, executing on the endpoint, that took the action, wherein the description of the action further includes a second identifier of an object programmatically associated with the process through the action;

    at the endpoint, receiving from the remote threat management facility a reputation score for the action and a time to live for the action, the reputation score based on the description of the action including the process and the object programmatically associated with the process through the action;

    caching the description and the reputation score in an event cache on the endpoint for a duration equal to the time to live;

    accumulating a plurality of the descriptions and reputation scores that have not expired in the event cache;

    expiring at least one of the descriptions and reputation scores by removing the at least one of the descriptions and reputation scores from the event cache after the time to live;

    generating a threat detection when a pattern of the descriptions and reputation scores in the event cache indicates malicious software operating on the endpoint; and

    communicating the threat detection to the threat management facility.

View all claims
  • 4 Assignments
Timeline View
Assignment View
    ×
    ×