×

Communication-based host reputation system

  • US 8,381,289 B1
  • Filed: 03/31/2009
  • Issued: 02/19/2013
  • Est. Priority Date: 03/31/2009
  • Status: Active Grant
First Claim
Patent Images

1. A computer system for generating a host reputation score for a host connected to a network, the computer system comprising:

  • a memory;

    a processor;

    a reporting module stored on the memory and executable by the processor to;

    receive information identifying a plurality of hosts connected to the network and information describing communications between a plurality of entities executing on a plurality of clients and the plurality of hosts;

    receive information identifying one or more of the plurality of entities executing on the plurality of clients as malware threats; and

    provide generated host reputation scores to the plurality of clients; and

    a host reputation module stored on the memory and executable by the processor to;

    identify malware entities executing onthe plurality of clients thatcommunicate with the host based at least on the informationidentifying the plurality of hosts, the information describingcommunications between the plurality of entities executing on theplurality of clients and the plurality of hosts, and the informationidentifying one or more of the plurality of entities as malware threats;

    determine a number of the malware entities executing on the plurality ofclients that communicate with the host; and

    generate the host reputation score for the host based at least on thenumber of the malware entities executing on the plurality of clientsthat communicate with the hostwherein the host reputationscore for the host indicates a likelihood that the host is malicious.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×