Patent · US Active

Identifying application reputation based on resource accesses

US9065826B2 · kind B2 · utility

29Cited by
45References
20Claims
0Family size

Assignee

Inventors

Key dates

Filing dateAug 8, 2011
Grant dateJun 23, 2015
Priority date
Expiry dateMar 31, 2033

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F2221/2141
  • WIPO fieldDigital communication
  • WIPO sectorElectrical engineering

Abstract

Malware detection is often based on monitoring a local application binary and/or process, such as detecting patterns of malicious code, unusual local resource utilization, or suspicious application behavior. However, the volume of available software, variety of malware, and sophistication of evasion techniques may reduce the effectiveness of detection based on monitoring local resources. Presented herein are techniques for identifying malware based on the reputations of remote resources (e.g., web content, files, databases, IP addresses, services, and users) accessed by an application. Remote resource accesses may be reported to a reputation service, which may identify reputations of remote resources, and application reputations of applications that utilize such remote resources. These application reputations may be used to adjust the application policies of the applications executed by devices and servers. These techniques thereby achieve rapid detection and mitigation of newly identified malware through application telemetry in a predominantly automated manner.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.