首页> 外国专利> AGENT ASSISTED MALICIOUS APPLICATION BLOCKING IN A NETWORK ENVIRONMENT

AGENT ASSISTED MALICIOUS APPLICATION BLOCKING IN A NETWORK ENVIRONMENT

机译:网络环境中的Agent辅助恶意应用程序阻止

摘要

Embodiments are configured to receive metadata of a process intercepted on an end host when attempting to access a network. The metadata includes a hash of an application associated with the process and an endpoint reputation score of the application. Embodiments are configured to request a threat intelligence reputation score based on the hash of the application, to determine an action to be taken by the end host based, at least in part, on one or more policies and at least one of the threat intelligence reputation score and the endpoint reputation score, and to send a response indicating the action to be taken by the end host. Further embodiments request another threat intelligence reputation score based on another hash of a dynamic link library module loaded by the process on the end host, and the action is determined based, at least in part, on the other threat intelligence score.
机译:实施例被配置为在尝试访问网络时接收在终端主机上截获的过程的元数据。元数据包括与该流程相关联的应用程序的哈希值和该应用程序的端点信誉得分。实施例被配置为基于应用的哈希来请求威胁情报信誉分数,以至少部分地基于一种或多种策略以及威胁情报信誉中的至少一个来确定最终主机要采取的动作。分数和端点信誉分数,并发送响应以指示最终主机要采取的操作。进一步的实施例基于该过程在终端主机上加载的动态链接库模块的另一个哈希来请求另一个威胁情报信誉分数,并且至少部分地基于另一个威胁情报分数来确定动作。

著录项

  • 公开/公告号US2020228546A1

    专利类型

  • 公开/公告日2020-07-16

    原文格式PDF

  • 申请/专利权人 MCAFEE LLC;

    申请/专利号US202016834643

  • 发明设计人 CHANDAN CP;SRINIVASAN NARASIMHAN;

    申请日2020-03-30

  • 分类号H04L29/06;G06F21/55;G06F21/56;

  • 国家 US

  • 入库时间 2022-08-21 11:24:57

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号