IP Library Granted Patent US 8,332,947
Granted Patent B1
US 8,332,947 · App. 11/426,917 · Granted Dec 11, 2012

Security threat reporting in light of local security tools

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,332,947
App. No.
11/426,917
Granted
Dec 11, 2012
Kind
B1
Abstract

When a client receives a potential threat source (PTS), a user of the client may desire to make an informed decision regarding the PTS. The PTS can be, for example, an email or instant message with an embedded executable, a link to a network destination (e.g., included in search engine results or an email, or webpage), or an executable file (e.g., downloaded from a website). The PTS is identified and characterized to establish a threat rating. The threat rating can then be presented to the user, so as to inform the user as to the PTS riskiness. The threat rating is determined in light of the local security tools available. If there are no local security tools that mitigate the threat of the PTS, then a security tool that is known to mitigate the threat can be identified and recommended to the user.

Claims (62)

1. A computer implemented method for threat reporting in light of local security tools, comprising:

using a computer to perform steps comprising:

identifying a network link identifying a web site that is a potential threat source (PTS) for the computer;

determining a plurality of security threats associated with the PTS, wherein the plurality of security threats are associated with characteristics of the web site identified by the network link;

determining an initial threat rating for the PTS based on the plurality of security threats associated with the PTS;

identifying mitigated security threats of the plurality of security threats that are mitigated by local security on the computer and unmitigated security threats of the plurality of security threats that are not mitigated by local security on the computer;

adjusting the initial threat rating for the PTS to account for the mitigated security threats and the unmitigated security threats to produce an adjusted threat rating based on the unmitigated security threats; and

providing the adjusted threat rating to a user of the computer.

2. The method of claim 1 further comprising:

identifying one or more characteristics of the web site, the characteristics selected from the set consisting of: a frequency with which the computer has visited the web site, whether a previous visit to the web site had a negative impact on the computer, a type of negative impact on the computer resulting from a previous visit to the web site, and a source of the network link identifying the web site; and

determining threat weights associated with unmitigated ones of the identified characteristics;

wherein the adjusted threat rating of the PTS is determined based at least in part on the threat weights of the unmitigated characteristics of the web site.

3. The method of claim 2 , further comprising:

normalizing a sum of the threat weights associated with the unmitigated characteristics of the web site to produce the threat adjusted rating.

4. The method of claim 1 further comprising:

automatically determining one or more security tools that would mitigate one or more of the unmitigated security threats.

5. The method of claim 4 further comprising:

automatically suggesting procurement of the one or more security tools to the user to improve the adjusted threat rating.

6. The method of claim 1 further comprising:

automatically suggesting procurement of security tools to the user that would lower the adjusted threat rating.

7. The method of claim 1 wherein providing the adjusted threat rating to the user includes providing a graphical indicator.

8. The method of claim 1 , further comprising:

determining whether one or more of the plurality of security threats associated with characteristics of the web site identified by the network link are mitigated by security settings of a web browser used by the user to access web sites from the computer, wherein a security threat associated with a characteristic of the web site is designated a mitigated threat if it is mitigated by the security settings of the web browser.

9. The method of claim 1 , wherein the network link is presented to the user on a web page, and wherein the adjusted threat rating is provided to the user of the computer in association with the presentation of the network link on the web page.

10. The method of claim 9 , wherein the adjusted threat rating is provided to the user as a pop-up message.

11. A non-transitory computer-readable storage medium encoded with instructions, that when executed by one or more processors, cause the processors to carry out a process for threat reporting in light of local security tools, the process comprising:

identifying a network link identifying a web site that is a potential threat source (PTS) for a computer;

determining a plurality of security threats associated with the PTS, wherein the plurality of security threats are associated with characteristics of the web site identified by the network link;

determining an initial threat rating for the PTS based on the plurality of security threats associated with the PTS;

identifying mitigated security threats of the plurality of security threats that are mitigated by local security on the computer and unmitigated security threats of the plurality of security threats that are not mitigated by local security on the computer;

adjusting the initial threat rating for the PTS to account for the mitigated security threats and the unmitigated security threats to produce an adjusted threat rating based on the unmitigated security threats; and

providing the adjusted threat rating to a user of the computer.

12. The computer-readable storage medium of claim 11 , the process further comprising:

identifying one or more characteristics of the web site, the characteristics selected from the set consisting of: a frequency with which the computer has visited the web site, whether a previous visit to the web site had a negative impact on the computer, a type of negative impact on the computer resulting from a previous visit to the web site, and a source of the network link identifying the web site; and

determining threat weights associated with unmitigated ones of the identified characteristics;

wherein the adjusted threat rating of the PTS is determined based at least in part on the threat weights of the unmitigated characteristics of the web site.

13. The computer-readable storage medium of claim 11 , the process further comprising:

automatically determining one or more security tools that would mitigate one or more of the unmitigated security threats.

14. The computer-readable storage medium of claim 13 , the process further comprising:

automatically suggesting procurement of the one or more security tools to the user to improve the adjusted threat rating.

15. The computer-readable storage medium of claim 11 , the process further comprising:

automatically suggesting procurement of security tools to the user that would lower the adjusted threat rating.

16. A system for threat reporting in light of local security tools, comprising:

a non-transitory computer-readable storage medium encoded with executable instructions for:

identifying a network link identifying a web site that is a potential threat source (PTS) for a computer;

determining a plurality of security threats associated with the PTS, wherein the plurality of security threats are associated with characteristics of the web site identified by the network link;

determining an initial threat rating for the PTS based on the plurality of security threats associated with the PTS;

identifying mitigated security threats of the plurality of security threats that are mitigated by local security on the computer;

identifying unmitigated security threats of the plurality of security threats that are not mitigated by local security on the computer;

adjusting the initial threat rating for the PTS to account for the mitigated security threats and the unmitigated security threats to produce an adjusted threat rating based on the unmitigated security threats; and

providing the adjusted threat rating to a user of the computer; and

a processor for executing the instructions.

17. The system of claim 16 further comprising instructions for:

identifying one or more characteristics of the web site, the characteristics selected from the set consisting of: a frequency with which the computer has visited the web site, whether a previous visit to the web site had a negative impact on the computer, a type of negative impact on the computer resulting from a previous visit to the web site, and a source of the network link identifying the web site; and

determining threat weights associated with unmitigated ones of the identified characteristics;

wherein the adjusted threat rating of the PTS is determined based at least in part on the threat weights of the unmitigated characteristics of the web site.

18. The system of claim 16 further comprising instructions for:

automatically determining one or more security tools that would mitigate one or more of the unmitigated security threats.

19. The system of claim 18 further comprising instructions for:

automatically suggesting procurement of the one or more security tools to the user to improve the adjusted threat rating.

20. The system of claim 16 further comprising instructions for:

automatically suggesting procurement of security tools to the user that would lower the adjusted threat rating.

Assignments (5)
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
CHANGE OF NAME Recorded Jun 18, 2020
From: SYMANTEC CORPORATION
To: NORTONLIFELOCK INC.
Reel/Frame 053306/0878 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 27, 2006
From: BREGMAN, MARK; SOBEL, WILLIAM E.
To: SYMANTEC CORPORATION
Reel/Frame 017853/0133 →