IP Library Granted Patent US 9,419,990
Granted Patent B2
US 9,419,990 · App. 13/754,810 · Granted Aug 16, 2016

Apparatus and method for characterizing the risk of a user contracting malicious software

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,419,990
App. No.
13/754,810
Granted
Aug 16, 2016
Kind
B2
Abstract

A non-transitory computer readable storage medium includes executable instructions to identify specified network interactions initiated by a client machine. The specified network interactions are compared to normative values to produce a promiscuity score indicative of the risk of the client machine contracting malicious software. Depending upon the promiscuity score, prophylactic actions are optionally applied to the client machine.

Claims (21)

1. A server, comprising:

a processor; and

a memory storing a scoring module with instructions executed by a processor to:

identify specified network interactions, wherein the specified network interactions include a client machine initiating connections to network endpoints; and

evaluate a statistical deviation of the specified network interactions relative to a normative value for the client machine to produce a promiscuity score indicative of a risk of the client machine contracting malicious software, wherein the specified network interactions include:

a host communication count during a specified time period and the normative value is a mean host communication count;

evaluations of accessed servers with respect to normative values for low risk server countries and Uniform Resource Locator character distribution;

evaluations of domain name system queries against normative values for combinations or distributions of characters in a domain name system query and the number of IP addresses a domain name system query resolves to;

evaluations of executable file transfers against a white list of permissible executable files;

evaluations of excessive server message block connections; and

evaluations of the number of Hypertext Transfer Protocol (HTTP) posts and the data set size of HTTP posts.

2. The server of claim 1 further comprising executable instructions stored in the memory and executable by the processor to apply a prophylactic action to the client machine.

3. The server of claim 2 , wherein the prophylactic action is installing anti-virus software on the client machine.

4. The server of claim 2 , wherein the prophylactic action is isolating the client machine with a firewall.

5. The server of claim 2 , wherein the prophylactic action is automatically remediating an infection.

6. The server of claim 2 , wherein the prophylactic action is delivering an alert to an administrator.

7. The server of claim 1 , wherein the client machine is selected from the group consisting of a personal computer, a tablet, and smart phone, and a personal digital assistant.

8. The server of claim 1 , wherein the host communication count is a total number of unique endpoints the client machine communicates with.

9. The server of claim 1 , wherein the host communication count is a total number of connections made the client machine with a specific endpoint.

10. The server of claim 1 , wherein the host communication count is a combination of a total number of unique endpoints the client machine communicates with and a total number of connections made by the client machine with a specific endpoint.

11. The server of claim 1 , wherein the specified network interactions include evaluations of SSL and TLS sessions.

Assignments (10)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2019
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 051144/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 27, 2016
From: BLUE COAT SYSTEMS, INC.
To: SYMANTEC CORPORATION
Reel/Frame 039851/0044 →
RELEASE OF SECURITY INTEREST Recorded Aug 1, 2016
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 039516/0929 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 30747/0452 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC., AS SUCCESSOR BY MERGER TO SOLERA NETWORKS, INC.
Reel/Frame 035797/0332 →
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 30521/0379 Recorded May 29, 2015
From: JEFFERIES FINANCE LLC
To: BLUE COAT SYSTEMS, INC., AS SUCCESSOR BY MERGER TO SOLERA NETWORKS, INC.
Reel/Frame 035797/0899 →
SECURITY INTEREST Recorded May 22, 2015
From: BLUE COAT SYSTEMS, INC.
To: JEFFERIES FINANCE LLC, AS THE COLLATERAL AGENT
Reel/Frame 035751/0348 →
MERGER Recorded Feb 10, 2014
From: SOLERA NETWORKS, INC.
To: BLUE COAT SYSTEMS, INC.
Reel/Frame 032188/0063 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Jul 3, 2013
From: SOLERA NETWORKS, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 030747/0452 →
PATENT SECURITY AGREEMENT Recorded May 31, 2013
From: SOLERA NETWORKS, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 030521/0379 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 30, 2013
From: LEVY, JOSEPH H.; WOOD, MATTHEW S.
To: SOLERA NETWORKS, INC.
Reel/Frame 029726/0895 →