IP Library Granted Patent US 10,404,733
Granted Patent B1
US 10,404,733 · App. 15/013,893 · Granted Sep 3, 2019

Active push-based remediation for reputation-based security systems

Inventor: Michael Shavell (Merrimack, NH)
Assignee: Symantec Corporation
H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,404,733
App. No.
15/013,893
Granted
Sep 3, 2019
Kind
B1
Abstract

The present disclosure relates to initiating remediation of security risks on an endpoint system based on updated reputation data. According to one embodiment, a reputation service receives a request, from a first endpoint system, for reputation data about an object. A reputation service transmits, in response to the request, data indicating a current reputation of the object. The reputation service determines that the object presents a security risk and updates reputation data associated with the object to indicate that the object presents a security risk. Upon updating the reputation data, the reputation system transmits, to the first endpoint system, updated reputation data associated with the object and instructions to remedy the security risk.

Claims (57)

1. A method for initiating remediation of security risks on an endpoint system based on updated reputation data, comprising:

receiving a request, from a first endpoint system, for reputation data about an object;

transmitting, to the first endpoint system in response to the request, current reputation data associated with the object;

after transmitting the data indicating the current reputation data associated with the object in response to the request, determining that the object presents a security risk without receiving a subsequent request for reputation data about the object from the first endpoint system;

updating reputation data associated with the object to indicate that the object presents a security risk; and

asynchronously initiating remediation of the security risk at the first endpoint system by pushing, to the first endpoint system, the updated reputation data associated with the object and instructions to remediate the security risk at the first endpoint system, wherein the instructions to remediate the security risk comprise one or more of:

instructions to restore the first endpoint system to a state prior to execution of the object on the first endpoint system,

instructions to remove, from the first endpoint system, the object and one or more other objects installed by the object, or

instructions to block, at the first endpoint system, network traffic generated by the object to one or more network destinations.

2. The method of claim 1 , further comprising:

saving the request to a log file.

3. The method of claim 2 , wherein saving the request to the log file comprises saving a timestamp associated with the request and wherein an offset from the timestamp indicates a time at which the request is to be deleted from the log file.

4. The method of claim 2 , wherein the pushing the updated reputation data associated with the object and the instructions to remediate the security risk comprises:

searching the log file for requests performed by one or more second endpoint systems for reputation data related to the object; and

for each second endpoint system that requested reputation data related to the object, pushing the updated reputation data associated with the object and instructions to initiate remediation procedures against the object.

5. The method of claim 1 , wherein determining that the object presents a security risk comprises:

receiving, from one or more endpoint systems, telemetry data about activity on the endpoint systems related to the object; and

determining, based on the telemetry data, that the object includes a malicious payload.

6. A non-transitory computer-readable storage medium storing instructions, which, when executed on a processor, perform operations for initiating remediation of security risks on an endpoint system based on updated reputation data, the operations comprising:

receiving a request, from a first endpoint system, for reputation data about an object;

transmitting, to the first endpoint system in response to the request, current reputation data of the object;

after transmitting the data indicating the current reputation data of the object in response to the request, determining that the object presents a security risk without receiving a subsequent request for reputation data about the object from the first endpoint system;

updating reputation data associated with the object to indicate that the object presents a security risk; and

asynchronously initiating remediation of the security risk at the first endpoint system by pushing, to the first endpoint system, the updated reputation data associated with the object and instructions to remediate the security risk at the first endpoint system, wherein the instructions to remediate the security risk comprise one or more of:

instructions to restore the first endpoint system to a state prior to execution of the object on the first endpoint system,

instructions to remove, from the first endpoint system, the object and one or more other objects installed by the object, or

instructions to block, at the first endpoint system, network traffic generated by the object to one or more network destinations.

7. The computer-readable medium of claim 6 , wherein the operations further comprise:

saving the request to a log file.

8. The computer-readable medium of claim 7 , wherein saving the request to the log file comprises saving a timestamp associated with the request and wherein an offset from the timestamp indicates a time at which the request is to be deleted from the log file.

9. The computer-readable medium of claim 7 , wherein

the pushing the updated reputation data associated with the object and the instructions to remediate the security risk comprises:

searching the log file for requests performed by one or more second endpoint systems for reputation data related to the object; and

for each second endpoint system that requested reputation data related to the object, pushing the updated reputation data associated with the object and instructions to initiate remediation procedures against the object.

10. The computer-readable medium of claim 6 , wherein determining that the object presents a security risk comprises:

receiving, from one or more endpoint systems, telemetry data about activity on the endpoint systems related to the object; and

determining, based on the telemetry data, that the object includes a malicious payload.

11. A system comprising:

a processor; and

memory storing code, which, when executed on the processor, performs an operation for initiating remediation of security risks on a first endpoint system based on updated reputation data, the operation comprising:

receiving a request, from the first endpoint system, for reputation data about an object;

transmitting, to the first endpoint system in response to the request, current reputation data associated with the object;

after transmitting the current reputation data associated with the object in response to the request, determining that the object presents a security risk without receiving a subsequent request for reputation data about the object from the first endpoint system;

updating reputation data associated with the object to indicate that the object presents a security risk; and

asynchronously initiating remediation of the security risk at the first endpoint system by pushing, to the first endpoint system, the updated reputation data associated with the object and instructions to remediate the security risk at the first endpoint system, wherein the instructions to remediate the security risk comprise one or more of:

instructions to restore the first endpoint system to a state prior to execution of the object on the first endpoint system,

instructions to remove, from the first endpoint system, the object and one or more other objects installed by the object, or

instructions to block, at the first endpoint system, network traffic generated by the object to one or more network destinations.

12. The system of claim 11 , wherein the operation further comprises:

saving the request to a log file.

13. The system of claim 12 , wherein saving the request to the log file comprises saving a timestamp associated with the request and wherein an offset from the timestamp indicates a time at which the request is to be deleted from the log file.

14. The system of claim 12 , wherein the pushing the updated reputation data associated with the object and the instructions to remediate the security risk comprises:

searching the log file for requests performed by one or more second endpoint systems for reputation data related to the object; and

for each second endpoint system that requested reputation data related to the object, pushing the updated reputation data associated with the object and instructions to initiate remediation procedures against the object.

15. The system of claim 11 , wherein determining that the object presents a security risk comprises:

receiving, from one or more endpoint systems, telemetry data about activity on the endpoint systems related to the object; and

determining, based on the telemetry data, that the object includes a malicious payload.

Assignments (6)
CHANGE OF NAME Recorded Feb 6, 2023
From: NORTONLIFELOCK INC.
To: GEN DIGITAL INC.
Reel/Frame 062714/0605 →
NOTICE OF SUCCESSION OF AGENCY (REEL 050926 / FRAME 0560) Recorded Sep 13, 2022
From: JPMORGAN CHASE BANK, N.A.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 061422/0371 →
SECURITY AGREEMENT Recorded Sep 13, 2022
From: NORTONLIFELOCK INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062220/0001 →
CHANGE OF NAME Recorded Mar 10, 2020
From: SYMANTEC CORPORATION
To: NORTONLIFELOCK INC.
Reel/Frame 052135/0745 →
SECURITY AGREEMENT Recorded Nov 4, 2019
From: SYMANTEC CORPORATION; BLUE COAT LLC; LIFELOCK, INC,; SYMANTEC OPERATING CORPORATION
To: JPMORGAN, N.A.
Reel/Frame 050926/0560 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 3, 2016
From: SHAVELL, MICHAEL
To: SYMANTEC CORPORATION
Reel/Frame 037657/0735 →
Cited By (4)
US 12,223,037 US 12,273,366 US 12,549,566 US 12,694,046