IP Library Granted Patent US 10,594,717
Granted Patent B2
US 10,594,717 · App. 15/970,814 · Granted Mar 17, 2020

Context-dependent timeout for remote security services

Inventors: Neil Robert Tyndale Watkiss (Oxford, GB); Emile Marcus Kenning (Abingdon, GB); Mark D. Harris (Oxon, GB)
Assignee: Sophos Limited
H04L63/1425G06N20/00H04L63/1416H04L63/1433H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,594,717
App. No.
15/970,814
Granted
Mar 17, 2020
Kind
B2
Abstract

A threat management facility that remotely stores global reputation information for network content can be used in combination with a recognition engine such as a machine learning classifier that is locally deployed on endpoints within an enterprise network. More specifically, the recognition engine can locally evaluate reputation for a network address being accessed by an endpoint, and this reputation information can be used to dynamically establish a timeout for a request from the endpoint to the threat management facility for corresponding global reputation information.

Claims (17)

1. A computer program product comprising computer executable code embodied on a non-transitory computer readable medium that, when executing on an endpoint, performs the steps of:

intercepting a request for content from a browser executing on the endpoint, the request including a Uniform Resource Locator that identifies a recipient for the request on a data network;

applying a machine learning classifier locally on the endpoint to estimate a risk associated with the Uniform Resource Locator;

transmitting a lookup request for the Uniform Resource Locator from the endpoint to a remote threat management facility;

determining a timeout for a response from the remote threat management facility to the lookup request based on the risk determined by the machine learning classifier, the timeout providing a window of limited duration for receiving the response at the endpoint;

when the response is received within the window provided by the timeout, processing the request for content according to the response from the remote threat management facility; and

when the response is not received within the window provided by the timeout, processing the request for content using a default local rule on the endpoint.

2. The computer program product of claim 1 wherein processing the request for content includes blocking retrieval of the content.

3. The computer program product of claim 1 wherein processing the request for content includes scanning the content for malware.

4. The computer program product of claim 1 wherein processing the request for content includes executing the content.

5. A system comprising:

an endpoint associated with an enterprise network, the endpoint including a computing device comprising a memory and a processor;

an endpoint security agent executing on the processor based on instructions in the memory, the endpoint security agent including a recognition engine for evaluating riskiness of a network address, and the endpoint security agent configured to determine a risk value for network communications of the endpoint containing the network address using the recognition engine, and to transmit the risk value and a security request for the network address to a remote resource for evaluation; and

a threat management facility for the enterprise network, the threat management facility coupled in a communicating relationship with the endpoint and the threat management facility configured to respond to the security request based on the risk value, wherein the threat management facility is configured to prioritize a response to the endpoint relative to one or more other requests from one or more other endpoints based upon the risk value.

6. The system of claim 5 wherein the network communications include content retrieved from the network address, and wherein the threat management facility adjusts a scanning of the content based on the risk value.

7. The system of claim 6 wherein the threat management facility is configured to adjust the scanning by adjusting an amount of the content that is scanned.

8. The system of claim 6 wherein the threat management facility is configured to adjust the scanning by adjusting a size of a library used to identify malware.

Assignments (4)
RELEASE OF SECURITY INTEREST IN PATENTS AT R/F 053476/0681 Recorded Mar 9, 2021
From: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
To: SOPHOS LIMITED
Reel/Frame 056469/0815 →
PATENT SECURITY AGREEMENT FIRST LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 053124/0350 →
PATENT SECURITY AGREEMENT SECOND LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 053476/0681 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 8, 2018
From: WATKISS, NEIL ROBERT TYNDALE; KENNING, EMILE MARCUS; HARRIS, MARK DAVID
To: SOPHOS LIMITED
Reel/Frame 046029/0426 →
Continuity (1)
Related Publication 20190342312A1 · Nov 7, 2019