IP Library › Granted Patent US 10,476,892
Granted Patent B2
US 10,476,892 · App. 15/393,899 · Granted Nov 12, 2019

Reputation-based application caching and white-listing

Inventors: Khandi Sudhakar Reddy (Bangalore, IN); Rajeev Chaubey (Bangalore, IN); Srinivas Koripella (Bangalore, IN)
Assignee: Juniper Networks, Inc.
H04L63/1408G06N20/00H04L63/0227
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,476,892
App. No.
15/393,899
Granted
Nov 12, 2019
Kind
B2
Abstract

A device may classify an application, associated with an endpoint, based on traffic associated with the endpoint. The device may determine a reputation score associated with the endpoint. The reputation score may be indicative of a level of trustworthiness of the endpoint. The device may selectively store a classification result, associated with classifying the application, in an application cache based on the reputation score associated with the endpoint. The classification result may be selectively used to process further traffic associated with the endpoint.

Claims (116)

1. A device, comprising:

a memory; and

one or more processors to:

classify an application, associated with an endpoint, based on traffic associated with the endpoint;

send, to another device that has processed other traffic associated with the endpoint, a request for information regarding a reputation of the endpoint;

receive, from the other device based on the request, the information,

the information including at least one of:

a first indication that the endpoint is identified in a white-list, or

a second indication that the endpoint is identified in a black-list;

determine, based on receiving the information from the other device, a first reputation score associated with the endpoint,

the first reputation score being indicative of a level of trustworthiness of the endpoint;

determine whether the first reputation score satisfies a threshold;

selectively store a classification result, associated with classifying the application, in an application cache based on the first reputation score satisfying the threshold;

determine a security policy based on the classification result;

process the traffic using the security policy;

receive an indication to inspect the classification result stored in the application cache;

determine a second reputation score associated with the endpoint;

compare the second reputation score and the first reputation score; and

selectively remove the classification result from the application cache based on comparing the second reputation score and the first reputation score.

2. The device of claim 1 , where the one or more processors are further to:

determine whether an instance of suspicious activity, associated with the endpoint, has occurred; and

where the one or more processors, when selectively storing the classification result, are to:

selectively store the classification result based on whether an instance of suspicious activity, associated with the endpoint, has occurred.

3. The device of claim 1 , where the one or more processors are further to:

determine that the first reputation score does not satisfy the threshold; and

where the one or more processors, when selectively storing the classification result, are to:

discard the classification result, without storing the classification result in the application cache, based on determining that the first reputation score does not satisfy the threshold.

4. The device of claim 1 ,

where the classification result includes information that identifies the endpoint.

5. The device of claim 1 , where the one or more processors, are further to:

determine, based on additional traffic associated with the endpoint and based on storing the classification result, that the endpoint is identified in the application cache;

determine, based on determining that the endpoint is identified in the application cache, that the application is to be re-classified;

re-classify the application; and

selectively remove the classification result from the application cache based on re-classifying the application.

6. The device of claim 5 , where the one or more processors are further to:

determine that a threshold amount of resources, associated with the device, is available; and

where the one or more processors, when determining that the application is to be re-classified, are to:

determine that the application is to be re-classified based on determining that the threshold amount of resources are available.

7. The device of claim 5 , where the one or more processors are further to:

determine that the application has not been classified a threshold number of times; and

where the one or more processors, when determining that the application is to be re-classified, are to:

determine that the application is to be re-classified based on determining that the application has not been classified the threshold number of times.

8. The device of claim 5 , where the one or more processors are further to:

determine that a random re-classification or a periodic re-classification is to be performed; and

where the one or more processors, when determining that the application is to be re-classified, are to:

determine that the application is to be re-classified based on determining that the random re-classification or the periodic re-classification is to be performed.

9. The device of claim 5 , where the one or more processors are further to:

determine whether a re-classification result, associated with re-classifying the application, matches the classification result; and

where the one or more processors, when selectively removing the classification result from the application cache, are to:

selectively remove the classification result based on whether the re-classification result matches the classification result.

10. A non-transitory computer-readable medium storing instructions, the instructions comprising:

one or more instructions that, when executed by one or more processors of a device, cause the one or more processors to:

classify an application, associated with an endpoint, based on first traffic associated with the endpoint;

send, to another device that has processed second traffic associated with the endpoint, a request for information regarding a reputation of the endpoint;

receive, from the other device based on the request, the information,

the information including at least one of:

a first indication that the endpoint is identified in a white-list, or

a second indication that the endpoint is identified in a black-list;

determine, based on receiving the information from the other device, a first reputation score associated with the endpoint;

determine whether the first reputation score satisfies a threshold;

selectively store a classification result, associated with classifying the application, in an application cache, based on the first reputation score satisfying the threshold;

determine a security policy based on the classification result;

process the first traffic using the security policy;

receive an indication to inspect the classification result stored in the application cache;

determine a second reputation score associated with the endpoint;

compare the second reputation score and the first reputation score; and

selectively remove the classification result from the application cache based on comparing the second reputation score and the first reputation score.

11. The non-transitory computer-readable medium of claim 10 , where the one or more instructions, when executed by the one or more processors, further cause the one or more processors to:

determine, based on third traffic associated with the endpoint and based on the classification result, that the endpoint is identified in the application cache;

determine that a threshold amount of resources, associated with performing re-classification, is available;

determine that the application is to be re-classified determining that the endpoint is identified in the application cache and based on determining that the threshold amount of resources are available;

re-classify the application; and

selectively remove the classification result from the application cache based on re-classifying the application.

12. The non-transitory computer-readable medium of claim 11 , where the one or more instructions, when executed by the one or more processors, further cause the one or more processors to:

determine that the application has not been classified a threshold number of times; and

where the one or more instructions, that cause the one or more processors to determine that the application is to be re-classified, cause the one or more processors to:

determine that the application is to be re-classified based on determining that the application has not been classified the threshold number of times.

13. The non-transitory computer-readable medium of claim 11 , where the one or more instructions, when executed by the one or more processors, further cause the one or more processors to:

determine that a random re-classification or a periodic re-classification is to be performed; and

where the one or more instructions, that cause the one or more processors to determine that the application is to be re-classified, cause the one or more processors to:

determine that the application is to be re-classified based on determining that the random re-classification or the periodic re-classification is to be performed.

14. The non-transitory computer-readable medium of claim 11 , where the one or more instructions, when executed by the one or more processors, further cause the one or more processors to:

determine whether a re-classification result, associated with re-classifying the application, matches the classification result; and

where the one or more instructions, that cause the one or more processors to selectively remove the classification result from the application cache, cause the one or more processors to:

selectively remove the classification result based on whether the re-classification result matches the classification result.

15. A method, comprising:

classifying, by a device, an application, associated with an endpoint, based on traffic associated with the endpoint;

sending, by the device to another device that has processed other traffic associated with the endpoint, a request for information regarding a reputation of the endpoint;

receiving, by the device from the other device based on the request, the information,

the information including at least one of:

a first indication that the endpoint is identified in a white-list, or

a second indication that the endpoint is identified in a black-list;

determining, by the device and based on receiving the information from the other device, a first reputation score, associated with the endpoint, that is indicative of a level of trustworthiness of the endpoint;

determining, by the device, whether the first reputation score satisfies a threshold; and selectively:

selectively storing, by the device, a classification result, associated with classifying the application, in an application cache based on the first reputation score satisfying the threshold,

determining, by the device, a security policy based on the classification result,

processing, by the device, the traffic using the security policy;

receiving, by the device, an indication to inspect the classification result stored in the application cache;

determining, by the device, a second reputation score associated with the endpoint;

comparing, by the device, the second reputation score and the first reputation score; and

selectively removing, by the device, the classification result from the application cache based on comparing the second reputation score and the first reputation score.

16. The method of claim 15 , further comprising:

determining whether an instance of suspicious activity, associated with the endpoint, has occurred; and

where storing the classification result comprises:

storing the classification result in the application cache based on whether an instance of suspicious activity, associated with the endpoint, has occurred.

17. The method of claim 15 , further comprising:

determining a plurality of reputation scores associated with the endpoint; and

where determining the first reputation score comprises:

determining the first reputation score based on the plurality of reputation scores.

18. The method of claim 15 , further comprising:

discarding the classification result based on the first reputation score not satisfying the threshold; and

storing information indicating that another classification result, associated with the endpoint, is not permitted to be cached at a later time.

19. The device of claim 1 , where the one or more processors, when selectively removing the classification result from the application cache based on comparing the second reputation score and the first reputation score, are to:

allow the classification result to remain in the application cache based on determining that the second reputation score is not below the first reputation score.

20. The non-transitory computer-readable medium of claim 10 , where the one or more instructions, that cause the one or more processors to selectively remove the classification result from the application cache based on comparing the second reputation score and the first reputation score, cause the one or more processors to:

allow the classification result to remain in the application cache based on determining that the second reputation score is not below the first reputation score.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 29, 2016
From: REDDY, KHANDI SUDHAKAR; CHAUBEY, RAJEEV; KORIPELLA, SRINIVAS
To: JUNIPER NETWORKS, INC.
Reel/Frame 040804/0447 →
Continuity (1)
Related Publication 20180191743A1 · Jul 5, 2018