IP Library Granted Patent US 7,937,480
Granted Patent B2
US 7,937,480 · App. 11/626,479 · Granted May 3, 2011

Aggregation of reputation data

Assignee: McAfee, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,937,480
App. No.
11/626,479
Granted
May 3, 2011
Kind
B2
Abstract

Methods and systems for operation upon one or more data processors for aggregating reputation data from dispersed reputation engines and deriving global reputation information for use in handling received communications.

Claims (45)

1. A computer-implemented reputation system, the system comprising:

a centralized reputation engine operable to receive feedback from a plurality of local reputation engines, the plurality of local reputation engines being operable to determine local reputations based upon of one or more entities and respectively associated with the local reputation engines;

an aggregation engine operable to derive a global reputation for a queried entity based upon an aggregation of the plurality of local reputations; and

wherein;

the centralized reputation engine is operable to provide the global reputation of the queried entity to one or more of the local reputation engines responsive to receiving a reputation query from said one or more of the local reputation engines;

the centralized reputation engine is operable to apply, for each local reputation engine that originates a reputation query, a local reputation bias to the global reputation based on preferences of the local reputation engine to generate a local reputation for the local reputation engine from the global reputation, so that for each local reputation engine a different local reputation is generated from the global reputation.

2. The system of claim 1 , wherein the aggregation engine is operable to store confidence values associated with a respective local reputation engine, the aggregation engine being further operable to aggregate the plurality of local reputations using the confidence values associated with each of the plurality of local reputations through its respective local reputation engine.

3. The system of claim 2 , wherein each local reputation engine is a subsystem to the centralized reputation system, and performs the reputation scoring on a local scale based upon the communications received by the local reputation engine, and the centralized reputation engine performs reputation scoring based upon communications received by the centralized reputation engine and reputation information received from the local reputation engines.

4. The system of claim 2 , wherein the local reputations are weighted based on their respective confidence values prior to aggregation of the local reputations.

5. The system of claim 4 , wherein the confidence values are tuned based upon feedback received from the plurality of local reputation engines.

6. The system of claim 1 , wherein the local reputations and global reputations are vectors which identify the characteristics of the respective entities to which they are associated.

7. The system of claim 6 , wherein the characteristics comprise one or more of a spamming characteristic, a phishing characteristic, a bulk mailing characteristic, a virus source characteristic, a legitimate communication characteristic, an intrusion characteristic, an attack characteristic, a spyware characteristic, or a geolocation characteristic.

8. The system of claim 1 , wherein the local reputations are based upon an aggregation of reputable and non-reputable criteria.

9. The system of claim 1 , wherein generating a local reputation for the local reputation engine from the global reputation comprises emphasizing first criteria for reputation in the global reputation while de-emphasizing second other criteria for reputation in the global reputation based upon the local reputation bias.

10. The system of claim 1 , wherein the local reputation engine originates the reputation query responsive to receiving a communication associated with an external entity with respect to a protected enterprise network associated with the local reputation engine.

11. The system of claim 10 , wherein the local reputation engine originates the reputation query responsive to a local reputation associated with the external entity being indeterminate.

12. The system of claim 1 , wherein the centralized reputation engine is further operable to aggregate reputation for a plurality of identities associated with one or more of the plurality of entities.

13. The system of claim 12 , wherein the centralized reputation engine is further operable to correlate attributes associated with different identities to identify relationships between the different entities, and to assign a portion of the reputation associated with one entity to the reputation of another entity where a relationship have been identified between entities.

14. A computer-implemented method of producing a global reputation, comprising the steps of:

receiving a reputation query from a requesting local reputation engine;

retrieving a plurality of local reputations the local reputations being respectively associated with a plurality of local reputation engines;

aggregating the plurality of local reputations; deriving a global reputation from the aggregation of the local reputations;

applying, for each local reputation engine that originates a reputation query, a local reputation bias to the global reputation based on preferences of the local reputation engine to generate a local reputation for the local reputation engine from the global reputation, so that for each local reputation engine a different local reputation is generated from the global reputation; and

responding to the reputation query with the global reputation.

15. The method of claim 14 , further comprising retrieving confidence values associated with the local reputation engines, the deriving step using the confidence values to derive the global reputation.

16. The method of claim 15 , wherein the deriving step further comprises weighting the local reputations using their respective confidence values and combining the weighted reputations to generate the global reputation.

17. The method of claim 16 , further comprising tuning the confidence values based upon feedback from the plurality of local reputation engines.

18. The method of claim 14 , wherein the local reputations and global reputations are vectors which identify the characteristics of the respective entities to which they are associated.

19. The method of claim 18 , wherein the characteristics comprise one or more of a spamming characteristic, a phishing characteristic, a bulk mailing characteristic, a malware source characteristic, or a legitimate mail characteristic.

20. The method of claim 14 , wherein the local reputations are based upon an aggregation of reputable and non-reputable criteria.

21. The method of claim 14 , wherein generating a local reputation for the local reputation engine from the global reputation comprises emphasizing first criteria for reputation in the global reputation based upon the local reputation bias and de-emphasizing second other criteria for reputation in the global reputation based upon the local reputation bias.

22. The method of claim 14 , wherein the requesting local reputation engine originates the reputation query responsive to receiving a communication associated with an external entity with respect to a protected enterprise network associated with the requesting local reputation engine.

23. The method of claim 22 , wherein the requesting local reputation engine originates the reputation query responsive to a local reputation associated with the external entity being indeterminate.

24. The method of claim 14 , wherein deriving the global reputation is further based upon public and private information not available to any of the plurality of local reputation engines.

25. One or more non-transitory computer readable storage media having computer executable instructions operable to perform steps to aggregate a plurality of local reputation vectors to produce a global reputation vector, the steps comprising:

receiving a reputation query from a requesting local reputation engine;

retrieving a plurality of local reputations the local reputations being respectively associated with a plurality of local reputation engines;

aggregating the plurality of local reputations; deriving a global reputation from the aggregation of the local reputations;

applying, for each local reputation engine that originates a reputation query, a local reputation bias to the global reputation based on preferences of the local reputation engine to generate a local reputation for the local reputation engine from the global reputation, so that for each local reputation engine a different local reputation is generated from the global reputation; and responding to the reputation query with the global reputation.

26. The non-transitory computer readable storage media of claim 25 wherein deriving the global reputation is further based upon public or private information available only to a central server.

27. The non-transitory computer readable storage media of claim 25 further comprising computer executable instructions operable to aggregate reputation for a plurality identities associated with one or more of the plurality of entities.

28. A computer-implemented reputation system, the system comprising:

a communications interface operable to receive global reputation information from a central server, the central server being operable to determine global reputations based upon feedback received from one or more local reputation engines, the global reputation being respectively associated with one or more entities;

a reputation engine operable to bias the global reputation received from the central server based upon defined local preferences, the biasing comprising applying, for each local reputation engine that originates a reputation query, a local reputation bias to the global reputation based on preferences of the local reputation engine to generate a local reputation for the local reputation engine from the global reputation, so that for each local reputation engine a different local reputation is generated from the global reputation; and

wherein the centralized reputation engine is operable to provide the global reputation of the queried entity to the communications interface responsive to receiving a reputation query from said communications interface.

Assignments (11)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 11, 2010
From: SECURE COMPUTING, LLC
To: MCAFEE, INC.
Reel/Frame 023915/0990 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 27, 2007
From: ALPEROVITCH, DMITRI; HERNANDEZ, ALEJANDRO MANUEL; JUDGE, PAUL; KRASSER, SVEN; SCHNECK, PHYLLIS ADELE
To: SECURE COMPUTING CORPORATION
Reel/Frame 019616/0125 →
Continuity (3)
Continuation In Part 11173941 · Jul 1, 2005
Continuation In Part 11142943 · Jun 2, 2005
Related Publication 20070130351A1 · Jun 7, 2007