JP7068294B2 - コンピュータセキュリティ動作を最適化するための動的評判インジケータ - Google Patents

コンピュータセキュリティ動作を最適化するための動的評判インジケータ Download PDF

Info

Publication number
JP7068294B2
JP7068294B2 JP2019522880A JP2019522880A JP7068294B2 JP 7068294 B2 JP7068294 B2 JP 7068294B2 JP 2019522880 A JP2019522880 A JP 2019522880A JP 2019522880 A JP2019522880 A JP 2019522880A JP 7068294 B2 JP7068294 B2 JP 7068294B2
Authority
JP
Japan
Prior art keywords
reputation
target entity
reputation indicator
entity
indicator
Prior art date
Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
Active
Application number
JP2019522880A
Other languages
English (en)
Japanese (ja)
Other versions
JP2019533258A (ja
JP2019533258A5 (enExample
Inventor
ハジマサン,ゲオルゲ-フローリン
モンドク,アレクサンドラ
ポルタセ,ラドゥ-マリアン
Original Assignee
ビットディフェンダー アイピーアール マネジメント リミテッド
Priority date (The priority date is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the date listed.)
Filing date
Publication date
Application filed by ビットディフェンダー アイピーアール マネジメント リミテッド filed Critical ビットディフェンダー アイピーアール マネジメント リミテッド
Publication of JP2019533258A publication Critical patent/JP2019533258A/ja
Publication of JP2019533258A5 publication Critical patent/JP2019533258A5/ja
Application granted granted Critical
Publication of JP7068294B2 publication Critical patent/JP7068294B2/ja
Active legal-status Critical Current
Anticipated expiration legal-status Critical

Links

Images

Classifications

    • GPHYSICS
    • G06COMPUTING OR CALCULATING; COUNTING
    • G06FELECTRIC DIGITAL DATA PROCESSING
    • G06F21/00Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
    • G06F21/50Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
    • G06F21/55Detecting local intrusion or implementing counter-measures
    • G06F21/56Computer malware detection or handling, e.g. anti-virus arrangements
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1408Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1408Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
    • H04L63/1425Traffic logging, e.g. anomaly detection
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/14Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
    • H04L63/1441Countermeasures against malicious traffic
    • H04L63/145Countermeasures against malicious traffic the attack involving the propagation of malware through the network, e.g. viruses, trojans or worms
    • HELECTRICITY
    • H04ELECTRIC COMMUNICATION TECHNIQUE
    • H04LTRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
    • H04L63/00Network architectures or network communication protocols for network security
    • H04L63/20Network architectures or network communication protocols for network security for managing network security; network security policies in general

Landscapes

  • Engineering & Computer Science (AREA)
  • Computer Security & Cryptography (AREA)
  • Computer Hardware Design (AREA)
  • General Engineering & Computer Science (AREA)
  • Computing Systems (AREA)
  • Computer Networks & Wireless Communication (AREA)
  • Signal Processing (AREA)
  • Software Systems (AREA)
  • Theoretical Computer Science (AREA)
  • General Health & Medical Sciences (AREA)
  • Virology (AREA)
  • Health & Medical Sciences (AREA)
  • Physics & Mathematics (AREA)
  • General Physics & Mathematics (AREA)
  • Computer And Data Communications (AREA)
  • Debugging And Monitoring (AREA)
  • Information Transfer Between Computers (AREA)
  • Information Retrieval, Db Structures And Fs Structures Therefor (AREA)
JP2019522880A 2016-10-27 2017-10-26 コンピュータセキュリティ動作を最適化するための動的評判インジケータ Active JP7068294B2 (ja)

Applications Claiming Priority (3)

Application Number Priority Date Filing Date Title
US15/336,387 2016-10-27
US15/336,387 US10237293B2 (en) 2016-10-27 2016-10-27 Dynamic reputation indicator for optimizing computer security operations
PCT/EP2017/077390 WO2018077996A1 (en) 2016-10-27 2017-10-26 Dynamic reputation indicator for optimizing computer security operations

Publications (3)

Publication Number Publication Date
JP2019533258A JP2019533258A (ja) 2019-11-14
JP2019533258A5 JP2019533258A5 (enExample) 2020-11-26
JP7068294B2 true JP7068294B2 (ja) 2022-05-16

Family

ID=60935760

Family Applications (1)

Application Number Title Priority Date Filing Date
JP2019522880A Active JP7068294B2 (ja) 2016-10-27 2017-10-26 コンピュータセキュリティ動作を最適化するための動的評判インジケータ

Country Status (12)

Country Link
US (1) US10237293B2 (enExample)
EP (1) EP3516572B1 (enExample)
JP (1) JP7068294B2 (enExample)
KR (1) KR102116573B1 (enExample)
CN (1) CN109891422B (enExample)
AU (1) AU2017350292B2 (enExample)
CA (1) CA3037453C (enExample)
ES (1) ES2871898T3 (enExample)
IL (1) IL266200B (enExample)
RU (1) RU2723665C1 (enExample)
SG (1) SG11201903491XA (enExample)
WO (1) WO2018077996A1 (enExample)

Families Citing this family (17)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US10237293B2 (en) * 2016-10-27 2019-03-19 Bitdefender IPR Management Ltd. Dynamic reputation indicator for optimizing computer security operations
US9756061B1 (en) * 2016-11-18 2017-09-05 Extrahop Networks, Inc. Detecting attacks using passive network monitoring
TWI755616B (zh) 2017-04-21 2022-02-21 美商時美媒體公司 用於編碼器導引自適應性品質演現的系統及方法
US11050783B2 (en) * 2018-01-31 2021-06-29 International Business Machines Corporation System and method for detecting client participation in malware activity
US11165814B2 (en) 2019-07-29 2021-11-02 Extrahop Networks, Inc. Modifying triage information based on network monitoring
US11409868B2 (en) * 2019-09-26 2022-08-09 At&T Intellectual Property I, L.P. Ransomware detection and mitigation
CN111027067A (zh) * 2019-11-25 2020-04-17 深圳传音控股股份有限公司 基于大数据分析的恶意软件识别方法、服务器及存储介质
US11165823B2 (en) 2019-12-17 2021-11-02 Extrahop Networks, Inc. Automated preemptive polymorphic deception
KR102180105B1 (ko) * 2020-08-13 2020-11-17 최원천 장치에 설치된 소프트웨어에 대한 악성 소프트웨어 판단 방법 및 장치
US11683331B2 (en) * 2020-11-23 2023-06-20 Juniper Networks, Inc. Trust scoring of network entities in networks
US11349861B1 (en) 2021-06-18 2022-05-31 Extrahop Networks, Inc. Identifying network entities based on beaconing activity
US11914709B2 (en) * 2021-07-20 2024-02-27 Bank Of America Corporation Hybrid machine learning and knowledge graph approach for estimating and mitigating the spread of malicious software
US12074879B2 (en) 2021-09-14 2024-08-27 Juniper Networks, Inc. Inferring trust in computer networks
US12170670B2 (en) 2021-12-15 2024-12-17 Juniper Networks, Inc. Use of sentiment analysis to assess trust in a network
US12348568B1 (en) * 2022-12-23 2025-07-01 F5, Inc. Methods for optimizing selection of a hardware security server and devices thereof
US12355803B2 (en) 2022-12-30 2025-07-08 Juniper Networks, Inc. Remediation work score for network trust applications
US12483384B1 (en) 2025-04-16 2025-11-25 Extrahop Networks, Inc. Resynchronizing encrypted network traffic

Citations (4)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20090328209A1 (en) 2008-06-30 2009-12-31 Symantec Corporation Simplified Communication of a Reputation Score for an Entity
US20140123279A1 (en) 2012-10-29 2014-05-01 Michael G. Bishop Dynamic quarantining for malware detection
US20150007315A1 (en) 2013-06-28 2015-01-01 Symantec Corporation Techniques for Detecting a Security Vulnerability
US20150096018A1 (en) 2013-09-27 2015-04-02 Bitdefender IPR Management Ltd. Systems and Methods for Using a Reputation Indicator to Facilitate Malware Scanning

Family Cites Families (31)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US6931540B1 (en) 2000-05-31 2005-08-16 Networks Associates Technology, Inc. System, method and computer program product for selecting virus detection actions based on a process by which files are being accessed
US20020184362A1 (en) * 2001-05-31 2002-12-05 International Business Machines Corporation System and method for extending server security through monitored load management
US8635690B2 (en) 2004-11-05 2014-01-21 Mcafee, Inc. Reputation based message processing
WO2006101549A2 (en) 2004-12-03 2006-09-28 Whitecell Software, Inc. Secure system for allowing the execution of authorized computer program code
WO2007117585A2 (en) * 2006-04-06 2007-10-18 Smobile Systems Inc. System and method for managing malware protection on mobile devices
US8769673B2 (en) * 2007-02-28 2014-07-01 Microsoft Corporation Identifying potentially offending content using associations
US8584094B2 (en) * 2007-06-29 2013-11-12 Microsoft Corporation Dynamically computing reputation scores for objects
US7392544B1 (en) 2007-12-18 2008-06-24 Kaspersky Lab, Zao Method and system for anti-malware scanning with variable scan settings
US8225406B1 (en) 2009-03-31 2012-07-17 Symantec Corporation Systems and methods for using reputation data to detect shared-object-based security threats
US8381289B1 (en) * 2009-03-31 2013-02-19 Symantec Corporation Communication-based host reputation system
US8001606B1 (en) * 2009-06-30 2011-08-16 Symantec Corporation Malware detection using a white list
US8955131B2 (en) 2010-01-27 2015-02-10 Mcafee Inc. Method and system for proactive detection of malicious shared libraries via a remote reputation system
US9147071B2 (en) * 2010-07-20 2015-09-29 Mcafee, Inc. System and method for proactive detection of malware device drivers via kernel forensic behavioral monitoring and a back-end reputation system
US8327441B2 (en) 2011-02-17 2012-12-04 Taasera, Inc. System and method for application attestation
US9106680B2 (en) * 2011-06-27 2015-08-11 Mcafee, Inc. System and method for protocol fingerprinting and reputation correlation
US9262624B2 (en) 2011-09-16 2016-02-16 Mcafee, Inc. Device-tailored whitelists
RU2011138462A (ru) * 2011-09-20 2013-04-10 Закрытое акционерное общество "Лаборатория Касперского" Использование решений пользователей для обнаружения неизвестных компьютерных угроз
US9235706B2 (en) * 2011-12-02 2016-01-12 Mcafee, Inc. Preventing execution of task scheduled malware
US8769676B1 (en) * 2011-12-22 2014-07-01 Symantec Corporation Techniques for identifying suspicious applications using requested permissions
US8918881B2 (en) * 2012-02-24 2014-12-23 Appthority, Inc. Off-device anti-malware protection for mobile devices
US9614865B2 (en) * 2013-03-15 2017-04-04 Mcafee, Inc. Server-assisted anti-malware client
WO2014143000A1 (en) * 2013-03-15 2014-09-18 Mcafee, Inc. Server-assisted anti-malware
WO2014143012A1 (en) * 2013-03-15 2014-09-18 Mcafee, Inc. Remote malware remediation
US9363282B1 (en) * 2014-01-28 2016-06-07 Infoblox Inc. Platforms for implementing an analytics framework for DNS security
US9009827B1 (en) * 2014-02-20 2015-04-14 Palantir Technologies Inc. Security sharing system
US9411959B2 (en) * 2014-09-30 2016-08-09 Juniper Networks, Inc. Identifying an evasive malicious object based on a behavior delta
US10079846B2 (en) * 2015-06-04 2018-09-18 Cisco Technology, Inc. Domain name system (DNS) based anomaly detection
US10063571B2 (en) * 2016-01-04 2018-08-28 Microsoft Technology Licensing, Llc Systems and methods for the detection of advanced attackers using client side honeytokens
CN105578455B (zh) * 2016-01-27 2020-06-09 哈尔滨工业大学深圳研究生院 一种机会网络中分布式动态信誉评估方法
US10237293B2 (en) * 2016-10-27 2019-03-19 Bitdefender IPR Management Ltd. Dynamic reputation indicator for optimizing computer security operations
US10681070B2 (en) * 2017-05-26 2020-06-09 Qatar Foundatiion Method to identify malicious web domain names thanks to their dynamics

Patent Citations (8)

* Cited by examiner, † Cited by third party
Publication number Priority date Publication date Assignee Title
US20090328209A1 (en) 2008-06-30 2009-12-31 Symantec Corporation Simplified Communication of a Reputation Score for an Entity
JP2011527046A (ja) 2008-06-30 2011-10-20 シマンテック コーポレーション エンティティのレピュテーションスコアの簡易化された伝達
US20140123279A1 (en) 2012-10-29 2014-05-01 Michael G. Bishop Dynamic quarantining for malware detection
JP2015530678A (ja) 2012-10-29 2015-10-15 マカフィー, インコーポレイテッド マルウェア検出の動的な検疫
US20150007315A1 (en) 2013-06-28 2015-01-01 Symantec Corporation Techniques for Detecting a Security Vulnerability
JP2015531951A (ja) 2013-06-28 2015-11-05 シマンテック コーポレーションSymantec Corporation セキュリティ脆弱性を検出するための技術
US20150096018A1 (en) 2013-09-27 2015-04-02 Bitdefender IPR Management Ltd. Systems and Methods for Using a Reputation Indicator to Facilitate Malware Scanning
JP2016538614A (ja) 2013-09-27 2016-12-08 ビットディフェンダー アイピーアール マネジメント リミテッド 評判インジケータを使用してマルウェアスキャニングを容易にするためのシステムおよび方法

Also Published As

Publication number Publication date
KR20190067820A (ko) 2019-06-17
CN109891422B (zh) 2023-03-10
CA3037453A1 (en) 2018-05-03
JP2019533258A (ja) 2019-11-14
CA3037453C (en) 2021-04-27
RU2723665C1 (ru) 2020-06-17
WO2018077996A1 (en) 2018-05-03
KR102116573B1 (ko) 2020-06-03
CN109891422A (zh) 2019-06-14
EP3516572A1 (en) 2019-07-31
US20180124078A1 (en) 2018-05-03
IL266200A (en) 2019-06-30
AU2017350292A1 (en) 2019-04-04
ES2871898T3 (es) 2021-11-02
IL266200B (en) 2021-01-31
EP3516572B1 (en) 2021-03-24
AU2017350292B2 (en) 2021-08-26
US10237293B2 (en) 2019-03-19
SG11201903491XA (en) 2019-05-30

Similar Documents

Publication Publication Date Title
JP7068294B2 (ja) コンピュータセキュリティ動作を最適化するための動的評判インジケータ
US9117077B2 (en) Systems and methods for using a reputation indicator to facilitate malware scanning
CN107851155B (zh) 用于跨越多个软件实体跟踪恶意行为的系统及方法
US11893114B2 (en) Memory layout based monitoring
US12437073B2 (en) Systems and methods for countering persistent malware
HK40004203A (en) Dynamic reputation indicator for optimizing computer security operations
HK40004203B (en) Dynamic reputation indicator for optimizing computer security operations
WO2025051590A1 (en) Systems and methods for countering persistent malware
Hunter Inferring Application Behavior through Network, User Interaction, and File Access Sensors
HK1219790B (zh) 使用声誉指示符来促进恶意软件扫描的系统和方法

Legal Events

Date Code Title Description
A521 Request for written amendment filed

Free format text: JAPANESE INTERMEDIATE CODE: A523

Effective date: 20201014

A621 Written request for application examination

Free format text: JAPANESE INTERMEDIATE CODE: A621

Effective date: 20201014

A977 Report on retrieval

Free format text: JAPANESE INTERMEDIATE CODE: A971007

Effective date: 20210813

A131 Notification of reasons for refusal

Free format text: JAPANESE INTERMEDIATE CODE: A131

Effective date: 20210820

A521 Request for written amendment filed

Free format text: JAPANESE INTERMEDIATE CODE: A523

Effective date: 20211111

TRDD Decision of grant or rejection written
A01 Written decision to grant a patent or to grant a registration (utility model)

Free format text: JAPANESE INTERMEDIATE CODE: A01

Effective date: 20220331

A61 First payment of annual fees (during grant procedure)

Free format text: JAPANESE INTERMEDIATE CODE: A61

Effective date: 20220428

R150 Certificate of patent or registration of utility model

Ref document number: 7068294

Country of ref document: JP

Free format text: JAPANESE INTERMEDIATE CODE: R150

R250 Receipt of annual fees

Free format text: JAPANESE INTERMEDIATE CODE: R250