发明名称 Detecting malicious resources in a network based upon active client reputation monitoring
摘要 Systems and methods for detecting malicious resources by analyzing communication between multiple resources coupled to a network are provided. According to one embodiment, a method is performed for client reputation monitoring. A monitoring unit within a network observes activities relating to multiple monitored devices within the network. For each observed activity, the monitoring unit assigns a score to the observed activity based upon a policy of multiple polices established within the monitoring unit. For each of the monitored devices, the monitoring unit maintains a current reputation score for the monitored device based upon the score and a historical score associated with the monitored device. The monitoring unit classifies one of the monitored devices as potentially being a malicious resource based upon its current reputation score.
申请公布号 US9497212(B2) 申请公布日期 2016.11.15
申请号 US201213476171 申请日期 2012.05.21
申请人 Fortinet, Inc. 发明人 Turnbull Darren W.
分类号 G06F21/00;H04L29/06;G06F21/55 主分类号 G06F21/00
代理机构 Hamilton, DeSanctis & Cha LLP 代理人 Hamilton, DeSanctis & Cha LLP
主权项 1. A method comprising: maintaining, by a monitoring unit within a protected private network, a plurality of policies in a form of rules, wherein each policy of the plurality of policies is configurable by a network administrator of the protected private network via a browser-based interface provided by the monitoring unit and specifies (i) a perceived risky activity of a plurality of perceived risky activities potentially indicative of malware activity and (ii) a corresponding score, wherein the plurality of perceived risky activities include bad connection attempts, interactions with a hosts in particular geographic locations external to the protected private network, interactions with undesired websites external to the protected network and failed Domain Name Server (DNS) resolution requests; observing, by the monitoring unit, activities relating to a plurality of monitored devices within the protected private network; for each observed activity, assigning, by the monitoring unit, a score to the observed activity based upon a matching policy of the plurality of polices; for each of the plurality of monitored devices, maintaining, by the monitoring unit, a current reputation score for the monitored device based upon the score and a historical score associated with the monitored device; and classifying, by the monitoring unit, a monitored device of the plurality of monitored devices as potentially being a malicious resource based upon the current reputation score for the monitored device.
地址 Sunnyvale CA US