发明名称 AGENT ASSISTED MALICIOUS APPLICATION BLOCKING IN A NETWORK ENVIRONMENT
摘要 Embodiments are configured to receive metadata of a process intercepted on an end host when attempting to access a network. The metadata includes a hash of an application associated with the process and an endpoint reputation score of the application. Embodiments are configured to request a threat intelligence reputation score based on the hash of the application, to determine an action to be taken by the end host based, at least in part, on one or more policies and at least one of the threat intelligence reputation score and the endpoint reputation score, and to send a response indicating the action to be taken by the end host. Further embodiments request another threat intelligence reputation score based on another hash of a dynamic link library module loaded by the process on the end host, and the action is determined based, at least in part, on the other threat intelligence score.
申请公布号 US2017118228(A1) 申请公布日期 2017.04.27
申请号 US201715399091 申请日期 2017.01.05
申请人 McAfee, Inc. 发明人 CP Chandan;Narasimhan Srinivasan
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项
地址 Santa Clara CA US