发明名称 REDUCTION OF FALSE POSITIVE REPUTATIONS THROUGH COLLECTION OF OVERRIDES FROM CUSTOMER DEPLOYMENTS
摘要 <p>An automated arrangement for reducing the occurrence and/or minimizing the impact of false positives by a reputation service is provided in which overrides for a reputation of an adversary are reported to a reputation service from security devices, such as unified threat management systems, deployed in enterprise or consumer networks. An override is typically performed by an administrator at a customer network to allow the security device to accept traffic from, or send traffic to a given IP address or URL. Such connectivity is allowed&mdash;even if such objects have a blacklisted reputation provided by a reputation service&mdash;in cases where the administrator recognizes that the blacklisted reputation is a false positive. The reputation service uses the reported overrides to adjust the fidelity (i.e., a confidence level) of that object's reputation, and then provides an updated reputation, which reflects the fidelity adjustment, to all the security devices that use the reputation service.</p>
申请公布号 EP2156361(A1) 申请公布日期 2010.02.24
申请号 EP20080744154 申请日期 2008.03.20
申请人 MICROSOFT CORPORATION 发明人 NEYSTADT, JOHN;HUDIS, EFIM
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项
地址