主权项 |
1. A method, comprising:
receiving, by a server, information regarding known epitypes of malness, wherein the information includes malness scores and behaviors for the known epitypes of malness, wherein the server receives information for setting a first threshold level and a second threshold level, and wherein the first threshold level and the second threshold level indicate values that are associated with malness scores that are not malness free values; storing, by the server, the information regarding the known epitypes of malness, and the information for setting the first threshold level and the second threshold level; building, by the server, a model based on the information regarding the known epitypes of malness stored by the server and information associated with a plurality of malness scores for different applications; receiving, by the server, applications from a device for use with the model; generating, by the server, other malness scores for one or more of the applications using data from the one or more applications in combination with the model; and determining, by the server, a response based on the other malness scores, wherein determining the response comprises:
allowing one or more of the applications or the device to access a network when the other malness scores for one or more of the applications are below the first threshold level;blocking one or more of the applications or the device from accessing the network when the other malness scores for one or more of the applications are above the second threshold level, where the first threshold level is less than the second threshold level; andtransmitting for further analysis information associated with the other malness scores, for one or more of the applications, when the other malness scores falls within a range that is between the first threshold level and the second threshold level. |