发明名称 Detection of adversaries through collection and correlation of assessments
摘要 An automated arrangement for detecting adversaries is provided in which assessments of detected adversaries are reported to a reputation service from security devices, such as unified threat management systems in deployed customer networks. By using actual deployed networks, the number of available sensors can be very large to increase the scope of the adversary detection, while still observing real attacks and threats including those that are targeted to small sets of customers. The reputation service performs a number of correlations and validations on the received assessments to then return a reputation back to the security device in the enterprise network that can be used for blocking adversaries, but only when multiple, distinct sources report the same adversary in their assessments to thus ensure that the reputation is accurate and reliable.
申请公布号 US8677479(B2) 申请公布日期 2014.03.18
申请号 US20070893934 申请日期 2007.08.17
申请人 NEYSTADT JOHN;HUDIS EFIM;MICROSOFT CORPORATION 发明人 NEYSTADT JOHN;HUDIS EFIM
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项
地址