Invention Grant
- Patent Title: Detection of adversaries through collection and correlation of assessments
- Patent Title (中): 通过收集和相关评估来检测对手
-
Application No.: US11893934Application Date: 2007-08-17
-
Publication No.: US08677479B2Publication Date: 2014-03-18
- Inventor: John Neystadt , Efim Hudis
- Applicant: John Neystadt , Efim Hudis
- Applicant Address: US WA Redmond
- Assignee: Microsoft Corporation
- Current Assignee: Microsoft Corporation
- Current Assignee Address: US WA Redmond
- Agent Ben Tabor; Kate Drakos; Micky Minhas
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
An automated arrangement for detecting adversaries is provided in which assessments of detected adversaries are reported to a reputation service from security devices, such as unified threat management systems in deployed customer networks. By using actual deployed networks, the number of available sensors can be very large to increase the scope of the adversary detection, while still observing real attacks and threats including those that are targeted to small sets of customers. The reputation service performs a number of correlations and validations on the received assessments to then return a reputation back to the security device in the enterprise network that can be used for blocking adversaries, but only when multiple, distinct sources report the same adversary in their assessments to thus ensure that the reputation is accurate and reliable.
Public/Granted literature
- US20080256619A1 Detection of adversaries through collection and correlation of assessments Public/Granted day:2008-10-16
Information query