Invention Grant
- Patent Title: Labeling objects on an endpoint for encryption management
-
Application No.: US14485769Application Date: 2014-09-14
-
Publication No.: US09965627B2Publication Date: 2018-05-08
- Inventor: Kenneth D. Ray , Daniel Salvatore Schiappa , Simon Neil Reed , Mark D. Harris , Neil Robert Tyndale Watkiss , Andrew J. Thomas , Robert W. Cook , Harald Schütz , John Edward Tyrone Shaw , Anthony John Merry
- Applicant: Sophos Limited
- Applicant Address: GB Abingdon
- Assignee: Sophos Limited
- Current Assignee: Sophos Limited
- Current Assignee Address: GB Abingdon
- Agency: Strategic Patents, P.C.
- Main IPC: G06F3/033
- IPC: G06F3/033 ; G06F21/55 ; G06F21/56 ; G06F21/62 ; H04L29/06

Abstract:
Threat detection instrumentation is simplified by providing and updating labels for computing objects in a context-sensitive manner. This may include simple labeling schemes to distinguish between objects, e.g., trusted/untrusted processes or corporate/private data. This may also include more granular labeling schemes such as a three-tiered scheme that identifies a category (e.g., financial, e-mail, game), static threat detection attributes (e.g., signatures, hashes, API calls), and explicit identification (e.g., what a file or process calls itself). By tracking such data for various computing objects and correlating these labels to malware occurrences, rules can be written for distribution to endpoints to facilitate threat detection based on, e.g., interactions of labeled objects, changes to object labels, and so forth. In this manner, threat detection based on complex interactions of computing objects can be characterized in a platform independent manner and pre-processed on endpoints without requiring significant communications overhead with a remote threat management facility.
Public/Granted literature
- US20160078225A1 LABELING OBJECTS ON AN ENDPOINT FOR ENCRYPTION MANAGEMENT Public/Granted day:2016-03-17
Information query