US2017250995A1PendingUtilityA1
Obtaining suspect objects based on detecting suspicious activity
Est. expiryMar 31, 2035(~8.7 yrs left)· nominal 20-yr term from priority
G06F 21/567G06F 2221/034H04L 63/145G06F 21/56H04L 63/1408
52
PatentIndex Score
0
Cited by
0
References
0
Claims
Abstract
A device may detect a suspicious activity. The device may automatically obtain a suspect object from a client device that is associated with the suspicious activity and based on detecting the suspicious activity. The suspect object may be an object that is possibly associated with the suspicious activity. The device may determine that the suspect object is malicious. The device may perform an action based on determining that the suspect object is malicious.
Claims
exact text as granted — not AI-modified1 - 20 . (canceled)
21 . A method, comprising:
detecting, by a device, a suspicious activity related to a first client device; obtaining, by the device, a suspect object based on detecting the suspicious activity; determining, by the device, that the suspect object is malicious; and causing, by the device, a second client device to perform an action based on determining that the suspect object is malicious,
the second client device being different than the first client device.
22 . The method of claim 21 , where obtaining the suspect object comprises:
obtaining the suspect object without user input.
23 . The method of claim 21 , where obtaining the suspect object comprises:
obtaining the suspect object based on the suspect object being capable of causing the first client device to perform the suspicious activity.
24 . The method of claim 23 , where the suspect object is an executable object.
25 . The method of claim 21 , where obtaining the suspect object comprises:
obtaining the suspect object using a remote management interface.
26 . The method of claim 21 , where causing the second client device to perform the action comprises:
causing the second client device to search for a file related to the suspect object to determine whether the second client device stores the suspect object.
27 . The method of claim 21 , where the suspicious activity comprises port scanning; and
where obtaining the suspect object comprises:
obtaining the suspect object based on the port scanning.
28 . A non-transitory computer-readable medium storing instructions, the instructions comprising:
one or more instructions that, when executed by one or more processors of a device, cause the one or more processors to:
detect a suspicious activity related to a first client device;
obtain a suspect object based on detecting the suspicious activity;
determine that the suspect object is malicious; and
cause a second client device to perform an action based on determining that the suspect object is malicious,
the second client device being different than the first client device.
29 . The non-transitory computer-readable medium of claim 28 , where the one or more instructions, that cause the one or more processors to obtain the suspect object, cause the one or more processors to:
obtain the suspect object without user input.
30 . The non-transitory computer-readable medium of claim 28 , where the one or more instructions, that cause the one or more processors to obtain the suspect object, cause the one or more processors to:
obtain the suspect object based on the suspect object being capable of causing the first client device to perform the suspicious activity.
31 . The non-transitory computer-readable medium of claim 30 , where the suspect object is an executable object.
32 . The non-transitory computer-readable medium of claim 28 , where the one or more instructions, that cause the one or more processors to obtain the suspect object, cause the one or more processors to:
obtain the suspect object using a remote management interface.
33 . The non-transitory computer-readable medium of claim 28 , where the one or more instructions, that cause the one or more processors to cause the second client device to perform the action, cause the one or more processors to:
cause the second client device to search for a file related to the suspect object to determine whether the second client device stores the suspect object.
34 . The non-transitory computer-readable medium of claim 28 , where the suspicious activity comprises port scanning; and
where the one or more instructions, that cause the one or more processors to obtain the suspect object, cause the one or more processors to:
obtain the suspect object based on the port scanning.
35 . A device, comprising:
one or more memories; and one or more processors, communicatively coupled to the one or more memories, to:
detect a suspicious activity related to a first client device;
obtain a suspect object based on detecting the suspicious activity;
determine that the suspect object is malicious; and
cause a second client device to perform an action based on determining that the suspect object is malicious,
the second client device being different than the first client device.
36 . The device of claim 35 , where the one or more processors, when obtaining the suspect object, are to:
obtain the suspect object based on the suspect object being capable of causing the first client device to perform the suspicious activity.
37 . The device of claim 36 , where the suspect object is an executable object.
38 . The device of claim 35 , where the one or more processors, when obtaining the suspect object, are to:
obtain the suspect object using a remote management interface.
39 . The device of claim 35 , where the one or more processors, when causing the second client device to perform the action, are to:
cause the second client device to search for a file related to the suspect object to determine whether the second client device stores the suspect object.
40 . The device of claim 35 , where the suspicious activity comprises port scanning; and
where the one or more processors, when obtaining the suspect object, are to:
obtain the suspect object based on the port scanning.Join the waitlist — get patent alerts
Track US2017250995A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.