Pre-launch process vulnerability assessment
Abstract
There is disclosed in one example a server apparatus, including: a hardware platform including a processor and a memory; a network interface; and a vulnerability assessment server engine including instructions encoded within the memory to instruct the processor to: receive via the network interface an endpoint payload including a platform identification string, including an identifier for an application and an identifier for an action to be taken by the application; query a vulnerability database and platform identification string database to procure an application-specific reputation for the action; and send via the network interface the application-specific reputation for the action.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A server apparatus, comprising:
a hardware platform comprising a processor and a memory; a network interface; and a vulnerability assessment server engine comprising instructions encoded within the memory to instruct the processor to:
receive via the network interface an endpoint payload comprising a platform identification string, comprising an identifier for an application and an identifier for an action to be taken by the application;
query a vulnerability database and platform identification string database to procure an application-specific reputation for the action; and
send via the network interface the application-specific reputation for the action.
2 . The server apparatus of claim 1 , wherein the vulnerability assessment server engine further comprises instructions to:
determine that the application has an available patch to repair a vulnerability of the application related to the action; and push the patch to the endpoint via the network interface.
3 . The server apparatus of claim 1 , wherein the action is installation of the application, and wherein the application-specific reputation for the action is to block installation of the application.
4 . The server apparatus of claim 2 , wherein the vulnerability assessment server engine further comprises instructions to instruct the endpoint to install a less vulnerable application to perform the action.
5 . The server apparatus of claim 1 , wherein pushing the patch comprises creating a work item, and assigning the work item to an update agent of the endpoint.
6 . The server apparatus of claim 1 , wherein the vulnerability assessment server engine further comprises instructions to receive a confirmation that the endpoint has installed an updated application or applied a requested patch, and to update a platform identification string for the endpoint.
7 . The server apparatus of claim 6 , wherein the vulnerability assessment server engine is further to instruct a shim agent of the endpoint to monitor the updated or patched application.
8 . The server apparatus of claim 1 , wherein the vulnerability assessment server engine further comprises instructions to interface with a research service to identify new vulnerabilities in applications.
9 . The server apparatus of claim 1 , wherein the platform identification string is a common platform enumeration (CPE)-like string.
10 . One or more tangible, non-transitory computer-readable media having stored thereon executable instructions to instruct a processor to:
receive from an endpoint via a network interface a common platform enumeration (CPE)-like string comprising an identification of a requested action by a process of the endpoint; query vulnerability and CPE databases to determine a process-specific reputation for the requested action; send via the network interface the process-specific reputation for the action; determine that a host application of the process has an available update, or that the action can be provided by a more secure application; and instruct the endpoint via the network interface to apply the available update or to install the more secure application.
11 . The one or more tangible, non-transitory computer-readable media of claim 10 , wherein the instructions are further to update the CPE database according to the instruction to the endpoint.
12 . A computing apparatus, comprising:
a processor and a memory; and a process-reputation store comprising a plurality of process identifiers, and one or more whitelisted actions on a per-process basis; instructions encoded within the memory to instruct the processor to provide a shim application to:
identify a process for inspection;
hook an attempted action of the process;
determine that the attempted action is not a pre-load action for the process and is not a whitelisted action for the process;
compute a reputation for the action in context of the process; and
according to the computed reputation, whitelist, blacklist, or graylist the action in context of the process.
13 . The computing apparatus of claim 12 , wherein the process-reputation store further comprises blacklist and graylist reputations for at least some processes.
14 . The computing apparatus of claim 13 , wherein the instructions are further to cache the reputation in the process-reputation store.
15 . The computing apparatus of claim 14 , wherein the instructions are to solicit feedback before executing a graylist action.
16 . The computing apparatus of claim 15 , wherein the instructions are to cache the feedback in the process-reputation store.
17 . The computing apparatus of claim 15 , wherein soliciting feedback comprises requesting verification from a local user.
18 . The computing apparatus of claim 12 , wherein computing the reputation for the action comprises sending to a remote server a payload comprising an identifier for the process and an identifier for the action, and receiving the reputation from the server.
19 . The computing apparatus of claim 18 , wherein the payload is a platform identification string.
20 . The computing apparatus of claim 19 , wherein the platform identification string is a common platform enumeration (CPE)-like string.Join the waitlist — get patent alerts
Track US2020042720A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.