US2020042720A1PendingUtilityA1

Pre-launch process vulnerability assessment

Assignee: MCAFEE LLCPriority: Sep 22, 2014Filed: Oct 15, 2019Published: Feb 6, 2020
Est. expirySep 22, 2034(~8.2 yrs left)· nominal 20-yr term from priority
G06F 21/554G06F 2221/033G06F 21/34G06F 21/566G06F 21/51G06F 21/577
56
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

There is disclosed in one example a server apparatus, including: a hardware platform including a processor and a memory; a network interface; and a vulnerability assessment server engine including instructions encoded within the memory to instruct the processor to: receive via the network interface an endpoint payload including a platform identification string, including an identifier for an application and an identifier for an action to be taken by the application; query a vulnerability database and platform identification string database to procure an application-specific reputation for the action; and send via the network interface the application-specific reputation for the action.

Claims

exact text as granted — not AI-modified
What is claimed is: 
     
         1 . A server apparatus, comprising:
 a hardware platform comprising a processor and a memory;   a network interface; and   a vulnerability assessment server engine comprising instructions encoded within the memory to instruct the processor to:
 receive via the network interface an endpoint payload comprising a platform identification string, comprising an identifier for an application and an identifier for an action to be taken by the application; 
 query a vulnerability database and platform identification string database to procure an application-specific reputation for the action; and 
 send via the network interface the application-specific reputation for the action. 
   
     
     
         2 . The server apparatus of  claim 1 , wherein the vulnerability assessment server engine further comprises instructions to:
 determine that the application has an available patch to repair a vulnerability of the application related to the action; and   push the patch to the endpoint via the network interface.   
     
     
         3 . The server apparatus of  claim 1 , wherein the action is installation of the application, and wherein the application-specific reputation for the action is to block installation of the application. 
     
     
         4 . The server apparatus of  claim 2 , wherein the vulnerability assessment server engine further comprises instructions to instruct the endpoint to install a less vulnerable application to perform the action. 
     
     
         5 . The server apparatus of  claim 1 , wherein pushing the patch comprises creating a work item, and assigning the work item to an update agent of the endpoint. 
     
     
         6 . The server apparatus of  claim 1 , wherein the vulnerability assessment server engine further comprises instructions to receive a confirmation that the endpoint has installed an updated application or applied a requested patch, and to update a platform identification string for the endpoint. 
     
     
         7 . The server apparatus of  claim 6 , wherein the vulnerability assessment server engine is further to instruct a shim agent of the endpoint to monitor the updated or patched application. 
     
     
         8 . The server apparatus of  claim 1 , wherein the vulnerability assessment server engine further comprises instructions to interface with a research service to identify new vulnerabilities in applications. 
     
     
         9 . The server apparatus of  claim 1 , wherein the platform identification string is a common platform enumeration (CPE)-like string. 
     
     
         10 . One or more tangible, non-transitory computer-readable media having stored thereon executable instructions to instruct a processor to:
 receive from an endpoint via a network interface a common platform enumeration (CPE)-like string comprising an identification of a requested action by a process of the endpoint;   query vulnerability and CPE databases to determine a process-specific reputation for the requested action;   send via the network interface the process-specific reputation for the action;   determine that a host application of the process has an available update, or that the action can be provided by a more secure application; and   instruct the endpoint via the network interface to apply the available update or to install the more secure application.   
     
     
         11 . The one or more tangible, non-transitory computer-readable media of  claim 10 , wherein the instructions are further to update the CPE database according to the instruction to the endpoint. 
     
     
         12 . A computing apparatus, comprising:
 a processor and a memory; and   a process-reputation store comprising a plurality of process identifiers, and one or more whitelisted actions on a per-process basis;   instructions encoded within the memory to instruct the processor to provide a shim application to:
 identify a process for inspection; 
 hook an attempted action of the process; 
 determine that the attempted action is not a pre-load action for the process and is not a whitelisted action for the process; 
 compute a reputation for the action in context of the process; and 
 according to the computed reputation, whitelist, blacklist, or graylist the action in context of the process. 
   
     
     
         13 . The computing apparatus of  claim 12 , wherein the process-reputation store further comprises blacklist and graylist reputations for at least some processes. 
     
     
         14 . The computing apparatus of  claim 13 , wherein the instructions are further to cache the reputation in the process-reputation store. 
     
     
         15 . The computing apparatus of  claim 14 , wherein the instructions are to solicit feedback before executing a graylist action. 
     
     
         16 . The computing apparatus of  claim 15 , wherein the instructions are to cache the feedback in the process-reputation store. 
     
     
         17 . The computing apparatus of  claim 15 , wherein soliciting feedback comprises requesting verification from a local user. 
     
     
         18 . The computing apparatus of  claim 12 , wherein computing the reputation for the action comprises sending to a remote server a payload comprising an identifier for the process and an identifier for the action, and receiving the reputation from the server. 
     
     
         19 . The computing apparatus of  claim 18 , wherein the payload is a platform identification string. 
     
     
         20 . The computing apparatus of  claim 19 , wherein the platform identification string is a common platform enumeration (CPE)-like string.

Join the waitlist — get patent alerts

Track US2020042720A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.