USRE48043EActiveUtility
System, method and computer program product for sending unwanted activity information to a central system
Est. expiryDec 10, 2027(~1.4 yrs left)· nominal 20-yr term from priority
Inventors:Ahmed Said Sallam
G06F 21/552G06F 21/566H04L 63/1416
57
PatentIndex Score
0
Cited by
35
References
32
Claims
Abstract
A system, method and computer program product are provided for sending, to a central system, information associated with unwanted activity. In use, information associated with unwanted activity is identified utilizing a plurality of different types of security systems. Further, the information is sent to a central system.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1. A method, comprising:
receiving one or more rules from a central system;
identifying information associated with unwanted activity, utilizing a plurality of different types of security systems of a client system, which includes a processor and a memory, and which is configured with a plurality of rules for resolving the unwanted activity independent of instructions provided by a the central system, wherein at least one of the different types of security systems utilizes behavioral monitoring that includes heuristics of the unwanted activity to detect the unwanted activity without utilizing the one or more rules, and the client system is further configured to detect the unwanted activity utilizing the one or more rules;
sending the information to the central system for aggregating the information with additional information sets provided by additional client systems; and
receiving a response sent from the central system to the client system and to the additional client systems, wherein the response is based on the information and is indicative of whether the information was verified as being associated with the unwanted activity, and wherein the response includes a rule for removing code associated with the unwanted activity, and the response includes a rule for detecting future instances of the information, and the response includes a rule for adding the information to a blacklist.
2. The method of claim 1 , wherein the plurality of different types of security systems include two or more of a firewall, an intrusion prevention system, an anti-spyware system, and a virus scanner.
3. The method of claim 1 , wherein the information is correlated prior to sending the information to the central system.
4. The method of claim 1 , wherein the information includes a source of the unwanted activity.
5. The method of claim 1 , wherein the information includes a decision made in response to the unwanted activity.
6. The method of claim 5 , wherein the decision is to block execution of the unwanted activity.
7. The method of claim 1 , wherein the information includes an alert.
8. The method of claim 1 , further comprising detecting the unwanted activity, utilizing the plurality of different security systems.
9. The method of claim 8 , wherein the unwanted activity is detected utilizing at least one rule received from the central system.
10. The method of claim 1 , wherein the information is sent to a database via the central system.
11. The method of claim 1 , wherein the information is sent to the central system for correlation with other information associated with at least one network security system.
12. A computer program product embodied on a non-transitory computer readable medium for performing operations, comprising:
receiving one or more rules from a central system;
identifying information associated with unwanted activity, utilizing a plurality of different types of security systems of a client system, which includes a processor and a memory, and which is configured with a plurality of rules for resolving the unwanted activity independent of instructions provided by a the central system, wherein at least one of the different types of security systems utilizes behavioral monitoring that includes heuristics of the unwanted activity to detect the unwanted activity without utilizing the one or more rules, and the client system is further configured to detect the unwanted activity utilizing the one or more rules;
sending the information to the central system for aggregating the information with additional information sets provided by additional client systems; and
receiving a response sent from the central system to the client system and to the additional client systems, wherein the response is based on the information and is indicative of whether the information was verified as being associated with the unwanted activity, and wherein the response includes a rule for removing code associated with the unwanted activity, and the response includes a rule for detecting future instances of the information, and the response includes a rule for adding the information to a blacklist.
13. An apparatus, comprising:
a client system including a processor, wherein the apparatus is configured forand a memory; and
logic that is executable by the processor for:
receiving one or more rules from a central system;
identifying information associated with unwanted activity, utilizing a plurality of different types of security systems of a the client system, which includes a processor and a memory, and which is configured with a plurality of rules for resolving the unwanted activity independent of instructions provided by a the central system, wherein at least one of the different types of security systems utilizes behavioral monitoring that includes heuristics of the unwanted activity to detect the unwanted activity without utilizing the one or more rules, and the client system is further configured to detect the unwanted activity utilizing the one or more rules;
sending the information to the central system configured for aggregating the information with additional information sets provided by additional client systems; and
receiving a response sent from the central system to the client system and to the additional client systems, wherein the response is based on the information and is indicative of whether the information was verified as being associated with the unwanted activity, and wherein the response includes a rule for removing code associated with the unwanted activity, and the response includes a rule for detecting future instances of the information, and the response includes a rule for adding the information to a blacklist.
14. The apparatus of claim 13 , wherein the processor remains in communication with the memory and a display via a bus.
15. The computer program product of claim 12, wherein the plurality of different types of security systems includes two or more of a firewall, an intrusion prevention system, an anti-spyware system, and a virus scanner.
16. The computer program product of claim 12, wherein the information is correlated prior to sending the information to the central system.
17. The computer program product of claim 12, wherein the information includes a source of the unwanted activity.
18. The computer program product of claim 12, wherein the information includes a decision made in response to the unwanted activity.
19. The computer program product of claim 18, wherein the decision is to block execution of the unwanted activity.
20. The computer program product of claim 12, wherein the information includes an alert.
21. The computer program product of claim 12, wherein the computer program product is embodied on the non-transitory computer readable medium for performing further operations comprising detecting the unwanted activity, utilizing the plurality of different types of security systems.
22. The computer program product of claim 12, wherein the information is sent to a database via the central system.
23. The computer program product of claim 12, wherein the information is sent to the central system for correlation with other information associated with at least one network security system.
24. The apparatus of claim 13, wherein the plurality of different types of security systems includes two or more of a firewall, an intrusion prevention system, an anti-spyware system, and a virus scanner.
25. The apparatus of claim 13, wherein the information is correlated prior to sending the information to the central system.
26. The apparatus of claim 13, wherein the information includes a source of the unwanted activity.
27. The apparatus of claim 13, wherein the information includes a decision made in response to the unwanted activity.
28. The apparatus of claim 27, wherein the decision is to block execution of the unwanted activity.
29. The apparatus of claim 13, wherein the information includes an alert.
30. The apparatus of claim 13, wherein the apparatus is further configured for detecting the unwanted activity, utilizing the plurality of different types of security systems.
31. The apparatus of claim 13, wherein the information is sent to a database via the central system.
32. The apparatus of claim 13, wherein the information is sent to the central system for correlation with other information associated with at least one network security system.Join the waitlist — get patent alerts
Track USRE48043E — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.