Risk information output device, information output system, risk information output method, and recording medium
US-2024414180-A1 · Dec 12, 2024 · US
US2016234232A1 · US · A1
| Field | Value |
|---|---|
| Publication number | US-2016234232-A1 |
| Application number | US-201615040670-A |
| Country | US |
| Kind code | A1 |
| Filing date | Feb 10, 2016 |
| Priority date | Feb 11, 2015 |
| Publication date | Aug 11, 2016 |
| Grant date | — |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
According to some aspects, disclosed methods and systems may comprise generating a profile that is based on monitoring a communication pattern associated with a device. Subsequent communications associated with the device may be monitored. Based on the profile and the subsequent communication, a security status may be associated with the device.
Opening claim text (preview).
1 . A method comprising: generating, by a computing device, a profile of expected communication behavior for one or more first devices associated with a first network based on monitoring, at a first time, at least one communication to or from each of the one or more first devices; monitoring, at a second time, communication associated with each of the one or more first devices; and determining, based respectively on the profile associated with each of the one or more devices and on the monitoring at the second time, a security status associated with each of the one or more first devices. 2 . The method of claim 1 , further comprising: performing an action based on the security status associated with each of the one or more first devices. 3 . The method of claim 2 , wherein the performing comprises limiting communication to or from the one or more first devices, blocking communication to or from the one or more first devices, or allowing communication to or from the one or more first devices. 4 . The method of claim 3 , wherein the one or more first devices are initially obstructed from performing one or more communication actions via the first network, and wherein allowing the communication to or from the one or more first devices comprises allowing the one or more first devices to perform the one or more communication actions via the first network. 5 . The method of claim 1 , wherein determining the security status comprises associating, based on the monitoring at the second time and the profile, one of a plurality of device threat categories with each of the one or more first devices, wherein the device threat categories are based on level of threat to the first network. 6 . The method of claim 1 , further comprising generating an indication of the security status associated with each of the one or more first devices. 7 . The method of claim 6 , wherein generating the indication of the security status comprises providing the security status via a user interface, the method further comprising receiving, via the user interface, an input indicating whether the monitored at least one communication is approved. 8 . The method of claim 1 , wherein generating the profile of expected communication behavior for each of the one or more first devices further comprises generating the profile based on one or more of the following: determining information associated with one or more second devices with which a respective first device typically communicates; a packet size associated with communication to or from a respective first device; a frequency associated with communication to or from a respective first device; timing information associated with communication to or from a respective first device; or a size associated with communication to or from a respective first device. 9 . The method of claim 1 , wherein in response to determining that the communication at the second time deviates from a respective profile of expected communication behavior, limiting access of the at least one of the one or more first devices to one or more resources associated with the first network. 10 . The method of claim 1 , wherein the monitoring at the first time comprises monitoring communication between the one or more first devices and a second device that is not associated with the first network. 11 . The method of claim 1 , wherein the monitoring at the first time comprises monitoring communication between the one or more first devices and a second device that is associated with the first network. 12 . The method of claim 1 , further comprising: associating a device type with each of the one or more first devices; and wherein the generating comprises generating a respective profile of expected communication behavior based on a respective device type. 13 . The method of claim 1 , further comprising: determining that a device type associated with a second device corresponds to a device type associated with at least one of the one or more first devices; and determining a security status associated with the second device based on the profile of expected communication behavior associated with the at least one of the one or more first devices. 14 . The method of claim 13 , wherein the second device is associated with a second network. 15 . A method comprising: generating a profile of expected communication behavior associated with a first device associated with a network based on monitoring communication between the first device and a second device via the network; monitoring subsequent communication associated with the first device; and determining whether to modify network access associated with the first device based on a degree of deviation between the subsequent communication associated with the first device and the profile of expected communication behavior. 16 . The method of claim 15 , wherein determining to modify comprises determining to limit the network access associated with the first device responsive to the deviation satisfying a threshold level. 17 . The method of claim 15 , wherein determining to modify comprises determining to expand the network access associated with the first device responsive to the deviation falling below a threshold level. 18 . The method of claim 15 , wherein the one or more second devices are associated with a second network external to the network. 19 . A method comprising: determining, by a computing device, a profile of expected communication behavior for a first device associated with a network; monitoring communication associated with the first device; determining whether the monitored communication conflicts with the profile of expected communication behavior; and performing, based on the determining, a security action associated with the first device. 20 . The method of claim 19 , wherein performing the security action comprises modifying a status of a network permission associated with the first device.
Traffic logging, e.g. anomaly detection · CPC title
by monitoring network traffic (monitoring network traffic per se H04L43/00) · CPC title
Event detection, e.g. attack signature detection · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.