System and method of assigning reputation scores to hosts

US2016359888A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2016359888-A1
Application numberUS-201615171580-A
CountryUS
Kind codeA1
Filing dateJun 2, 2016
Priority dateJun 5, 2015
Publication dateDec 8, 2016
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A method provides for receiving network traffic from a host having a host IP address and operating in a data center, and analyzing a malware tracker for IP addresses of hosts having been infected by a malware to yield an analysis. When the analysis indicates that the host IP address has been used to communicate with an external host infected by the malware to yield an indication, the method includes assigning a reputation score, based on the indication, to the host. The method can further include applying a conditional policy associated with using the host based on the reputation score. The reputation score can include a reduced reputation score from a previous reputation score for the host.

First claim

Opening claim text (preview).

What is claimed is: 1 . A method comprising: receiving network traffic from a host having a host IP address and operating in a data center, wherein data associated with the network traffic is received from at least a first capture agent at a device hardware layer of the data center, a second capture agent at a hypervisor layer of the data center, and a third capture agent at a virtual machine layer of the data center; analyzing a malware tracker for IP addresses of hosts having been infected by a malware to yield an analysis; and when the analysis indicates that the host IP address has been used to communicate with an external host infected by the malware to yield an indication, assigning a reputation score, based on the indication, to the host. 2 . The method of claim 1 , further comprising, applying a conditional policy associated with using the host based on the reputation score. 3 . The method of claim 1 , wherein the reputation score comprises a reduced reputation score from a previous reputation score for the host. 4 . The method of claim 1 , further comprising: analyzing an effectiveness of a policy related to communications with the host based on the reputation score. 5 . The method of claim 1 , further comprising: separating malicious and non-malicious behavior based on the indication. 6 . The method of claim 1 , wherein analyzing the malware tracker further comprises crawling multiple malware trackers. 7 . The method of claim 1 , wherein assigning the reputation score is further based on data associated with the host and received from a whois database. 8 . A system comprising: a processor; and a computer-readable storage medium storing instructions which, when executed by the processor, cause the processor to perform operations comprising: receiving network traffic from a host having a host IP address and operating in a data center, wherein data associated with the network traffic is received from at least a first capture agent at a device hardware layer of the data center, a second capture agent at a hypervisor layer of the data center, and a third capture agent at a virtual machine layer of the data center; analyzing a malware tracker for IP addresses of hosts having been infected by a malware to yield an analysis; and when the analysis indicates that the host IP address has been used to communicate with an external host infected by the malware to yield an indication, assigning a reputation score, based on the indication, to the host. 9 . The system of claim 8 , further comprising, applying a conditional policy associated with using the host based on the reputation score. 10 . The system of claim 8 , wherein the reputation score comprises a reduced reputation score from a previous reputation score for the host. 11 . The system of claim 8 , wherein the computer-readable storage medium stores further instructions which, when executed by the processor, cause the processor to perform operations comprising further comprising: analyzing an effectiveness of a policy related to communications with the host based on the reputation score. 12 . The system of claim 8 , further comprising: separating malicious and non-malicious behavior based on the indication. 13 . The system of claim 8 , wherein analyzing the malware tracker further comprises crawling multiple malware trackers. 14 . The system of claim 8 , wherein assigning the reputation score is further based on data associated with the host and received from a whois database. 15 . A computer-readable storage device storing instructions which, when executed by a processor, cause the processor to perform operations comprising: receiving network traffic from a host having a host IP address and operating in a data center, wherein data associated with the network traffic is received from at least a first capture agent at a device hardware layer of the data center, a second capture agent at a hypervisor layer of the data center, and a third capture agent at a virtual machine layer of the data center; analyzing a malware tracker for IP addresses of hosts having been infected by a malware to yield an analysis; and when the analysis indicates that the host IP address has been used to communicate with an external host infected by the malware to yield an indication, assigning a reputation score, based on the indication, to the host. 16 . The computer-readable storage device of claim 15 , wherein the computer-readable storage device stores further instructions which, when executed by the processor, cause the processor to perform operations comprising further comprising: applying a conditional policy associated with using the host based on the reputation score. 17 . The computer-readable storage device of claim 15 , wherein the reputation score comprises a reduced reputation score from a previous reputation score for the host. 18 . The computer-readable storage device of claim 15 , wherein the computer-readable storage device stores further instructions which, when executed by the processor, cause the processor to perform operations comprising further comprising: analyzing an effectiveness of a policy related to communications with the host based on the reputation score. 19 . The computer-readable storage device of claim 15 , wherein the computer-readable storage device stores further instructions which, when executed by the processor, cause the processor to perform operations comprising further comprising: separating malicious and non-malicious behavior based on the indication. 20 . The computer-readable storage device of claim 15 , wherein analyzing the malware tracker further comprises crawling multiple malware trackers.

Assignees

Inventors

Classifications

  • Drawing of charts or graphs · CPC title

  • based on quality criteria · CPC title

  • Policy-based network configuration management · CPC title

  • Test or assess software · CPC title

  • Dual mode as a secondary aspect · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2016359888A1 cover?
A method provides for receiving network traffic from a host having a host IP address and operating in a data center, and analyzing a malware tracker for IP addresses of hosts having been infected by a malware to yield an analysis. When the analysis indicates that the host IP address has been used to communicate with an external host infected by the malware to yield an indication, the method inc…
Who is the assignee on this patent?
Cisco Tech Inc
What technology area does this patent fall under?
Primary CPC classification H04L63/1425. Mapped technology areas include Electricity.
When was this patent published?
Publication date Thu Dec 08 2016 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 2 related publications on this page (citations in our corpus or others sharing the same primary CPC).