Machine learned model for generating opinionated threat assessments of security vulnerabilities
US-2024411898-A1 · Dec 12, 2024 · US
US2017230397A1 · US · A1
| Field | Value |
|---|---|
| Publication number | US-2017230397-A1 |
| Application number | US-201715498325-A |
| Country | US |
| Kind code | A1 |
| Filing date | Apr 26, 2017 |
| Priority date | Oct 21, 2008 |
| Publication date | Aug 10, 2017 |
| Grant date | — |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A server receives from a mobile communication device information about a data object (e.g., application) on the device when the device cannot assess the data object. The server uses the information along with other information stored at the server to assess the data object. Based on the assessment, the device may be permitted to access the data object or the device may not be permitted to access the data object. The other information stored at the server can include data objects known to be bad, data objects known to be good, or both.
Opening claim text (preview).
What is claimed is: 1 . A non-transitory, non-volatile, non-printed computer-readable storage medium having stored thereon a plurality of instructions, which, when executed by a processor of a server, cause the server to perform the steps of a method for assessing a data object present on a mobile communications device, the assessment provided by a server, the method comprising: before receiving data identifying at least a portion of the data object present on the mobile communications device at the server, determining if previously stored definition information stored in a local store at the mobile communications device corresponds to the data identifying at least a portion of the data object present on the mobile communications device, the local store storing a corresponding assessment for the previously stored definition information; and, if the previously stored definition information in the local store at the mobile communications device does not correspond to the data identifying at least a portion of the data object present on the mobile communications device, then at the server, receiving data identifying at least a portion of the data object present on the mobile communications device at the server, determining if previously-stored definition information for a data object corresponds to the received data, the definition information stored in a data store accessible by the server, the data store storing a corresponding assessment for the definition information; if the previously-stored definition information corresponds to the received data from the mobile communications device, then at the server, providing the assessment of the data object present on the mobile communications device corresponding to the previously-stored definition information. 2 . The non-transitory, non-volatile, non-printed computer-readable storage medium of claim 1 , wherein the data identifying at least a portion of the data object present on the mobile communications device is application data for the data object present on the mobile communications device. 3 . The non-transitory, non-volatile, non-printed computer-readable storage medium of claim 1 , wherein the data identifying at least a portion of the data object present on the mobile communications device is behavioral data for the data object present on the mobile communications device. 4 . The non-transitory, non-volatile, non-printed computer-readable storage medium of claim 1 , wherein the data identifying at least a portion of the data object present on the mobile communications device is metadata for the data object present on the mobile communications device. 5 . The non-transitory, non-volatile, non-printed computer-readable storage medium of claim 1 , wherein the data identifying at least a portion of the data object present on the mobile communications device includes at least a portion of the data object present on the mobile communications device. 6 . The non-transitory, non-volatile, non-printed computer-readable storage medium of claim 1 , wherein the previously stored definition information includes a hash identifier for the data object present on the mobile communications device. 7 . The non-transitory, non-volatile, non-printed computer-readable storage medium of claim 1 , wherein the previously stored definition information includes a package name for the data object present on the mobile communications device. 8 . The non-transitory, non-volatile, non-printed computer-readable storage medium of claim 1 , wherein the previously stored definition information includes at least a portion of the data object present on the mobile communications device. 9 . The non-transitory, non-volatile, non-printed computer-readable storage medium of claim 1 , wherein the previously stored definition information includes an identifier for the data object present on the mobile communications device. 10 . The non-transitory, non-volatile, non-printed computer-readable storage medium of claim 1 , further comprising: if the data identifying at least a portion of the data object present on the mobile communications device does not correspond to previously stored definition information stored in the data store accessible to the server, then analyzing, by the server, at least a portion of the data identifying at least a portion of the data object present on the mobile communications device to determine an assessment corresponding to the data identifying at least a portion of the data object present on the mobile communications device; and, storing the assessment corresponding to the data identifying at least a portion of the data object present on the mobile communications device in the data store accessible to the server. 11 . The non-transitory, non-volatile, non-printed computer-readable storage medium of claim 10 , wherein analyzing at least a portion of the data identifying at least a portion of the data object present on the mobile communications device comprises analyzing by a decision component accessible by the server. 12 . The non-transitory, non-volatile, non-printed computer-readable storage medium of claim 1 , further comprising: if the data identifying at least a portion of the data object present on the mobile communications device does not correspond to definition information stored in the data store accessible to the server, then analyzing, by the server, at least a portion of the data identifying at least a portion of the data object present on the mobile communications device to determine an assessment corresponding to the data identifying at least a portion of the data object present on the mobile communications device; requesting, by the server, additional data pertaining to the data object present on the mobile communications device; analyzing, by the server, at least a portion of the additional data pertaining to the data object present on the mobile communications device to determine an assessment corresponding to the data object present on the mobile communications device; and storing the determined assessment in the data store accessible to the server. 13 . The non-transitory, non-volatile, non-printed computer-readable storage medium of claim 1 , further comprising, after the step of providing the assessment, if the assessment indicates that the data object present on the mobile communications device is undesirable, then at the server, transmitting instructions to the mobile communications device to prevent the mobile communications device from accessing the data object present on the mobile communications device. 14 . The non-transitory, non-volatile, non-printed computer-readable storage medium of claim 1 , further comprising, after the step of providing the assessment, if the assessment indicates that the data object present on the mobile communications device is undesirable, then at the server, transmitting a notification to the mobile communications device. 15 . The non-transitory, non-volatile, non-printed computer-readable storage medium of claim 14 , wherein the notification is a warning. 16 . The non-transitory, non-volatile, non-printed computer-readable storage medium of claim 14 , wherein the notification is an instruction to uninstall the data object. 17 . A non-transitory, non-volatile, non-printed computer-readable storage medium having stored thereon a plurality of instructions, which, when executed by a processor of a server, cause the server to perform the steps of a method for assessing a data object present on a mobile communications device by a server comprising: receivin
the attack involving the propagation of malware through the network, e.g. viruses, trojans or worms · CPC title
by monitoring network traffic (monitoring network traffic per se H04L43/00) · CPC title
Filtering policies (mail message filtering H04L51/212) · CPC title
Protecting privacy or anonymity, e.g. protecting personally identifiable information [PII] · CPC title
Vulnerability analysis · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.