System and method of reporting and visualizing malware on mobile networks
US-9069957-B2 · Jun 30, 2015 · US
US9779253B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-9779253-B2 |
| Application number | US-201615393089-A |
| Country | US |
| Kind code | B2 |
| Filing date | Dec 28, 2016 |
| Priority date | Oct 21, 2008 |
| Publication date | Oct 3, 2017 |
| Grant date | Oct 3, 2017 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Methods and systems are provided for sharing security risk information between collections of computing devices, such as mobile communications devices, to improve the functioning of devices associated with the collections. The methods and systems disclosed may share security risk information by identifying a security risk response by a first collection and then providing the security risk response to a second collection when a relationship database profile for the first collection indicates the security response may be shared with the second collection. Methods and systems are also provided for determining whether to allow a request from an originating device where the request may have been initiated by a remote device.
Opening claim text (preview).
What is claimed is: 1. A method for sharing security risk responses between a plurality of collections to improve the functioning of mobile communications devices associated with at least one collection based on the shared security risk responses, the method comprising: accessing, by a server security component, a security database including a plurality of security risk responses, each security risk response associated with at least one of the plurality of collections; identifying, by the server security component, a first security risk response in the security database, wherein the first security risk response was implemented by at least one of the plurality of collections; determining, by the server security component from the security database, a first collection associated with the first security risk response; accessing, by the server security component, a relationship database, the relationship database including collection profiles related to the sharing of information between the plurality of collections, the collection profiles including collection attributes; identifying, by the server security component from information related to the first security risk response in the security database, a set of response attributes of the first security risk response; identifying, for a second collection, a set of collection attributes that are similar to response attributes in set of response attributes; receiving, by the server security component, a response attribute value for each response attribute in the set of response attributes; assigning, by the server security component, a collection attribute value to each of the attributes in the set of collection attributes, wherein the collection attribute values are assigned to a collection attribute based on the response attribute value of the similar corresponding response attribute in the set of response attributes; summing, by the server security component, the assigned collection attribute values; and, providing, by the server security component, the first security risk response to the second collection: (i) when a first collection profile indicates that the first collection permits information related to the first security risk response to be provided to the second collection; and (ii) when the sum of the assigned collection attribute values equals or exceeds a threshold value. 2. The method of claim 1 , wherein the first security response was initiated from a first administrator device associated with a first administrator of the first collection and wherein the providing the first security risk response to the second collection includes providing the first security risk response to a second administrator device associated with a second administrator of the second collection. 3. The method of claim 1 , wherein the first security risk response was implemented in response to a first security risk type and wherein information related to the first security risk response includes information related to the first security risk type, the method further including: determining, by the server security component from the security database information, a third collection, the third collection having implemented a second security risk response in response to the first security risk type; accessing, by the server security component, the relationship database; and, providing, by the server security component, the second security risk response to the second collection when a third collection profile indicates that the third collection permits information related to the second security risk response to be provided to the second collection. 4. The method of claim 3 , further including providing, by the server security component, information related to the first security risk type to the second collection, the information related to the first security risk type including statistical information relating to the prevalence or propagation of the risk type, the statistical information derived from the security database. 5. The method of claim 1 , wherein the security database includes risk information acquired in part from device security components on mobile communications devices, wherein the mobile communications devices are associated with at least one collection of the plurality of collections, wherein the device security components send risk information related to security risk responses to the server security component, and wherein the server security component is associated with a platform, the platform associated with an entity separate from any of the plurality of collections. 6. The method of claim 1 further comprising: determining, for the set of collection attributes, the number of collection attributes in the set collection attributes, wherein the providing, by the server security component, the first security risk response to the second collection includes providing, by the server security component, the first security risk response to the second collection: (i) when the first collection profile indicates that the first collection permits information related to the first security risk response to be provided to the second collection; (ii) when the sum of the assigned collection attribute values equals or exceeds a threshold value; and (iii) when the determined number of collection attributes in the set of collection attributes equals or exceeds a threshold number. 7. The method of claim 6 , wherein the response attributes include attributes related to at least one of a risk, a mobile communications device, a collection, or a software, and wherein the collection attributes include attributes related to at least one of a collection of the plurality, the mobile communications devices of a collection, or a software of the collection. 8. The method of claim 1 , wherein the relationship database further includes relationship information related to the sharing of levels of information between the plurality of collections, wherein the first security risk response includes information of a first level and information of a second level, and wherein providing, by the server security component, the first security risk response to the second collection includes: providing, by the server security component, the first level information to the second collection and not providing the second level information to the second collection: (i) when the first collection profile indicates that the first collection permits information related to the first security risk response to be provided to the second collection; (ii) when the sum of the assigned collection attribute values equals or exceeds a threshold value; and (iii) when the first collection profile indicates that the first collection permits the first level information to be provided to the second collection and does not permit the second level information to be provide to the second collection. 9. The method of claim 1 , wherein the identified first security risk response includes a response to a detected security risk event, and wherein the detected security risk event was detected by a device security component on a mobile communications device associated with the first collection. 10. The method of claim 1 , wherein the identified first security risk response includes a response to a detected security risk event, and wherein the detected security risk event was detected by the server security component based on an analysis of the security database information. 11. The method of claim 1 , wherein the second collection automatically implements the first security risk response. 12. A method for sharing security risk responses between a plurality of collections to impro
by monitoring network traffic (monitoring network traffic per se H04L43/00) · CPC title
the attack involving the propagation of malware through the network, e.g. viruses, trojans or worms · CPC title
involving event detection and direct action · CPC title
Vulnerability analysis · CPC title
Detection or prevention of fraud · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.