System and method of reporting and visualizing malware on mobile networks
US-9069957-B2 · Jun 30, 2015 · US
US9781148B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-9781148-B2 |
| Application number | US-201514973636-A |
| Country | US |
| Kind code | B2 |
| Filing date | Dec 17, 2015 |
| Priority date | Oct 21, 2008 |
| Publication date | Oct 3, 2017 |
| Grant date | Oct 3, 2017 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
Methods are provided for determining an enterprise risk level, for sharing security risk information between enterprises by identifying a security response by a first enterprise and then sharing the security response to a second enterprise when a relationship database profile for the first collection indicates the security response may be shared. Methods are also provided for determining whether to allow a request from an originating device where the request may have been initiated by a remote device.
Opening claim text (preview).
What is claimed is: 1. A method for determining an acceptable risk level for a collection to improve the functioning of mobile communications devices associated with the collection, the method comprising: accessing, by a server security component, a security database including risk information received from a plurality of collections, wherein the risk information includes source information that associates the risk information with one or more collections from the plurality; determining, by the server security component, a risk level for each collection based on the accessed risk information associated with each collection, the determined risk levels including a first risk level associated with a first collection; determining, by the server security component, an acceptable risk level based on the determined risk levels; providing, by the server security component to the first collection, the acceptable risk level and the first risk level; determining, by the server security component, a new first risk level for the first collection based in part on new risk information associated with the first collection; determining, by the server security component, a new acceptable risk level based on a plurality of determined risk levels; providing, by the server security component to the first collection, the new acceptable risk level and the new first risk level; comparing, by the server security component, the new first risk level to the new acceptable risk level; and, notifying, by the server security component, the first collection when the comparison indicates that the new first risk level is more than a threshold amount greater than the new acceptable risk level. 2. The method of claim 1 , wherein providing, by the server security component to the first collection, the acceptable risk level and the first risk level includes providing the acceptable risk level and the first risk level to a first administrator device associated with a first administrator of the first collection. 3. The method of claim 1 , further comprising: comparing, by the server security component, the first risk level to the acceptable risk level; and alerting, by the server security component, the first collection when the comparison indicates that the first risk level is more than a threshold more than the acceptable risk level. 4. The method of claim 1 , wherein the determining, by the server security component, a new first risk level for the first collection was performed in response to the server security component receiving a request for the new first risk level from the first collection. 5. The method of claim 4 , wherein the request for the new first risk level was initiated from a device associated with an administrator of the first collection after a change was made that potentially affected the first risk level. 6. The method of claim 1 , wherein the security database further includes a plurality of security risk responses, each security risk response associated with at least one of the plurality of collections, the method further comprising: identifying, by the server security component, a first security risk response in the security database, wherein the first security risk response is associated with the first collection; accessing, by the server security component, a relationship database including collection profiles related to the sharing of information between the plurality of collections, wherein the relationship database includes a first collection profile indicating that the first collection permits information related to the first security risk response to be shared with a second collection of the plurality when a determined second risk level associated with the second collection is equal to or less than a second threshold more than the acceptable risk level; comparing, by the server security component, the second risk level to the acceptable risk level; and, providing, by the server security component, the first security risk response to the second collection when the second risk level is equal to or less than the second threshold more than the acceptable level. 7. A method for determining whether to allow a network access request, comprising: receiving, by a destination computing device running a destination computing device security component, an access request by a terminal computing device in a series of at least one computing devices, wherein the series begins with an initial computing device, wherein the initial computing device initiates the access request, and wherein the series includes all computing devices used to transmit the access request to the destination computing device; requesting, by the destination computing device security component, terminal source information relating to the access request from a terminal device security component running on the terminal computing device; requesting, by the destination computing device security component, next source information relating to the access request from a next device security component running on a next computing device of the series when the destination computing device security component receives terminal source information from the terminal device security component and the terminal source information indicates that the terminal computing device is trusted, and is not the initiator of the access request, and identifies the next computing device in the series; allowing, by the destination computing device security component, the access request: when the destination computing device security component receives next source information from the next device security component, and when the next source information: indicates that the next computing device is trusted, and indicates that the next computing device is the initial computing device and is not being controlled by a remote device; and repeating, for additional next computing devices, requesting, by the destination computing device security component, additional next source information relating to the initiator of the access request from additional next device security components running on additional next computing devices when the destination computing device security component receives source information from a previous device security component and the previous source information indicates that the previous computing device is trusted, and is not the initiator of the access request, and identifies the additional next computing device in the series, until the destination computing device security component receives additional next source information from an additional next device security component and the additional next source information indicates that the additional next computing device is trusted, and is the initiator of the access request. 8. A method for determining whether to allow a network access request, comprising: receiving, by a destination computing device running a destination computing device security component, an access request by a terminal computing device in a series of at least one computing devices, wherein the series begins with an initial computing device, wherein the initial computing device is the initiator of the access request, and wherein the access request is transmitted to the destination computing device using the series; requesting, by the destination computing device security component, terminal source information relating to the initiator of the access request from a terminal device security component running on the terminal computing device; requesting, by the destination computing device security component, next source information relating to the initiator of the access request from a next device security component running on a next computing device when the destination computing
the attack involving the propagation of malware through the network, e.g. viruses, trojans or worms · CPC title
by monitoring network traffic (monitoring network traffic per se H04L43/00) · CPC title
Vulnerability analysis · CPC title
Detection or prevention of fraud · CPC title
Filtering policies (mail message filtering H04L51/212) · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.