Invention Grant
- Patent Title: Using reputation to avoid false malware detections
-
Application No.: US17721614Application Date: 2022-04-15
-
Publication No.: US11722516B2Publication Date: 2023-08-08
- Inventor: Andrew J. Thomas
- Applicant: Sophos Limited
- Applicant Address: GB Abingdon
- Assignee: Sophos Limited
- Current Assignee: Sophos Limited
- Current Assignee Address: GB Abingdon
- Agency: Strategic Patents, P.C.
- Main IPC: H04L9/40
- IPC: H04L9/40

Abstract:
A variety of techniques are disclosed for detection of advanced persistent threats and similar malware. In one aspect, the detection of certain network traffic at a gateway is used to trigger a query of an originating endpoint, which can use internal logs to identify a local process that is sourcing the network traffic. In another aspect, an endpoint is configured to periodically generate and transmit a secure heartbeat, so that an interruption of the heartbeat can be used to signal the possible presence of malware. In another aspect, other information such as local and global reputation information is used to provide context for more accurate malware detection.
Public/Granted literature
- US20220368698A1 USING REPUTATION TO AVOID FALSE MALWARE DETECTIONS Public/Granted day:2022-11-17
Information query