The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Aug. 11, 2015

Filed:

Jun. 27, 2011
Applicants:

Dmitri Alperovitch, Atlanta, GA (US);

Zheng Bu, Fremont, CA (US);

David Frederick Diehl, Minneapolis, MN (US);

Sven Krasser, Atlanta, GA (US);

Inventors:

Dmitri Alperovitch, Atlanta, GA (US);

Zheng Bu, Fremont, CA (US);

David Frederick Diehl, Minneapolis, MN (US);

Sven Krasser, Atlanta, GA (US);

Assignee:

McAfee, Inc., Santa Clara, CA (US);

Attorney:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
G06F 21/55 (2013.01); H04L 29/06 (2006.01);
U.S. Cl.
CPC ...
H04L 63/1408 (2013.01); H04L 63/0227 (2013.01); H04L 63/14 (2013.01); H04L 63/1416 (2013.01); H04L 63/0236 (2013.01); H04L 63/0245 (2013.01);
Abstract

A method is provided in one example embodiment that includes generating a fingerprint based on properties extracted from data packets received over a network connection and requesting a reputation value based on the fingerprint. A policy action may be taken on the network connection if the reputation value received indicates the fingerprint is associated with malicious activity. The method may additionally include displaying information about protocols based on protocol fingerprints, and more particularly, based on fingerprints of unrecognized protocols. In yet other embodiments, the reputation value may also be based on network addresses associated with the network connection.


Find Patent Forward Citations

Loading…