Tracking and mitigation of an infected host device

    公开(公告)号:US10834103B2

    公开(公告)日:2020-11-10

    申请号:US15942530

    申请日:2018-04-01

    Abstract: A security platform may determine mapped attribute information associated with a plurality of host identifiers. The mapped attribute information may include information that identifies a set of related attributes. The security platform may determine, based on the mapped attribute information, that a host device is associated with at least two host identifiers of the plurality of host identifiers. The security platform may aggregate, based on the at two least host identifiers, threat information as aggregated threat information associated with the host device. The security platform may classify the host device as an infected device or a suspicious device based on the aggregated threat information.

    ENFORCING THREAT POLICY ACTIONS BASED ON NETWORK ADDRESSES OF HOST THREATS

    公开(公告)号:US20190297094A1

    公开(公告)日:2019-09-26

    申请号:US16024308

    申请日:2018-06-29

    Abstract: A device receives information identifying a specific host threat to a network, where the information includes a list of network addresses associated with the specific host threat. The device identifies network elements, of the network, associated with the specific host threat to the network, and determines a network control system associated with the identified network elements. The device determines a policy enforcement group of network elements, of the identified network elements, that maps to the list of network addresses associated with the specific host threat, where the network control system is associated with the policy enforcement group of network elements. The device determines a threat policy action to enforce for the specific host threat, and causes, via the network control system, the threat policy action to be enforced by the policy enforcement group of network elements.

Patent Agency Ranking