Enterprise URL Reputation Engine with Local Caching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing enterprise security systems lack the ability to effectively differentiate between URL reputations that are benign or beneficial to one enterprise but harmful to another, leading to inefficient security measures and potential false positives, as global threat intelligence services do not account for enterprise-specific conditions and policies.

Innovation Solution

Implementing an enterprise threat intelligence server (ETIS) that provides customized URL reputation management, including proxying functions, administrator overrides, indicator of compromise support, and enhanced algorithms for blocking URLs, while integrating with global threat intelligence services to ensure consistent and tailored security measures.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If global threat intelligence services are used to determine URL reputation, then broad security coverage is achieved, but enterprise-specific security needs and conditions are not accounted for

Engineering Contradiction:
Improveenterprise-specific security adaptationVSAvoidsecurity measure accuracy
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent segments the monolithic global threat intelligence service into two distinct components: a global threat intelligence service providing broad URL reputation data, and an enterprise threat intelligence server providing enterprise-specific customization. This segmentation allows each component to specialize - the global service handles broad coverage while the enterprise server handles specific needs, resolving the contradiction between adaptability and reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The enterprise threat intelligence server acts as an intermediary between the global threat intelligence service and the enterprise network. It receives global URL reputation data, processes it through enterprise-specific algorithms and policies, and delivers customized security decisions. This intermediary role enables both global coverage and enterprise-specific adaptation to coexist.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If enterprise-specific URL reputation management is implemented, then false positives are reduced, but system complexity increases

Engineering Contradiction:
Improvesecurity decision accuracyVSAvoidreputation management system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges the global threat intelligence service with the enterprise threat intelligence server into an integrated system. The enterprise server combines global URL reputation data with enterprise-specific algorithms, administrator overrides, and local threat intelligence. This merging allows the system to maintain high reliability through enterprise customization while managing complexity through unified architecture and shared data structures.

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If cloud services are queried for every URL reputation check, then up-to-date security information is obtained, but query costs and network traffic increase

Engineering Contradiction:
Improvereputation data currencyVSAvoidquery cost and network bandwidth
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The enterprise threat intelligence server performs preliminary actions by maintaining local caches of URL reputation data and enterprise-specific security policies. Before querying the global cloud service, it checks local caches and applies enterprise algorithms to determine if a cloud query is necessary. This preliminary filtering reduces the frequency of expensive cloud queries while maintaining up-to-date security information for frequently accessed URLs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements local quality by maintaining enterprise-specific reputation data and security policies locally at the enterprise threat intelligence server. Rather than relying solely on centralized cloud services, the local server stores and processes enterprise-specific information, reducing the need for repeated cloud queries and lowering network traffic and query costs.

Inventive Principle:
Principle #3Local quality

Data Source

PatentEP3314860B1Enterprise reputations for uniform resource locators
Publication Date: 2021.01.13 MCAFEE LLC
  • EP3314860B1 patent drawingFigure 1a
  • EP3314860B1 patent drawingFigure 1b
  • EP3314860B1 patent drawingFigure 2

AI summary

There is disclosed in an example a computing apparatus configured to operate as an enterprise threat intelligence server, and including: a network interface configured to communicatively couple to a network; and one or more logic elements providing a reputation engine, operable for: receiving a first uniform resource locator (URL) identifier; determining that a first URL identified by the first URL identifier has an unknown enterprise reputation; and establishing a baseline reputation for the URL. There is further disclosed a method of providing the reputation engine, and one or more computer-readable mediums having stored thereon executable instructions for providing the reputation engine.