Enterprise URL Reputation Engine with Local Caching
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing enterprise security systems lack the ability to effectively differentiate between URL reputations that are benign or beneficial to one enterprise but harmful to another, leading to inefficient security measures and potential false positives, as global threat intelligence services do not account for enterprise-specific conditions and policies.
Innovation Solution
Implementing an enterprise threat intelligence server (ETIS) that provides customized URL reputation management, including proxying functions, administrator overrides, indicator of compromise support, and enhanced algorithms for blocking URLs, while integrating with global threat intelligence services to ensure consistent and tailored security measures.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If global threat intelligence services are used to determine URL reputation, then broad security coverage is achieved, but enterprise-specific security needs and conditions are not accounted for
Solution Approach 1:
The patent segments the monolithic global threat intelligence service into two distinct components: a global threat intelligence service providing broad URL reputation data, and an enterprise threat intelligence server providing enterprise-specific customization. This segmentation allows each component to specialize - the global service handles broad coverage while the enterprise server handles specific needs, resolving the contradiction between adaptability and reliability.
Solution Approach 2:
The enterprise threat intelligence server acts as an intermediary between the global threat intelligence service and the enterprise network. It receives global URL reputation data, processes it through enterprise-specific algorithms and policies, and delivers customized security decisions. This intermediary role enables both global coverage and enterprise-specific adaptation to coexist.
2Reliability
If enterprise-specific URL reputation management is implemented, then false positives are reduced, but system complexity increases
Solution Approach 1:
The patent merges the global threat intelligence service with the enterprise threat intelligence server into an integrated system. The enterprise server combines global URL reputation data with enterprise-specific algorithms, administrator overrides, and local threat intelligence. This merging allows the system to maintain high reliability through enterprise customization while managing complexity through unified architecture and shared data structures.
3Reliability
If cloud services are queried for every URL reputation check, then up-to-date security information is obtained, but query costs and network traffic increase
Solution Approach 1:
The enterprise threat intelligence server performs preliminary actions by maintaining local caches of URL reputation data and enterprise-specific security policies. Before querying the global cloud service, it checks local caches and applies enterprise algorithms to determine if a cloud query is necessary. This preliminary filtering reduces the frequency of expensive cloud queries while maintaining up-to-date security information for frequently accessed URLs.
Solution Approach 2:
The system implements local quality by maintaining enterprise-specific reputation data and security policies locally at the enterprise threat intelligence server. Rather than relying solely on centralized cloud services, the local server stores and processes enterprise-specific information, reducing the need for repeated cloud queries and lowering network traffic and query costs.
Data Source
Figure 1a
Figure 1b
Figure 2
AI summary
There is disclosed in an example a computing apparatus configured to operate as an enterprise threat intelligence server, and including: a network interface configured to communicatively couple to a network; and one or more logic elements providing a reputation engine, operable for: receiving a first uniform resource locator (URL) identifier; determining that a first URL identified by the first URL identifier has an unknown enterprise reputation; and establishing a baseline reputation for the URL. There is further disclosed a method of providing the reputation engine, and one or more computer-readable mediums having stored thereon executable instructions for providing the reputation engine.