Invention Application
- Patent Title: CONTEXT-AWARE PROACTIVE THREAT MANAGEMENT SYSTEM
- Patent Title (中): 背景知识主动威胁管理系统
-
Application No.: PCT/US2013/070858Application Date: 2013-11-19
-
Publication No.: WO2015076790A1Publication Date: 2015-05-28
- Inventor: BHARGAV-SPANTZEL, Abhilasha , VICENTE, John, B. , HAGHIGHAT, Mohammad, R. , CHEN, Oliver, W. , KHOSRAVI, Hormuzd, M. , KAHANA, Uri
- Applicant: INTEL CORPORATION , BHARGAV-SPANTZEL, Abhilasha , VICENTE, John, B. , HAGHIGHAT, Mohammad, R. , CHEN, Oliver, W. , KHOSRAVI, Hormuzd, M. , KAHANA, Uri
- Applicant Address: 2200 Mission College Blvd Santa Clara, California 95052 US
- Assignee: INTEL CORPORATION,BHARGAV-SPANTZEL, Abhilasha,VICENTE, John, B.,HAGHIGHAT, Mohammad, R.,CHEN, Oliver, W.,KHOSRAVI, Hormuzd, M.,KAHANA, Uri
- Current Assignee: INTEL CORPORATION,BHARGAV-SPANTZEL, Abhilasha,VICENTE, John, B.,HAGHIGHAT, Mohammad, R.,CHEN, Oliver, W.,KHOSRAVI, Hormuzd, M.,KAHANA, Uri
- Current Assignee Address: 2200 Mission College Blvd Santa Clara, California 95052 US
- Agency: PFLEGER, Edmund, P. et al.
- Main IPC: G06F21/00
- IPC: G06F21/00
Abstract:
This disclosure is directed to a context-aware proactive threat management system. In general, a device may use internal activity data along with data about external activities (e.g., provided by remote resources) for threat assessment and mitigation. A device may comprise, for example, a hostile environment detection (HED) module to coordinate threat assessment and mitigation. The HED module may accumulate internal activity data (e.g., from security services in the device), and external activity data regarding a system environment and/or a physical environment from the remote resources. The HED module may then assess threats based on the activity data and determine automated and/or manual mitigation operations to respond to the threats. In one embodiment, visualization features may also be used to, for example, visualize threats to a user, visualize automatic/manual mitigation operations, request user confirmation regarding the performance of manual mitigation operations, etc.
Information query