Device identification
    1.
    发明授权

    公开(公告)号:US12057959B2

    公开(公告)日:2024-08-06

    申请号:US16731882

    申请日:2019-12-31

    申请人: McAfee, LLC

    摘要: There is disclosed in one example a computing apparatus, including: a hardware platform including a processor and a memory; a network interface to communicatively couple to a network; and a network gateway engine to identify devices on the network, the network gateway engine including instructions encoded within the memory to instruct the processor to provide two-phase identification for a device newly-identified on the network, including: a static identification phase including applying discovery probes to the newly-identified device; and a dynamic identification phase including collecting network telemetry for the newly-identified device over time and analyzing the collected network telemetry to determine if the network telemetry is consistent with expected network usage for the newly-discovered device.

    Agentless security services
    3.
    发明授权

    公开(公告)号:US11824645B2

    公开(公告)日:2023-11-21

    申请号:US16933289

    申请日:2020-07-20

    申请人: McAfee, LLC

    IPC分类号: H04L9/40

    CPC分类号: H04L63/126 H04L63/20

    摘要: There is disclosed in one example a computing apparatus, including: a hardware platform including a processor, a memory, and a network interface; and instructions encoded within the memory to instruct the processor to: receive an incoming packet via the network interface; extract from the incoming packet a source port and a source internet protocol (IP) address; correlate the source port and source IP to a device identifier (ID); receive a network policy for the device ID; and apply the network policy to the incoming packet.

    Secure DNS Using Delegated Credentials and Keyless SSL

    公开(公告)号:US20220321528A1

    公开(公告)日:2022-10-06

    申请号:US17402271

    申请日:2021-08-13

    申请人: McAfee, LLC

    摘要: There is disclosed in an example a gateway device, including a hardware computing platform, and a secure domain name system (DNS) engine having circuitry and stored instructions to-program the circuitry, the secure DNS engine to communicatively couple to an endpoint via a local network, begin a secure DNS transaction with the endpoint, determine whether the endpoint supports delegated credentials, and after determining that the endpoint supports delegated credentials, establish a secure DNS session with the endpoint using a delegated credential.

    Methods, systems, articles of manufacture and apparatus to verify application permission safety

    公开(公告)号:US10990679B2

    公开(公告)日:2021-04-27

    申请号:US15972803

    申请日:2018-05-07

    申请人: McAfee, LLC

    IPC分类号: G06F21/00 G06F21/57

    摘要: Methods, apparatus, systems and articles of manufacture are disclosed to verify application permission safety. An example apparatus to identify unsafe permissions associated with a candidate app disclosed herein includes an app classifier interface to retrieve a cluster of apps associated with the candidate app, the candidate app including a requested permission set (RPS), a trusted app (TA) identifier to identify a set of TAs within the cluster, the set of TAs associated with a designation of trust, a safe permission set (SPS) evaluator to generate an SPS list associated with the set of TAs within the cluster, and an RPS identifier to determine whether permissions of the RPS are listed in the SPS list, the SPS evaluator further to designate first respective ones of the permissions of the RPS as safe when the first respective ones of the permissions are listed in the SPS list, and designate second respective ones of the permissions of the RPS as unsafe when the second respective ones of the permissions are absent from the SPS list.

    COOPERATIVE MITIGATION OF DISTRIBUTED DENIAL OF SERVICE ATTACKS ORIGINATING IN LOCAL NETWORKS

    公开(公告)号:US20200067974A1

    公开(公告)日:2020-02-27

    申请号:US16154473

    申请日:2018-10-08

    申请人: McAfee, LLC

    摘要: Example methods, apparatus, systems and articles of manufacture to implement cooperative mitigation of distributed denial of service attacks originating in local networks are disclosed. An example local network router disclosed herein includes a mitigator to mitigate a distributed denial of service attack detected by an Internet service provider, the distributed denial of service attack associated with network traffic originating from a first device connected to a local network. The example local network router also includes a threat signaling server to identify the first device based on first information received from a threat signaling client of the Internet service provider, the first information describing the distributed denial of service attack. The example threat signaling server is also to transmit second information to notify the threat signaling client of the Internet service provider when the network traffic associated with the distributed denial of service attack has been mitigated.