| CPC H04L 63/1483 (2013.01) [H04L 63/1416 (2013.01); H04L 63/145 (2013.01); H04L 63/20 (2013.01)] | 18 Claims |

|
1. A method comprising:
(a) obtaining, by a threat detection server computer running a threat detection software application, a resource identifier associated with a remote computer;
(b) receiving, by the threat detection server computer, source code associated with the resource identifier;
(c) parsing, by the threat detection server computer, the source code;
(d) analyzing, by the threat detection server computer, the source code to determine an indicator of compromise is present in the source code;
(e) determining, by the threat detection server computer, that the indicator of compromise is associated with malware meta-data;
monitoring the source code associated with the resource identifier associated with the malware meta-data for a threshold time period;
determining that the source code includes the malware meta-data; and
transmitting, after determining that the source code includes the malware meta-data, a compromise notification associated with the malware meta-data to a transport entity.
|