| CPC H04L 47/20 (2013.01) [G06N 20/00 (2019.01); H04L 12/4641 (2013.01); H04L 61/4511 (2022.05)] | 33 Claims |

|
1. A mobile management method comprising:
receiving a DNS query for a host name from an application on a client;
retrieving reputation data associated with the host name from a local cache on the client;
determining a policy for the host name, which is associated with the host name and the reputation data associated with the host name;
based on the determined policy for the host name, blocking attempted network flows to a host corresponding to the host name;
sending at least attempted network flow metadata related to the blocked attempted network flows to a collector on the client; and
transmitting the attempted network flow metadata in the collector to a VPN server pool via a VPN tunnel.
|