| CPC G06F 21/554 (2013.01) [G06F 21/55 (2013.01); G06F 21/552 (2013.01); G06F 21/566 (2013.01); G06F 21/575 (2013.01); G06F 21/577 (2013.01); G06F 21/56 (2013.01)] | 17 Claims |

|
1. A method implemented by a computing device including at least one of firmware, a co-processor, a trusted execution environment, or a secure memory area, the method comprising:
registering a plurality of applications executing on a network of a plurality of client devices to be monitored for classes of errors, the classes of errors including a malware error and a non-malware error;
receiving reports of a plurality of security events related to the plurality of applications, the plurality of security events indicative of similar classes of errors in the plurality of applications;
receiving instructions for taking a security action based on the plurality of security events occurring within a period of time, the period of time indicative that the security events correspond to the malware error; and
causing the plurality of client devices to take the security action to remedy the malware error.
|