Threat protection networks are described. Embodiments of
threat protection network in accordance with the invention use expert systems to determine the nature of potential threats to a
remote computer. In several embodiments, a secure peer-to-peer network is used to rapidly distribute information concerning the nature of the potential
threat through the
threat protection network. One embodiment of the invention includes at least one
client computer connected to a network, a
server that stores threat definition data and is connected to the network, an
expert system in communication with the
server. In addition, the
client computer is configured to refer potential threats to the
server, the server is configured to refer to the
expert system any potential threat forwarded by a
client computer that is not identified in the threat definition data and the
expert system is configured to determine whether the potential threat is an actual threat by exposing at least one test computer to the potential threat and observing the behavior of the test computer.