- 专利标题: System, apparatus and method for automatically verifying exploits within suspect objects and highlighting the display information associated with the verified exploits
-
申请号: US15298159申请日: 2016-10-19
-
公开(公告)号: US10476909B1公开(公告)日: 2019-11-12
- 发明人: Ashar Aziz , Muhammad Amin , Osman Abdoul Ismael , Zheng Bu
- 申请人: FireEye, Inc.
- 申请人地址: US CA Milpitas
- 专利权人: FireEye, Inc.
- 当前专利权人: FireEye, Inc.
- 当前专利权人地址: US CA Milpitas
- 代理机构: Rutan & Tucker, LLP
- 主分类号: G06F21/56
- IPC分类号: G06F21/56 ; H04L29/06 ; G06F9/455
摘要:
According to one embodiment, a threat detection system comprising an intrusion protection system (IPS) logic, a virtual execution logic and a reporting logic is shown. The IPS logic is configured to receive a first plurality of objects and analyze the first plurality of objects to identify a second plurality of objects as potential exploits, the second plurality of objects being a subset of the first plurality of objects and being lesser or equal in number to the first plurality of objects. The virtual execution logic including at least one virtual machine configured to process content within each of the second plurality of objects and monitor for anomalous behaviors during the processing that are indicative of exploits to classify that a first subset of the second plurality of objects includes one or more verified exploits. The reporting logic configured to provide a display of exploit information associated with the one or more verified exploits.
信息查询