- 专利标题: Multi-tiered sandbox based network threat detection
-
申请号: US15448476申请日: 2017-03-02
-
公开(公告)号: US10534909B2公开(公告)日: 2020-01-14
- 发明人: Michael F. Chalmandrier-Perna
- 申请人: Fortinet, Inc.
- 申请人地址: US CA Sunnyvale
- 专利权人: Fortinet, Inc.
- 当前专利权人: Fortinet, Inc.
- 当前专利权人地址: US CA Sunnyvale
- 代理机构: Jaffery Watson Mendonsa & Hamilton, LLP
- 主分类号: G06F21/55
- IPC分类号: G06F21/55 ; G06F21/53 ; G06F9/455
摘要:
Systems and methods for multi-tiered sandbox based network threat detection are provided. According to one embodiment, a file is received by a computer system. The file is caused to exhibit a first set of behaviors by processing the file within a virtualization application based environment of the computer system. The virtualization application based environment is created based on an application to which the file pertains. The file is further caused to exhibit a second set of behaviors by processing the file within a container based environment of the computer system. Differences, if any, between the first set of behaviors and the second set of behaviors. Finally, the file is classified as malicious when the differences are greater than a predefined or configurable threshold.
公开/授权文献
- US20180253551A1 MULTI-TIERED SANDBOX BASED NETWORK THREAT DETECTION 公开/授权日:2018-09-06
信息查询