发明授权
- 专利标题: Technique for malware detection capability comparison of network security devices
-
申请号: US15358688申请日: 2016-11-22
-
公开(公告)号: US10587647B1公开(公告)日: 2020-03-10
- 发明人: Yasir Khalid , Nadeem Shahbaz
- 申请人: FireEye, Inc.
- 申请人地址: US CA Milpitas
- 专利权人: FireEye, Inc.
- 当前专利权人: FireEye, Inc.
- 当前专利权人地址: US CA Milpitas
- 代理机构: Rutan & Tucker, LLP
- 主分类号: G06F11/00
- IPC分类号: G06F11/00 ; H04L29/06 ; G06F9/455 ; G06F12/14
摘要:
A testing technique tests and compares malware detection capabilities of network security devices, such as those commercially available from a variety of cyber-security vendors. Testing is conducted on test samples in a “blind” fashion, where the security devices do not know beforehand whether the test samples are “live” malware or benign network traffic. The test samples are received from a remote server and potentially represent malicious attacks against a testing network. Notably, for truly blind testing, embodiments of the testing technique employ a mixture of malware and benign test samples, as well as addressing subterfuge, to prevent the security devices from being able to reliably determine maliciousness of the test samples based on a source of any of the samples.
信息查询