发明授权
- 专利标题: System and method for analyzing suspicious network data
- 专利标题(中): 用于分析可疑网络数据的系统和方法
-
申请号: US14078376申请日: 2013-11-12
-
公开(公告)号: US08984638B1公开(公告)日: 2015-03-17
- 发明人: Ashar Aziz , Ramesh Radhakrishnan , Osman Ismael
- 申请人: FireEye, Inc.
- 申请人地址: US CA Milpitas
- 专利权人: FireEye, Inc.
- 当前专利权人: FireEye, Inc.
- 当前专利权人地址: US CA Milpitas
- 代理机构: Blakely, Sokoloff, Taylor & Zafman LLP
- 主分类号: G06F12/14
- IPC分类号: G06F12/14 ; G06F11/30 ; H04L29/06
摘要:
A system is provided with a controller and a device configured to receive and output network data from a communication network to the controller. Accordingly, the controller is configured to (i) receive the network data from the device, (ii) conduct heuristic analysis on the network data, (iii) identify at least a portion of the network data as suspicious upon determining by the heuristic analysis of a likelihood that at least the portion of the network data including malware, (iv) simulate transmission of the suspicious network data to at least one virtual machine of a plurality of virtual machines that is selected or configured using at least one software profile, and (v) analyze effects of the suspicious network data on the at least one virtual machine.
信息查询