- 专利标题: Systems and methods for malicious code detection accuracy assurance
-
申请号: US14949918申请日: 2015-11-24
-
公开(公告)号: US09954980B2公开(公告)日: 2018-04-24
- 发明人: Roy Katmor , Tomer Bitton , Udi Yavo , Ido Kelson
- 申请人: enSilo Ltd.
- 申请人地址: IL Herzlia
- 专利权人: enSilo Ltd.
- 当前专利权人: enSilo Ltd.
- 当前专利权人地址: IL Herzlia
- 主分类号: H04L29/06
- IPC分类号: H04L29/06
摘要:
There is provided a method for authenticating an attempt at establishment of a network connection by allowed code, comprising: providing a dataset having previously observed stack trace templates each representing a stack trace pattern prevailing in stack traces recorded by monitoring stacks of clients executing an allowed code during a connection establishment process for establishing network connections related to the allowed code; receiving a new stack trace recorded during a new connection establishment process for a new network connection by a new client; measuring a similarity between the new stack trace and the plurality of stack trace templates to identify a match to a stack trace template; evaluating the matched stack trace template for a predefined rule requirement; and updating a rule-set database with the matched stack trace template to authenticate new network connection establishments associated with stack templates matching the matched stack trace template.
公开/授权文献
信息查询