MALWARE DATA ITEM ANALYSIS
    1.
    发明申请

    公开(公告)号:US20180046801A1

    公开(公告)日:2018-02-15

    申请号:US15726917

    申请日:2017-10-06

    Abstract: Embodiments of the present disclosure relate to a data analysis system that may automatically analyze a suspected malware file, or group of files. Automatic analysis of the suspected malware file(s) may include one or more automatic analysis techniques. Automatic analysis of may include production and gathering of various items of information related to the suspected malware file(s) including, for example, calculated hashes, file properties, academic analysis information, file execution information, third-party analysis information, and/or the like. The analysis information may be automatically associated with the suspected malware file(s), and a user interface may be generated in which the various analysis information items are presented to a human analyst such that the analyst may quickly and efficiently evaluate the suspected malware file(s). For example, the analyst may quickly determine one or more characteristics of the suspected malware file(s), whether or not the file(s) is malware, and/or a threat level of the file(s).

    Periodic database search manager for multiple data sources

    公开(公告)号:US10572487B1

    公开(公告)日:2020-02-25

    申请号:US15406195

    申请日:2017-01-13

    Abstract: Systems and techniques for searching multiple data sources are described herein. Users may specify searches of multiple data sources to occur on a periodic basis. The searches may be configured to search time or date ranges that have not previously been searched. A user may select the data sources of interest and specify search terms, review and edit previously created searches, and review results of searches. The system automatically performs the specified searches, and notifies the user and/or a team of the user each time new results are found. The system may efficiently search the data sources by storing previous search results and comparing the previous results to current search results to identify new search results.

    Periodic database search manager for multiple data sources
    6.
    发明授权
    Periodic database search manager for multiple data sources 有权
    定期数据库搜索管理器用于多个数据源

    公开(公告)号:US09547693B1

    公开(公告)日:2017-01-17

    申请号:US15152017

    申请日:2016-05-11

    CPC classification number: G06F17/30513 G06F17/30368 G06F17/30867

    Abstract: Systems and techniques for searching multiple data sources are described herein. Users may specify searches of multiple data sources to occur on a periodic basis. The searches may be configured to search time or date ranges that have not previously been searched. A user may select the data sources of interest and specify search terms, review and edit previously created searches, and review results of searches. The system automatically performs the specified searches, and notifies the user and/or a team of the user each time new results are found. The system may efficiently search the data sources by storing previous search results and comparing the previous results to current search results to identify new search results.

    Abstract translation: 本文描述了用于搜索多个数据源的系统和技术。 用户可以指定多个数据源的周期性搜索。 可以将搜索配置为搜索以前未被搜索的时间或日期范围。 用户可以选择感兴趣的数据源并指定搜索条件,查看和编辑先前创建的搜索,并查看搜索结果。 系统自动执行指定的搜索,并在每次找到新的结果时通知用户和/或用户的团队。 该系统可以通过存储先前的搜索结果并将先前的结果与当前搜索结果进行比较来高效地搜索数据源,以识别新的搜索结果。

    Malware data item analysis
    10.
    发明授权

    公开(公告)号:US09785773B2

    公开(公告)日:2017-10-10

    申请号:US14668833

    申请日:2015-03-25

    Abstract: Embodiments of the present disclosure relate to a data analysis system that may automatically analyze a suspected malware file, or group of files. Automatic analysis of the suspected malware file(s) may include one or more automatic analysis techniques. Automatic analysis of may include production and gathering of various items of information related to the suspected malware file(s) including, for example, calculated hashes, file properties, academic analysis information, file execution information, third-party analysis information, and/or the like. The analysis information may be automatically associated with the suspected malware file(s), and a user interface may be generated in which the various analysis information items are presented to a human analyst such that the analyst may quickly and efficiently evaluate the suspected malware file(s). For example, the analyst may quickly determine one or more characteristics of the suspected malware file(s), whether or not the file(s) is malware, and/or a threat level of the file(s).

Patent Agency Ranking