首页> 外国专利> System, apparatus and method for automatically verifying exploits within suspect objects and highlighting the display information associated with the verified exploits

System, apparatus and method for automatically verifying exploits within suspect objects and highlighting the display information associated with the verified exploits

机译:用于自动验证可疑对象内的漏洞利用并突出显示与已验证漏洞利用相关的显示信息的系统,装置和方法

摘要

According to one embodiment, a threat detection system comprising an intrusion protection system (IPS) logic, a virtual execution logic and a reporting logic is shown. The IPS logic is configured to receive a first plurality of objects and analyze the first plurality of objects to identify a second plurality of objects as potential exploits, the second plurality of objects being a subset of the first plurality of objects and being lesser or equal in number to the first plurality of objects. The virtual execution logic including at least one virtual machine configured to process content within each of the second plurality of objects and monitor for anomalous behaviors during the processing that are indicative of exploits to classify that a first subset of the second plurality of objects includes one or more verified exploits. The reporting logic configured to provide a display of exploit information associated with the one or more verified exploits.
机译:根据一个实施例,示出了一种威胁检测系统,其包括入侵防护系统(IPS)逻辑,虚拟执行逻辑和报告逻辑。 IPS逻辑被配置为接收第一多个对象并分析第一多个对象以将第二多个对象识别为潜在的利用,第二多个对象是第一多个对象的子集并且在数量上小于或等于编号到第一个多个对象。该虚拟执行逻辑包括至少一个虚拟机,该至少一个虚拟机被配置为处理第二多个对象中的每个对象内的内容并监视处理期间的异常行为,这些异常行为指示用于对第二多个对象的第一子集进行分类的漏洞的利用更多经过验证的漏洞利用。报告逻辑配置为提供与一个或多个已验证漏洞利用相关的漏洞利用信息的显示。

著录项

  • 公开/公告号US10476909B1

    专利类型

  • 公开/公告日2019-11-12

    原文格式PDF

  • 申请/专利权人 FIREEYE INC.;

    申请/专利号US201615298159

  • 申请日2016-10-19

  • 分类号G06F21/56;H04L29/06;G06F9/455;

  • 国家 US

  • 入库时间 2022-08-21 11:29:35

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号