首页> 外国专利> Identifying an evasive malicious object based on a behavior delta

Identifying an evasive malicious object based on a behavior delta

机译:根据行为增量识别逃避的恶意对象

摘要

A security device may receive actual behavior information associated with an object. The actual behavior information may identify a first set of behaviors associated with executing the object in a live environment. The security device may determine test behavior information associated with the object. The test behavior information may identify a second set of behaviors associated with testing the object in a test environment. The security device may compare the first set of behaviors and the second set of behaviors to determine a difference between the first set of behaviors and the second set of behaviors. The security device may identify whether the object is an evasive malicious object based on the difference between the first set of behaviors and the second set of behaviors. The security device may provide an indication of whether the object is an evasive malicious object.
机译:安全设备可以接收与对象关联的实际行为信息。实际行为信息可以标识与在实时环境中执行对象相关的第一组行为。安全设备可以确定与对象相关联的测试行为信息。测试行为信息可以标识与在测试环境中测试对象相关联的第二组行为。安全设备可以比较第一组行为和第二组行为以确定第一组行为和第二组行为之间的差异。安全设备可以基于第一组行为与第二组行为之间的差异来识别该对象是否是逃避的恶意对象。安全设备可以提供对象是否是逃避的恶意对象的指示。

著录项

  • 公开/公告号US10210332B2

    专利类型

  • 公开/公告日2019-02-19

    原文格式PDF

  • 申请/专利权人 JUNIPER NETWORKS INC.;

    申请/专利号US201815922467

  • 发明设计人 KYLE ADAMS;DANIEL J. QUINLAN;

    申请日2018-03-15

  • 分类号G06F21/53;G06F21/56;G06F11/36;

  • 国家 US

  • 入库时间 2022-08-21 12:12:17

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号