首页> 外国专利> System, apparatus and method for automatically verifying exploits within suspect objects and highlighting the display information associated with the verified exploits

System, apparatus and method for automatically verifying exploits within suspect objects and highlighting the display information associated with the verified exploits

机译:用于自动验证可疑对象内的漏洞利用并突出显示与已验证漏洞利用相关的显示信息的系统,装置和方法

摘要

A threat detection system is integrated with intrusion protection system (IPS) logic, virtual execution logic and reporting logic is shown. The IPS logic is configured to identify a first plurality of objects as suspicious objects and outputting information associated with the suspicious objects. The virtual execution logic is configured to receive the suspicious objects and verify whether any of the suspicious objects is an exploit. The virtual execution logic includes at least one virtual machine configured to virtually process content within the suspicious objects and monitor for anomalous behaviors during the virtual processing that are indicative of exploits. The reporting logic is configured to issue a report including the information associated with the suspicious objects from the IPS logic and results of the virtual processing of the content within the suspicious objects.
机译:威胁检测系统与入侵防护系统(IPS)逻辑集成在一起,图中显示了虚拟执行逻辑和报告逻辑。 IPS逻辑被配置为将第一多个对象识别为可疑对象,并输出与可疑对象相关联的信息。虚拟执行逻辑被配置为接收可疑对象,并验证是否有任何可疑对象是漏洞利用程序。该虚拟执行逻辑包括至少一个虚拟机,该至少一个虚拟机被配置为虚拟地处理可疑对象内的内容,并在虚拟处理期间监视指示漏洞利用的异常行为。报告逻辑被配置为发布报告,该报告包括来自IPS逻辑的与可疑对象相关的信息以及可疑对象内内容的虚拟处理结果。

著录项

  • 公开/公告号US9306974B1

    专利类型

  • 公开/公告日2016-04-05

    原文格式PDF

  • 申请/专利权人 FIREEYE INC.;

    申请/专利号US201514620055

  • 申请日2015-02-11

  • 分类号G08B23;G06F17;H04L29/06;

  • 国家 US

  • 入库时间 2022-08-21 14:27:56

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号