首页> 外国专利> MULTI-TIERED SANDBOX BASED NETWORK THREAT DETECTION

MULTI-TIERED SANDBOX BASED NETWORK THREAT DETECTION

机译:基于多层沙盒的网络威胁检测

摘要

Systems and methods for multi-tiered sandbox based network threat detection are provided. According to one embodiment, a file is received by a virtual sandbox appliance. The file is caused to exhibit a first set of behaviors by running the file within a virtualization application based environment of the virtual sandbox appliance. The virtualization application based environment acts as an intermediary between executable code, an operating system (OS) application programming interface (API), and an instruction set of a particular computer architecture. The file is further caused to exhibit a second set of behaviors by running the file within a container based environment of the virtual sandbox appliance. Differences, if any, between the first set of behaviors and the second set of behaviors are determined. Finally, the file is classified as malicious when the differences are greater than a predefined or configurable threshold.
机译:提供了用于基于多层沙箱的网络威胁检测的系统和方法。根据一个实施例,虚拟沙箱设备接收文件。通过在虚拟沙箱设备的基于虚拟化应用程序的环境中运行文件,使文件表现出第一组行为。基于虚拟化应用程序的环境充当可执行代码,操作系统(OS)应用程序编程接口(API)和特定计算机体系结构的指令集之间的中介。通过在虚拟沙箱设备的基于容器的环境中运行文件,进一步使文件表现出第二组行为。确定第一组行为与第二组行为之间的差异(如果有)。最后,当差异大于预定义或可配置的阈值时,文件被分类为恶意文件。

著录项

  • 公开/公告号US2020134177A1

    专利类型

  • 公开/公告日2020-04-30

    原文格式PDF

  • 申请/专利权人 FORTINET INC.;

    申请/专利号US201916730892

  • 发明设计人 MICHAEL F. CHALMANDRIER-PERNA;

    申请日2019-12-30

  • 分类号G06F21/55;G06F21/53;G06F9/455;G06F21/56;

  • 国家 US

  • 入库时间 2022-08-21 11:21:30

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号