首页> 外国专利> DETECTION AND MITIGATION OF TIME-DELAY BASED NETWORK ATTACKS

DETECTION AND MITIGATION OF TIME-DELAY BASED NETWORK ATTACKS

机译:基于时间延迟的网络攻击的检测和缓解

摘要

Systems and methods are described for mitigation of time-delay based network attacks that seek to avoid detection by email security solutions employing sandboxing. According to one embodiment, a potentially malicious link associated with a communication is received from a computer system by a sandbox device. A link evasion technique, in which a first file to which the potentially malicious link points to at a first time is replaced with a second file on or before a second time, is subverted by the sandbox by evaluating the potentially malicious link at multiple times including generating a first hash value of the contents of the first file, generating a second hash value of the contents of the second file, assigning a threat level to the communication when the hash values differ, and informing the computer system of the threat level assigned to the communication.
机译:描述了用于减轻基于时延的网络攻击的系统和方法,该网络和攻击试图避免被采用沙盒的电子邮件安全解决方案检测到。根据一个实施例,沙箱设备从计算机系统接收与通信关联的潜在恶意链接。通过多次评估潜在的恶意链接,沙盒可以颠覆一种链接逃避技术,其中沙漏通过颠覆技术将第一次可能指向恶意的链接指向的第一文件在第二次或第二次之前替换为第二文件。生成第一文件的内容的第一哈希值,生成第二文件的内容的第二哈希值,当哈希值不同时,将威胁等级分配给通信,并向计算机系统通知分配给该威胁等级的威胁等级。沟通。

著录项

  • 公开/公告号US2020329060A1

    专利类型

  • 公开/公告日2020-10-15

    原文格式PDF

  • 申请/专利权人 FORTINET INC.;

    申请/专利号US202016912977

  • 发明设计人 J. DENNIS BERGSTRÖM;

    申请日2020-06-26

  • 分类号H04L29/06;G06F21/53;H04L12/58;

  • 国家 US

  • 入库时间 2022-08-21 11:25:48

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号