首页> 外国专利> Multi-tiered sandbox based network threat detection

Multi-tiered sandbox based network threat detection

机译:基于多层沙箱的网络威胁检测

摘要

Systems and methods for multi-tiered sandbox based network threat detection are provided. According to one embodiment, a file is received by a computer system. The file is caused to exhibit a first set of behaviors by processing the file within a virtualization application based environment of the computer system. The virtualization application based environment is created based on an application to which the file pertains. The file is further caused to exhibit a second set of behaviors by processing the file within a container based environment of the computer system. Differences, if any, between the first set of behaviors and the second set of behaviors. Finally, the file is classified as malicious when the differences are greater than a predefined or configurable threshold.
机译:提供了用于基于多层沙箱的网络威胁检测的系统和方法。根据一个实施例,计算机系统接收文件。通过在计算机系统的基于虚拟化应用程序的环境中处理文件,使文件表现出第一组行为。基于虚拟化应用程序的环境是基于文件所属的应用程序创建的。通过在计算机系统的基于容器的环境内处理文件,进一步使文件表现出第二组行为。第一组行为与第二组行为之间的差异(如果有)。最后,当差异大于预定义或可配置的阈值时,文件被分类为恶意文件。

著录项

  • 公开/公告号US10534909B2

    专利类型

  • 公开/公告日2020-01-14

    原文格式PDF

  • 申请/专利权人 FORTINET INC.;

    申请/专利号US201715448476

  • 发明设计人 MICHAEL F. CHALMANDRIER-PERNA;

    申请日2017-03-02

  • 分类号G06F21/55;G06F21/53;G06F9/455;

  • 国家 US

  • 入库时间 2022-08-21 11:28:43

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号