首页> 外国专利> DETECTION AND MITIGATION OF TIME-DELAY BASED NETWORK ATTACKS

DETECTION AND MITIGATION OF TIME-DELAY BASED NETWORK ATTACKS

机译:基于时间延迟的网络攻击的检测和缓解

摘要

Systems and methods for mitigation of time-delay based network attacks are provided. According to one embodiment, an email directed to a user of an enterprise and containing a potentially malicious link is received by a mail server of the enterprise. At a first time, a file to which the potentially malicious link points is evaluated within a sandbox environment and a first hash value is generated based on contents of the file. At a second time, a file to which the potentially malicious link points is again evaluated, including downloading the file to which the potentially malicious link points to at the second time and generating a second hash value based on contents of the file. When the two hash values differ, then the file is treated by the mail server as a suspicious or high risk file or is caused to be evaluated within the sandbox environment.
机译:提供了用于减轻基于时间的网络攻击的系统和方法。根据一个实施例,由企业的邮件服务器接收针对企业用户并包含潜在恶意链接的电子邮件。第一次,在沙箱环境中评估潜在恶意链接指向的文件,并基于文件的内容生成第一哈希值。在第二时间,再次评估潜在恶意链接指向的文件,包括第二次下载潜在恶意链接指向的文件,并基于文件的内容生成第二哈希值。当两个哈希值不同时,邮件服务器会将文件视为可疑文件或高风险文件,或者在沙箱环境中对文件进行评估。

著录项

  • 公开/公告号US2019007426A1

    专利类型

  • 公开/公告日2019-01-03

    原文格式PDF

  • 申请/专利权人 FORTINET INC.;

    申请/专利号US201715640381

  • 发明设计人 J. DENNIS BERGSTRÖM;

    申请日2017-06-30

  • 分类号H04L29/06;G06F21/53;

  • 国家 US

  • 入库时间 2022-08-21 12:05:56

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号