首页> 外国专利> System and method for analysis of a memory dump associated with a potentially malicious content suspect

System and method for analysis of a memory dump associated with a potentially malicious content suspect

机译:用于分析与潜在恶意内容嫌疑人关联的内存转储的系统和方法

摘要

A network device for detecting malware is described. The network device features a memory storage device and a controller. The controller operating in cooperation with one or more virtual machines that are based on software modules stored within the memory storage device. The controller is configured to (i) monitor behaviors of at least a first virtual machine of the one or more virtual machines processing data received over a network, (ii) identify at least one anomalous behavior that includes either a communication anomaly or an execution anomaly, and (iii) detect, based on the identified at least one anomalous behavior, a presence of malware in the first virtual machine in response to identifying the at least one anomalous behavior.
机译:描述了一种用于检测恶意软件的网络设备。该网络设备具有存储器存储设备和控制器。控制器与基于存储在存储器存储设备中的软件模块的一个或多个虚拟机协同操作。控制器被配置为(i)监视处理通过网络接收的数据的一个或多个虚拟机中的至少第一虚拟机的行为,(ii)识别包括通信异常或执行异常的至少一个异常行为。 (iii)基于所识别的至少一个异常行为,响应于识别出至少一个异常行为,在第一虚拟机中检测到恶意软件的存在。

著录项

  • 公开/公告号US10198574B1

    专利类型

  • 公开/公告日2019-02-05

    原文格式PDF

  • 申请/专利权人 FIREEYE INC.;

    申请/专利号US201615167636

  • 申请日2016-05-27

  • 分类号G06F21/53;G06F21/56;G06F9/455;

  • 国家 US

  • 入库时间 2022-08-21 12:08:49

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号