首页> 外国专利> Retroactive identification of previously unknown malware based on network traffic analysis from a sandbox environment

Retroactive identification of previously unknown malware based on network traffic analysis from a sandbox environment

机译:根据沙盒环境中的网络流量分析,追溯识别以前未知的恶意软件

摘要

Techniques are provided for retroactively identifying malware programs when new signatures become available that later match network traffic previously obtained from the sandbox environment. An exemplary method comprises obtaining a plurality of packet capture files comprising previously captured network communications of malware programs that previously executed in a sandbox environment, wherein each of the packet capture files are associated with a corresponding malware program that generated the network communications; obtaining signatures indicative of at least one malware program; comparing the signatures to the packet capture files; and retroactively identifying a given malware program as malware if a signature matches a given packet capture file associated with the given malware program. A plurality of malware samples that were previously unidentified are optionally correlated with the given malware program based on a scan of additional packet capture files for the signature that matched the given packet capture file.
机译:提供了用于在新签名可用时追溯地识别恶意软件程序的技术,这些新签名随后与以前从沙盒环境中获取的网络流量匹配。一种示例性方法包括:获取多个分组捕获文件,其包括先前在沙盒环境中执行的恶意软件程序的先前捕获的网络通信,其中,每个分组捕获文件与生成网络通信的相应恶意软件程序相关联;获取指示至少一个恶意软件程序的签名;比较签名和数据包捕获文件;如果签名与与给定恶意软件程序相关联的给定数据包捕获文件匹配,则追溯地将给定恶意软件程序识别为恶意软件。基于对与给定数据包捕获文件相匹配的签名的附加数据包捕获文件的扫描,可以将先前未识别的多个恶意软件样本与给定的恶意软件程序相关联。

著录项

  • 公开/公告号US10313366B1

    专利类型

  • 公开/公告日2019-06-04

    原文格式PDF

  • 申请/专利权人 EMC IP HOLDING COMPANY LLC;

    申请/专利号US201615274127

  • 发明设计人 ERIK M. HEUSER;

    申请日2016-09-23

  • 分类号H04L29/06;G06F21/53;

  • 国家 US

  • 入库时间 2022-08-21 12:11:48

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号