首页> 外国专利> Detection and classification of exploit kits

Detection and classification of exploit kits

机译:漏洞利用工具包的检测和分类

摘要

A non-transitory computer readable storage medium having stored thereon instructions executable by a processor to perform operations including: responsive to determining that a correlation between a representation of the first portion of network traffic and a representation of a known exploit kit results in a score above a first prescribed score value, classifying the representation of the first portion of the received network traffic into an exploit kit family corresponding to the representation the known exploit kit; and responsive to determining that the score is below the first prescribed score value and above a second prescribed score value, (i) analyzing the representation of the first portion of the received network traffic, and (ii) processing, within a virtual machine, a second portion of the received network traffic to determine whether processing of the received network traffic results in behavior indicative of an exploit kit is shown.
机译:一种非暂时性计算机可读存储介质,其上存储有可由处理器执行以执行以下操作的指令:响应于确定网络流量的第一部分的表示与已知利用工具包的表示之间的相关性导致得分高于第一规定分数值,将接收到的网络业务的第一部分的表示分类为与已知利用工具包的表示相对应的利用工具包系列;并响应于确定该分数低于第一规定分数值且高于第二规定分数值,(i)分析接收到的网络流量的第一部分的表示,以及(ii)在虚拟机中处理确定接收到的网络流量的第二部分以确定是否处理接收到的网络流量导致指示漏洞利用工具包的行为。

著录项

  • 公开/公告号US9825976B1

    专利类型

  • 公开/公告日2017-11-21

    原文格式PDF

  • 申请/专利权人 FIREEYE INC.;

    申请/专利号US201514871830

  • 发明设计人 ABHISHEK SINGH;JOSHUA LEWIS GOMEZ;

    申请日2015-09-30

  • 分类号H04L29/06;G06N99/00;G06N7/00;

  • 国家 US

  • 入库时间 2022-08-21 12:55:12

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号