首页> 外国专利> System and method for detecting malicious activity based on at least one environmental property

System and method for detecting malicious activity based on at least one environmental property

机译:基于至少一种环境特性的恶意活动检测系统及方法

摘要

Techniques for detecting exfiltration content are described herein. According to one embodiment, a malicious content suspect is executed and a packet inspection of outbound network traffic is performed by a packet inspector running within the virtual machine. Occurring before the outbound network traffic leaving the virtual machine, the packet inspector determines whether a portion of outbound network traffic matches one or more portions of predetermined network traffic patterns or signatures. If so, a determination is made whether the outbound network traffic includes at least one environmental property of the virtual machine that is unique or almost unique to the virtual machine. If so, migration of the outbound network traffic outside of the virtual machine is precluded and an alert is transmitted. The alert includes the malicious content suspect that is attempting to perform an exfiltration of data.
机译:本文描述了检测渗出含量的技术。根据一个实施例,由虚拟机内运行的分组检查器执行恶意内容嫌疑人,并对出站网络流量进行分组检查。数据包检查器在出站网络流量离开虚拟机之前发生,以确定出站网络流量的一部分是否与预定网络流量模式或签名的一个或多个部分匹配。如果是这样,则确定出站网络流量是否包括虚拟机的至少一个虚拟机唯一或几乎唯一的环境属性。如果是这样,则排除了虚拟机外部的出站网络流量的迁移,并发送了警报。该警报包括试图执行数据泄露的恶意内容嫌疑人。

著录项

  • 公开/公告号US9934381B1

    专利类型

  • 公开/公告日2018-04-03

    原文格式PDF

  • 申请/专利权人 FIREEYE INC.;

    申请/专利号US201715425954

  • 发明设计人 DARIEN KINDLUND;JULIA WOLF;JAMES BENNETT;

    申请日2017-02-06

  • 分类号G06F12/14;G06F9/455;G06F11/30;H04L29/06;G06F21/56;G06F21/53;

  • 国家 US

  • 入库时间 2022-08-21 12:55:28

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号