首页> 外国专利> AUTOMATED CLASSIFICATION OF EXPLOITS BASED ON RUNTIME ENVIRONMENTAL FEATURES

AUTOMATED CLASSIFICATION OF EXPLOITS BASED ON RUNTIME ENVIRONMENTAL FEATURES

机译:基于运行时环境特征的漏洞自动分类

摘要

Various approaches are described herein for the automated classification of exploit(s) based on snapshots of runtime environmental features of a computing process in which the exploit(s) are attempted. The foregoing is achieved with a server and local station(s). Each local station is configured to neutralize operation of malicious code being executed thereon, obtain snapshot(s) indicating the state thereof at the time of the exploitation attempt, and perform a classification process using the snapshot(s). The snapshot(s) are analyzed with respect to a local classification model maintained by the local station to find a classification of the exploit therein. If a classification is found, an informed decision is made as to how to handle the classified exploit. If a classification is not found, the snapshot(s) are provided to the server for classification thereby. The server provides an updated classification model containing a classification for the exploit to the local station(s).
机译:本文中描述了多种方法,用于基于尝试进行漏洞利用的计算过程的运行时环境特征的快照来对漏洞利用方法进行自动分类。前述是通过服务器和本地站来实现的。每个本地站被配置为抵消在其上执行的恶意代码的操作,获得在利用尝试时指示其状态的快照,并使用该快照执行分类处理。关于由本地站维护的本地分类模型来分析快照,以在其中找到漏洞利用的分类。如果找到分类,则就如何处理分类的漏洞做出明智的决定。如果未找到分类,则将快照提供给服务器以进行分类。服务器向本地站提供更新的分类模型,其中包含用于利用的分类。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号