首页> 外国专利> Interactive infection visualization for improved exploit detection and signature generation for malware and malware families

Interactive infection visualization for improved exploit detection and signature generation for malware and malware families

机译:交互式感染可视化可改善恶意软件和恶意软件家族的漏洞利用检测和签名生成

摘要

According to one embodiment, a malware detection and visualization system comprises one or more processors; and a storage module communicatively coupled to the one or more processors, the storage module comprises logic, upon execution by the one or more processors, that accesses a first set of information that comprises (i) information directed to a plurality of observed events and (ii) information directed to one or more relationships that identify an association between different observed events of the plurality of observed events; and generates a reference model based on the first set of information, the reference model comprises at least a first event of the plurality of observed events, a second event of the plurality of observed events, and a first relationship that identifies that the second event is based on the first event, wherein at least one of (i) the plurality of observed events or (ii) the one or more relationships constitutes an anomalous behavior is provided.
机译:根据一个实施例,一种恶意软件检测和可视化系统包括一个或多个处理器。以及通信地耦合至一个或多个处理器的存储模块,该存储模块包括逻辑,该逻辑在由一个或多个处理器执行时访问第一组信息,该第一组信息包括(i)指向多个观察到的事件的信息,以及ii)指向一个或多个关系的信息,该关系标识多个观察事件中不同观察事件之间的关联;并基于第一组信息生成参考模型,该参考模型至少包括多个观察到的事件中的第一事件,多个观察到的事件中的第二事件以及标识该第二事件为基于第一事件,其中提供(i)多个观察到的事件或(ii)一个或多个关系构成异常行为中的至少一个。

著录项

  • 公开/公告号US10027689B1

    专利类型

  • 公开/公告日2018-07-17

    原文格式PDF

  • 申请/专利权人 FIREEYE INC.;

    申请/专利号US201414500587

  • 发明设计人 HIRENDRA RATHOR;KAUSHAL DALAL;ANIL GUPTA;

    申请日2014-09-29

  • 分类号H04L29/06;G06F3/0481;G06F21/56;G06F19/18;

  • 国家 US

  • 入库时间 2022-08-21 13:05:37

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号