首页> 外国专利> MALWARE DETECTION BY A SANDBOX SERVICE BY UTILIZING CONTEXTUAL INFORMATION

MALWARE DETECTION BY A SANDBOX SERVICE BY UTILIZING CONTEXTUAL INFORMATION

机译:利用上下文信息,通过沙箱服务检测恶意软件检测

摘要

Systems and methods for improving malware detection by a sandbox service by utilizing Endpoint Detection and Response (EDR) origin contextual information are provided. According to an embodiment, a sandbox service associated with a network security platform protecting an enterprise network receives a file associated with sandbox-evading malware, to be classified by the sandbox service, and contextual information related to the file. The file is received from an endpoint security solution of the network security platform running on an endpoint device of the enterprise network. The sandbox service classifies the file as being malware by detonating the sandbox-evading malware as a result of performing sandboxing on the file including emulating an environment of the endpoint device based on the contextual information.
机译:提供了通过利用端点检测和响应(EDR)原点来提高沙箱服务的恶意软件检测的系统和方法。根据一个实施例,与网络安全平台相关联的沙箱服务保护企业网络接收与沙箱逃避恶意软件相关联的文件,以由Sandbox服务分类,以及与文件相关的上下文信息。该文件是从在企业网络的端点设备上运行的网络安全平台的端点安全解决方案接收的文件。由于在文件上执行沙箱eDoding恶意软件,包括在包括基于上下文信息的内部点来模仿端点设备的环境的文件的结果,将文件分类为恶意软件。

著录项

  • 公开/公告号US2021200859A1

    专利类型

  • 公开/公告日2021-07-01

    原文格式PDF

  • 申请/专利权人 FORTINET INC.;

    申请/专利号US201916731291

  • 发明设计人 UDI YAVO;ROY KATMOR;IDO KELSON;

    申请日2019-12-31

  • 分类号G06F21/53;G06F21/56;

  • 国家 US

  • 入库时间 2022-08-24 19:42:17

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号