首页> 外国专利> System, apparatus and method for automatically verifying exploits within suspect objects and highlighting the display information associated with the verified exploits

System, apparatus and method for automatically verifying exploits within suspect objects and highlighting the display information associated with the verified exploits

机译:用于自动验证可疑物体内的利用的系统,装置和方法,并突出显示与验证的漏洞相关联的显示信息

摘要

According to one embodiment, a threat detection system comprising an intrusion protection system (IPS) logic, a virtual execution logic and a reporting logic is shown. The IPS logic is configured to receive a first plurality of objects and analyze the first plurality of objects to identify a second plurality of objects as potential exploits, the second plurality of objects being a subset of the first plurality of objects and being lesser or equal in number to the first plurality of objects. The virtual execution logic including at least one virtual machine configured to process content within each of the second plurality of objects and monitor for anomalous behaviors during the processing that are indicative of exploits to classify that a first subset of the second plurality of objects includes one or more verified exploits. The reporting logic configured to provide a display of exploit information associated with the one or more verified exploits.
机译:根据一个实施例,示出了包括入侵保护系统(IPS)逻辑,虚拟执行逻辑和报告逻辑的威胁检测系统。 IPS逻辑被配置为接收第一多个对象,并分析第一多个对象以将第二多个对象识别为潜在的漏洞,第二多个对象是第一多个对象的子集,并且更小或等于 向第一多个对象的编号。 虚拟执行逻辑,包括至少一个虚拟机,该虚拟机被配置为在指示用于分类第二多个对象的第一子集包括一个或或 更多已验证的漏洞利用。 报告逻辑被配置为提供与一个或多个验证的漏洞相关联的利用信息的显示。

著录项

  • 公开/公告号US11089057B1

    专利类型

  • 公开/公告日2021-08-10

    原文格式PDF

  • 申请/专利权人 FIREEYE INC.;

    申请/专利号US201916679030

  • 申请日2019-11-08

  • 分类号H04L29/06;G06F21/56;G06F9/455;G06F21/53;

  • 国家 US

  • 入库时间 2022-08-24 20:28:35

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号