WO2016109283A1 - Intelligent context aware user interaction for malware detection - Google Patents
Intelligent context aware user interaction for malware detection Download PDFInfo
- Publication number
- WO2016109283A1 WO2016109283A1 PCT/US2015/067082 US2015067082W WO2016109283A1 WO 2016109283 A1 WO2016109283 A1 WO 2016109283A1 US 2015067082 W US2015067082 W US 2015067082W WO 2016109283 A1 WO2016109283 A1 WO 2016109283A1
- Authority
- WO
- WIPO (PCT)
- Prior art keywords
- simulated
- action
- logic
- human interaction
- profile
- Prior art date
Links
Classifications
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1441—Countermeasures against malicious traffic
- H04L63/145—Countermeasures against malicious traffic the attack involving the propagation of malware through the network, e.g. viruses, trojans or worms
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/56—Computer malware detection or handling, e.g. anti-virus arrangements
- G06F21/566—Dynamic detection, i.e. detection performed at run-time, e.g. emulation, suspicious activities
-
- G—PHYSICS
- G06—COMPUTING; CALCULATING OR COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F9/00—Arrangements for program control, e.g. control units
- G06F9/06—Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
- G06F9/44—Arrangements for executing specific programs
- G06F9/455—Emulation; Interpretation; Software simulation, e.g. virtualisation or emulation of application or operating system execution engines
- G06F9/45533—Hypervisors; Virtual machine monitors
Definitions
- Embodiments of the disclosure relate to the field of cyber security. More specifically, one embodiment of the disclosure relates to a system, apparatus and method for detecting malware.
- malware malicious software
- malware has become a pervasive problem for Internet users.
- malware exploits vulnerabilities in networked resources.
- network devices such as vulnerabilities within operating systems for example.
- vulnerabilities continue to be addressed through software patches, prior to the release of such software patches, network devices will continue to be targeted for attack by exploits that use malicious computer code.
- the malware may attempt to acquire sensitive information or adversely influence or attack normal operations of a network device or the entire enterprise network.
- one or more virtual machines may be used to process objects, which may include, for example, content from network traffic and/or files retrieved from a storage location, in order to activate, observe, and thereby detect malicious software.
- objects may include, for example, content from network traffic and/or files retrieved from a storage location, in order to activate, observe, and thereby detect malicious software.
- GUI graphical user interface
- this processing may require user interaction, for example, in the form of an input initiated by an input device such as a graphical user interface (GUI), mouse, keyboard, keypad or the like.
- GUI graphical user interface
- current malware detection systems may fail to activate the malicious content within the objects.
- One reason is that sophisticated malware often has a self-defense mechanism, which attempts to detect whether it is running in a virtual environment of a malware detection system rather than the intended environment of a client device under user control.
- One type of self-defense mechanism involves the malware monitoring whether user input expected by an application is supplied at the appropriate time. If it is not, the malware may simply hibernate
- Some conventional malware detection systems apply generic, static patterns of simulated input device controls in a viitual run-time environment in the absence of actual human interaction.
- malware creators have been able to identify these patterns.
- they have been able to equip their malware to identify such static simulated device controls, and upon detection, cause the malware to refrain from activating the malicious code in order to remain undetected.
- some conventional malware detection systems may experience unacceptable levels of false negatives or be forced to deploy a multitude of pattern detection schemes that will increase the rate of false positives.
- FIG. 1 is an exemplary block diagram of a first embodiment of a malware detection system (MDS) which features user interaction (UI) control logic deployed as part of a virtual run-time environment to provide simulated user interaction to detonate a malicious object.
- MDS malware detection system
- UI user interaction
- FIG. 2 is an exemplary block diagram of a second embodiment of the MDS which features a second architecture scheme of the UI control logic deployed as part of the virtual run-time environment.
- FIG. 3A is an exemplary block diagram of a first operational flow for the UI control logic operating within the virtual ran-time environment.
- FIG. 3B is an exemplary block diagram of a second operational flow for the UI control logic operating within the virtual run-time environment.
- FIG. 4A is a flowchart illustrating an exemplary process conducted by passive UI simulation logic and device control simulation logic that are operating in accordance with a selected action profile and are conducting simulated user interactions to increase the likelihood in accurately detecting a malicious object.
- FIG. 4B is a flowchart illustrating an exemplary process conducted by the active UI simulation logic that is operating in accordance with the selected action profile and is conducting simulated user interactions to increase the likelihood in accurately detecting a malicious object.
- FIG. 5 is an exemplary block diagram of the logical architecture associated with the MDS of FIG. 1. DETAILED DESCRIPTION
- Various embodiments of the disclosure are directed to a system and method for determining whether or not an object is associated with a malicious attack through, at least, a dynamic analysis of the object within a virtual run-time environment.
- the virtual run-time environment features one or more virtual machine instances (VMs), which are provisioned with a guest image associated with a prescribed software profile.
- the guest image may include a software application in addition to an operating system (OS) along with monitors, namely software components that are configured to observe and capture run-time behavior of an object under analysis during processing within the virtual machine.
- OS operating system
- monitors namely software components that are configured to observe and capture run-time behavior of an object under analysis during processing within the virtual machine.
- the term “launch” represents performance of one or more events that starts activation of an object under analysis while the phrase “detonate” (and other tenses) represents performance of one or more events that trigger a malicious attack by the activated object.
- UI control logic may be deployed as part of the virtual run-time environment in order to provide simulated user interaction needed to detonate certain types of malicious objects within a VM.
- UI control logic comprises a plurality of components, including (1) a profile selector and (2) a UI framework, as described herein.
- the UI control logic may feature multiple implementations.
- the UI control logic may be provisioned as components of a VM.
- the UI framework may be provisioned as a component of the VM, but the profile selector may be deployed as part of a virtual machine monitor (VMM), which may be deployed, according to one embodiment of the disclosure, as part of a "hosted hypervisor" (e.g., software that runs on top of a host operating system) or as an intermediary operation layer between the hardware and the VMs.
- VMM virtual machine monitor
- the profile selector may be adapted to provision the UI framework component within the VM and perhaps multiple UI framework components within multiple VMs.
- the profile selector selects an action profile from a plurality of action profiles that may be hosted in the VM or outside the VM within the virtual run-time environment. This selection may be based, at least in part, on metadata associated with an object under analysis.
- the metadata defines, at least in part, the context for determining the action profile that governs the simulated user interaction.
- the metadata further determines the software appropriate to launch the object in the run-time environment.
- the selection of the action profile also may be based on a type of network device deploying (hosting) the VM (e.g., security appliance that analyzes network traffic, files within a file storage system, etc.) or other information from the static analysis of the object.
- the dynamic analysis of the object is "context aware".
- the metadata may include data that identifies the type of object under analysis.
- other metadata may be used by the profile selector for selecting the particular action profile.
- other metadata that may be used by the profile selector to select a particular action profile for controlling the simulation of user interactions with the object launched in the VM may include, but are not limited or restricted to information related to the following: (i) whether the object is enciypted and/or its type of encryption scheme, (ii) whether the object is an embedded object, (iii) the type of application needed for processing the object, and/or (iv) transmission protocol used in delivery of network content including the object.
- Each "action profile” is a collection of instructions and/or commands that performs UI functionality in accordance with a set of rules prescribed for that action profile.
- each action profile is configured for use in dynamically controlling UI actions associated with a certain type of object in contrast to the use of patterns perse.
- the action profile associated with a Microsoft® Excel® spreadsheet may conduct different UI actions (e.g., select tabs, add text to certain cells, scroll down a certain number of cell rows, etc.) than a PDF document (e.g., scroll pages of the document, etc.) and such actions may be conducted at different times depending on the behavior of the object under analysis.
- the UI framework comprises (i) the actuation logic, (ii) active UI simulation logic; (iii) passive UI simulation logic; and (iv) device control simulation logic.
- the actuation logic is a software component that is implemented as part of a software profile that provisions the VM and is responsible for launching the object under analysis. The particular implementation of the actuation logic may vary depending on the object type. Upon the actuation logic launching the object, the active UI simulation logic, the passive UI simulation logic and the device control simulation logic are instantiated with or are instantiated to access content within the selected action profile.
- the simulation logic within the UI framework conducts particular actions (e.g., expected user interface interactions and/or methods of activation) during particular operating states at which such actions are expected if the object was running on a targeted endpoint.
- actions e.g., expected user interface interactions and/or methods of activation
- These particular actions may be conducted in accordance with a predetermined sequence (order) and/or at (or within) predeteimined periods of time.
- two or more of these particular actions may be conducted concurrently (at least partially overlapping at the same time) or such actions may be performed sequentially.
- the active UI simulation logic detects input requests (e.g., password request, opening of a dialog box that requires dismissal prior to continuing, opening of a text box that requires text entry, etc.), which require human interaction that directly responds to the input request. This type of simulated human interaction is referred to herein as "active" simulated human interaction.
- the active UI simulation logic operates in accordance with the selected action profile to determine whether to provide a response and the type of response, where appropriate.
- the passive UI simulation logic operates in accordance with the selected action profile and, in certain cases, provides simulated human interaction in response to a prescribed level of inactivity by the object and/or a prescribed period of time after the suspect object has launched has elapsed.
- the passive UI simulation logic is in communication with timing circuitry (e.g., real time clock, counter, etc.), where the monitored time plays a factor in determining when to conduct prescribed simulated human interactions that are triggered by a period of inactivity by the object and/or an elapsed time from when the suspect object was launched.
- the passive UI simulation logic simulates user-initiated interactions on the object such as moving to a particular page in a Microsoft® Office Word document (object), switching to a particular tab in a Microsoft® Office Excel document (object), or switching to a different PowerPointTM slide in accordance with the object-specific action profile.
- object is a Microsoft® Office Excel document
- experiential knowledge of typical placement of exploit/malicious code (e.g., through machine learning techniques) in a Microsoft® Office Excel document may result in instructions by the selected action profile for the passive UI simulation logic to simulate human interaction by switching to the second sheet of the Microsoft® Office Excel document at a predetermined time after the actuation logic launches the object.
- the device control simulation logic operates in accordance with the selected action profile and provides simulated device controls that are agnostic to object type, which may occur in response to yet another level of prescribed inactivity.
- the device control simulation logic may receive instructions from the selected action profile to simulate certain device control interactions, such as simulate particular keystrokes and/or particular mouse movements, in an attempt to trigger a malicious attack by the object.
- Embodiments of the disclosure may be employed by or take the form of a network device, including a cyber-security appliance that features a malware detection system (MDS).
- MDS includes a static analysis engine and a dynamic analysis engine, or, in another embodiment, only a dynamic analysis engine.
- the MDS includes a static analysis engine and a dynamic analysis engine, or, in another embodiment, only a dynamic analysis engine.
- the MDS may be implemented as a server or client device or other system (any of which may be referred to as an "endpoint") connectable to a network.
- the dynamic analysis engine may include a virtual run-time environment that automatically analyzes, without user assistance, objects from the received network traffic and simulates human interaction to detonate and detect malicious objects during virtual processing. The results of the analysis may be reported to network administrators or other personnel for further analysis and action.
- logic is representative of hardware, firmware and/or software that is configured to perform one or more functions.
- logic may include circuitry having data processing or storage functionality. Examples of such circuitry may include, but are not limited or restricted to a microprocessor, one or more processors and/or processor cores, a programmable gate array, a microcontroller, an application specific integrated circuit, semiconductor memory, or combinatorial logic.
- Logic may be software in the form of one or more software modules, such as executable code in the form of an executable application, an application programming interface (API), a subroutine, a function, a procedure, an applet, a servlet, a routine, source code, object code, a shared library/dynamic load library, or one or more instructions.
- API application programming interface
- These software modules may be stored in any type of a suitable non-transitory storage medium, or transitory storage medium (e.g., electrical, optical, acoustical or other form of propagated signals such as carrier waves, infrared signals, or digital signals).
- non-transitory storage medium may include, but are not limited or restricted to a programmable circuit; a semiconductor memory; non-persistent storage such as volatile memory (e.g., any type of random access memory "RAM”); persistent storage such as non-volatile memory (e.g., read-only memory "ROM”, power-backed RAM, flash memory, phase-change memory, etc.), a solid-state drive, hard disk drive, an optical disc drive, or a portable memory device.
- volatile memory e.g., any type of random access memory "RAM”
- persistent storage such as non-volatile memory (e.g., read-only memory "ROM”, power-backed RAM, flash memory, phase-change memory, etc.), a solid-state drive, hard disk drive, an optical disc drive, or a portable memory device.
- the executable code may be stored in persistent storage.
- the term "object” generally refers to a collection of data, whether in transit (e.g., over a network) or at rest (e.g., stored), often having a logical structure or organization that enables it to be classified for purposes of analysis.
- the object may exhibit a set of expected characteristics and, during processing, a set of expected behaviors.
- the object may also exhibit a set of unexpected characteristics and a set of unexpected behaviors that may evidence the presence of malware and potentially allow the object to be classified as part of a malicious attack.
- Examples of objects may include one or more flows or a self-contained element within a flow itself.
- a "flow” generally refers to related packets that are received, transmitted, or exchanged within a communication session.
- a packet is broadly referred to as a series of bits or bytes having a prescribed format, which may, according to one embodiment, include packets, frames, or cells.
- an "object” may also refer to collective payloads of a number of related packets, e.g., a single webpage received over a network.
- an object may be a file or document retrieved from a storage location over a transmission medium.
- the object may be an executable (e.g., an
- non-executables may include a document (e.g., a Portable Document Format "PDF” document, Microsoft® Office® document, Microsoft®
- PDF Portable Document Format
- transmission medium may be construed as a physical or logical communication path between two or more network devices (e.g., any devices with data processing and network connectivity such as, for example, a security appliance, a server, a mainframe, a computer such as a desktop or laptop, netbook, tablet, firewall, smart phone, router, switch, bridge, etc.) or between components within a network device.
- network devices e.g., any devices with data processing and network connectivity such as, for example, a security appliance, a server, a mainframe, a computer such as a desktop or laptop, netbook, tablet, firewall, smart phone, router, switch, bridge, etc.
- RF radio frequency
- network device should be construed as any electronic device with the capability of connecting to a network.
- a network may be a public network such as the Internet or a private network such as a wireless data telecommunication network, wide area network, a type of local area network (LAN), or a combination of networks.
- Examples of a network device may include, but are not limited or restricted to, a laptop, a mobile phone, a tablet, a computer, a security appliance, or the like.
- the term "computerized” generally represents that any corresponding operations are conducted by hardware in combination with software and/or firmware. Also, the terms “compare” or “comparison” generally mean determining if a match (e.g., a certain level of correlation) is achieved between two items where one of the items may include a particular signature pattern.
- action profile should be interpreted as a plurality of instructions and/or commands that provision logic to conduct, in accordance with a set of rules prescribed for that particular action profile, different types of simulated user interactions.
- the simulated user interactions may include "active" simulated human interactions; “passive” simulated human interactions and simulated device control interactions.
- An active simulated human interaction includes simulated actions that may be performed by a user in response to an event initiated by a suspect object under analysis. In some situations, the simulated action may be required before any further activities are conducted by the object. Examples of an active simulated human interaction include closing a window or dialog box; selecting a particular radio button; and/or entering characters into a text box).
- a passive simulated human interaction includes simulated actions that are normally performed by a user during activation of the object, but such actions are not responsive to a particular behavior by the object.
- Examples of passive simulated human interaction include scrolling pages of a document (e.g., PDF or Word® document), browser, or other type of displayed image; selecting certain tabs of an Excel®
- a simulated device control interaction includes simulated input from an input device for an endpoint. Examples of a simulated device control interaction include keystrokes, mouse movement or clicks, and/or detected activation of certain area or areas of a touch screen.
- the invention may be utilized for detection, verification and/or prioritization of malware, which may include malicious content, in particular, through providing object- type specific simulated human interaction to an object activated in a virtual run-time environment.
- malware which may include malicious content
- object- type specific simulated human interaction to an object activated in a virtual run-time environment.
- MDS malware detection systems
- the management system 120 is adapted to manage each MDS 110i- 1 Kb.
- the management system 120 may be configured to perform content updates (e.g., upload new rules or modified rules, delete rules, modify parameters that are utilized by the rules and/or upload metadata) within logic operating as part of a communication interface 140, a static analysis engine 145, a dynamic analysis engine 160, a classification engine 190, and/or a reporting engine 195 with an optional user interface capability (e.g., for purposes of initial system set up and configuration).
- the management system 120 is configured to propagate updates to one or more action profiles (hereinafter "action profile(s)”) via action profile update logic 174.
- the action profile(s) 188 are used to control the simulation of human interactions with and/or device controls for the object during analysis, as described below.
- a first malware detection system (MDS) 11 Oi is an electronic device that is adapted to analyze information associated with incoming data (e.g., network traffic, input data over a communication network 105, input data from another type of transmission medium, etc.) from/to one or more endpoints 132.
- the communication network 105 may include a private network such as a wireless data telecommunication network, wide area network, a type of local area network (LAN), or a combination of networks.
- Other embodiments may include incoming data (files from a file store) being retrieved from a file storage location (e.g., a hard disk drive (HDD) or a flash drive storage) for malware detection.
- the first MDS 1 lOi is communicatively coupled with the communication network 105 via an interface 136 and/or an operational firewall 134.
- the interface 136 may operate as a data capturing device that is configured to receive at least a portion of network traffic propagating to/from one or more endpoints 132 and provide information associated with the received portion of the network traffic to the first MDS 110L This information may include an object, namely multiple packets collectively forming an executable or a non-executable (e.g., a document embedded within an email message or a web page). Alternatively, although not shown, the interface 136 may be configured to receive files or other objects that are not provided over a network.
- the interface 136 may be a data capturing device that automatically (or on command) accesses data stored in a storage system or another type of interface, such as a port, for receiving objects manually provided via a suitable dedicated communication link or from storage media such as portable flash drives.
- the interface 136 may be configured to capture data typically directed to the endpoint 132, where the captured data includes at least one object 147 for analysis and its corresponding metadata 148.
- the metadata 148 may be used, at least in part, to determine protocols, application types and other information that may be subsequently used by logic, such as a scheduler 150 for example, to configure one or more VMs 170I-170M (M>1) with selected software profiles.
- the metadata 148 may be used to determine which software images (e.g., application(s)), if any, in addition to operating systems to be fetched a storage device 151 for configuring operability of the VMs 170i-170Min order to process the subject object 147 at a desired time, for a desired period of time, and/or in a desired order. Additionally, as one feature of the invention, the metadata 148 associated with the suspect object 147 may be used by the profile selector 184, implemented in the VM(s) itself (e.g.
- VM 170i or in the virtual machine monitor (VMM) 172 as described below, to select which action profile(s) 188 for controlling simulated user interaction with the suspect object 147 in efforts to detonate the suspect object 147 within one or more of the VM 170I-170M.
- VMM virtual machine monitor
- interface 136 may be contained within the first MDS 110i.
- the interface 136 can be integrated into an intermediary device in the communication path (e.g., a firewall, router, switch or other networked electronic device) or can be a standalone component, such as an appropriate commercially available network tap as shown.
- the first MDS 110i comprises the communication interface 140, the static analysis engine 145, the dynamic analysis engine 160, the classification engine 190 and the reporting engine 195.
- the communication interface 140 receives an object from the interface 136 and converts that object into a format, as needed or appropriate, on which analysis by the static analysis engine 145 may be conducted. This conversion may involve decompression of the object, decompilation of the object, extraction of specific data associated with the object, and/or emulation of the extracted data (like JavascriptTM).
- the communication interface 140 in some embodiments, may be integrated into the interface 136.
- the static analysis engine 145 may include one or more controllers (e.g., processing circuitry such as one or more processors) that feature static analysis logic 152, metadata extraction logic 154, and object-type determination logic 156 for accessing magic number database 158 and/or data store 159.
- the data store 159 may be used to store the analyzed object 147 and/or extracted metadata 148 prior to transmission to the data analysis engine 160 upon determining that the object 147 is "suspicious" and requires further analysis to determine whether that object 147 is associated with a malicious attack.
- the static analysis logic 152 includes one or more software modules that, when executed by the controller(s), analyzes characteristics associated with the suspect object 147, which may be a portion of network traffic (or downloaded data) according to this embodiment of the disclosure.
- Such static analysis may include one or more checks being conducted on the object without its execution. Examples of the checks may include (i) heuristics, which is based on rules or policies as applied to the object 147 and may determine whether one or more portions of the object 147 is associated with anomalous or suspicious characteristics (e.g., a particular URL associated with known exploits, or a particular source or destination address etc.) associated with known exploits; or (ii) determinative rule-based analysis that may include blacklist or whitelist checking.
- the metadata extraction logic 154 is responsible for extracting and/or generating metadata 148 contained as part of and/or associated with the suspect object 147.
- the extraction and/or generation of the metadata 148 may occur after the object 147 is determined by the static analysis logic 152 to feature anomalous or suspicious characteristics.
- the metadata extraction logic 154 may extract and/or generate the metadata 148 prior to or concurrently with the operations conducted by static analysis logic 152.
- the metadata 148 may be identified as being associated with the suspect object 147, and is stored accordingly.
- metadata 148 may include, but are not restricted or limited to, information that identifies the type of object 147.
- a particular document e.g., Microsoft® Excel spreadsheet
- This metadata 148 may be subsequently used by the profile selector 184 to select at least one particular action profile for controlling simulated user interaction conducted during analysis of the object 147 within one or more VMs 170i-l 70M of the virtual run- time environment 164, as described below.
- Metadata may be captured by metadata extraction logic 154.
- metadata which may be used by the profile selector 184 for selecting the particular action profile.
- This metadata may include, but is not limited or restricted to the following: (i) data identifying whether the object is encrypted and/or its type of encryption scheme, (ii) data identifying whether the object is an embedded object, (iii) data identifying the type of application needed for processing the object, and/or (iv) data identifying the transmission protocol used in delivery of network content including the object.
- the object-type determination logic 156 may determine object type. For instance, the object-type determination logic 156 may analyze content within the object 147, which may identify the object type. For instance, as an illustrative example, the object-type determination logic 156 may identify a predetermined number of bytes at the beginning of the object 147 (sometimes referred to as the "magic numbers" for the object) and compare the values associated with these bytes with stored values within the magic number database 158. Upon a successful comparison, the object-type determination logic 156 has identified the object type.
- the object-type determination logic 156 may identify a predetermined number of bytes at the beginning of the object 147 (sometimes referred to as the "magic numbers" for the object) and compare the values associated with these bytes with stored values within the magic number database 158.
- the first few bytes of the object 147 may, in certain cases, be used to determine the object-type or at least infer the object type based on the communication protocol in use.
- the object-type may, in certain cases, be used to determine the object-type or at least infer the object type based on the communication protocol in use.
- the object-type may, in certain cases, be used to determine the object-type or at least infer the object type based on the communication protocol in use.
- the object-type may, in certain cases, be used to determine the object-type or at least infer the object type based on the communication protocol in use.
- the object-type may, in certain cases, be used to determine the object-type or at least infer the object type based on the communication protocol in use.
- the object-type may, in certain cases, be used to determine the object-type or at least infer the object type based on the communication protocol in use.
- the object-type may, in certain cases, be used to determine the object-type or at least infer the object type
- determination logic 156 may determine that the object 147 starts with the hexadecimal string value "4D5 A" which, upon comparison with entries within the magic number database 158, identifies that the object 147 is an executable. Similar, the object-type determination logic 156 may determine that the object 147 starts with a hexadecimal string value of "25 50 44 46" and, upon comparing this value with stored data within the magic number database 158, determines that the object 147 is a PDF document.
- the static analysis engine 145 may route the suspect object 147 along with the metadata 148 (inclusive of any object type information generated by the object-type determination logic 156) to the virtual run-time environment 164 within the dynamic analysis engine 160.
- the results of the static analysis may be used to establish an order of processing of objects in the virtual run-time environment 164 based on the level of "suspiciousness" of the objects (e.g., as established by a relative suspiciousness score).
- the static analysis engine 145 may also filter benign objects from further analysis.
- the static analysis engine 145 may simply denote that the object 147 is non-malicious and may refrain from subjecting the object 147 to further analysis. However, upon determining that the object 147 includes characteristics that are suspicious, extracting the metadata 148 associated with the suspect object 147 and determining the object type, the static analysis engine 145 may pass this suspect object 147 along with the metadata 148 to the dynamic analysis engine 160 for more in- depth analysis in a VM-based operating environment.
- the static analysis engine 145 may be integrated into the interface 136 or into other devices, such as a firewall or another network device, such as a network device located at the periphery of a network to be protected so as to capture and examine objects contained in ingress content.
- the dynamic analysis engine 160 may include processing logic 162, a virtual runtime environment 164, a data store 166, and/or a score determination logic 168.
- processing logic 162 may be configured to control interoperability between components within the dynamic analysis engine 160. For instance, the processing logic 162 may control the buffering of the passed objects and their corresponding metadata into the data store 166 and the loading of the objects and corresponding metadata into the VM(s) 170I-170M directly or into the VMM 172 for supply to the VMs 170i-170 M .
- the virtual run-time environment 164 provides for virtual processing of the object 147 through one or more VMs 170I-170M managed by a virtual machine monitor (VMM) 172.
- the VMM 172 manages reconfiguration of the one or more VMs 170i- 170M before conducting the virtual analysis based on externally provided configuration updates, namely software profiles (e.g., OS and/or application instances), action profiles, or the like.
- the VMM 172 features action profile update logic 174, which is responsible for updating rales, parameters, instructions, and/or other data maintained by the action profile(s) 188 hosted in VM 170i, as shown.
- the action profile update logic 174 may update action profile(s) 188 hosted in other VMs (e.g., VM 170M) or hosted outside the VM (e.g., within storage device 151, within data store 166, or within storage within the virtual run-time environment (not shown)).
- VM 170M e.g., VM 170M
- the operations of VM 170i are described, although all or some of the other VMs 170M or VMs 170 2 -170M may operate in a similar manner.
- the VM 170i may be provisioned with an operation system (OS) and, dependent on the object type, one or more applications 180, along with the monitoring logic 181 and user interaction (UI) control logic 182.
- the monitoring logic 181 monitors run-time behaviors of the object 147 when launched in the VM 170i .
- the UI control logic 182 provides simulated user interactions to detonate a malicious object that is loaded into the VM 170i and requires some sort of user interaction to initiate a malicious attack.
- the UI control logic 182 comprises a plurality of components, which include (1) a profile selector 184 and (2) UI framework 186.
- the profile selector 184 selects an action profile from the action profile(s) 188 that are shown as being hosted in the VM 170i. This selection may be based, at least in part, on the metadata 148 associated with the suspect object 147.
- the metadata 148 may include data produced by the object-type deteraiination logic 156 that identifies an object type for the object 147.
- the metadata 148 may include other data that is uncovered during parsing of the object 147 by the static analysis engine 145 (e.g., password protected fields, password in an email message that included the object 147, etc.), which may be relied upon for selecting a particular action profile within the action profile(s) 188.
- the UI framework 186 comprises (1) the actuation logic 340 and (2) different types of user interaction (UI) simulation logic 350, where the different UI simulation logic implemented within the UI framework 186 as described below.
- the actuation logic 340 is a software component which is implemented as part of the software profile that provisions the VM 170i and is responsible for "launching" the suspect object 147.
- the object may be "launched" by starting a process that starts the object 147 (when the object 147 is an executable or script) or starting a process that manipulates the object 147 (e.g., opens the object 147 using Adobe® Acrobat® Reader application when the object 147 is a PDF document; opens the object 147 using Microsoft® Office® application when the object 147 is an Excel® (.xls) file, etc.).
- a process that starts the object 147 when the object 147 is an executable or script
- a process that manipulates the object 147 e.g., opens the object 147 using Adobe® Acrobat® Reader application when the object 147 is a PDF document; opens the object 147 using Microsoft® Office® application when the object 147 is an Excel® (.xls) file, etc.
- the actuation logic 340 When launching the object 147, the actuation logic 340 notifies the UI simulation logic 350 of the launched object.
- logic within the simulation logic 350 is instantiated with or is instantiated to access the selected action profile, which controls the simulated user interaction conducted by the UI framework 186 during analysis of the object 147.
- the simulated user interaction may include signaling that simulates a particular action during a particular operating state of the object 147 at which such an action is expected if running on a targeted endpoint (client device).
- These particular actions may be order dependent (sequenced) and/or time dependent (e.g., occur at a particular time, occur at a particular time after a previous action, etc.).
- the monitoring logic 181 and UI framework log 176 collectively operate to record, while the object 147 is launched in the VM 170! , the requests for input by the object 147.
- the monitoring logic 181 and the UI framework log 176 also monitor and log any "active" simulated human interactions provided to the suspect object 147 in response to the input request, any responses to the simulated human interactions by the suspect object 147, "passive" simulated human interactions that are not responsive to behaviors by the suspect object 147, and/or simulated device control interactions.
- the data recorded by the UI framework log 176 may be referenced by the score determination logic 168, which determines a probability (score) that is used, at least in part by the classification engine 190, to determine (i) whether the suspect object 147 is associated with a malicious attack and (ii) severity of the malicious attack.
- the contents of the UI framework log 176 may also provide an ability to correlate, for reporting purposes, malicious objects that are detonated in response to certain type(s) of user interaction.
- the UI framework log 176 can provide information for understanding which simulation logic caused or helped a successful detonation. In other words, from data within the UI framework logic 176, a determination can be made as to the efficacy of action profiles and the UI framework. Such feedback can be used to "fine-tune" action profiles.
- malwares can be classified based on user interaction(s) necessary for detonation. This classification and details of user interaction(s) can augment the Threat Intelligence aspects such as forensic analysis of malwares and incidence response.
- the UI framework logic 176 provides information for understanding the shortcomings in the set of user interactions the UI framework 186 provides (e.g., a new feature might be required in UI framework 186 or new rales or parameters may be needed for the selected action profile).
- a user interaction performed by the UI framework obstructs object detonation, it can be rectified in subsequent action profile update.
- the reporting engine 195 is adapted to receive information from the classification engine 190 via transmission medium 189 and generate alerts (e.g., various types of messages including text messages and email messages, display images, or other types of information over a wired or wireless transmission medium) that identify to a network administrator that the suspect object 147 is associated with a malicious attack and is user-interaction dependent.
- alerts e.g., various types of messages including text messages and email messages, display images, or other types of information over a wired or wireless transmission medium
- FIG. 1 illustrates the MDS 110i as a dedicated network device and the discussion of FIG. 1 explains examples based on an object received over the network interface 136
- the MDS 110i may be implemented on an endpoint, such as the client device 132.
- the MDS 1 10i may launch the object in a sandboxed environment and conduct simulated user interactions, which may include simulated human interactions and simulated device controls. Responsive to non-anomalous behaviors by the object 147, the endpoint 132 is allowed to utilize the object.
- the MDS 110i may be implemented in the cloud computing services 138, where the above described simulated human and device control interactions may be fully or partially conducted therein.
- the dynamic analysis engine 160 includes processing logic 162, virtual run-time environment 164, data store 166 and/or score determination logic 168.
- VM(s) 170I-170M are not provisioned with action profile(s) 188 as shown in FIG. 1. Rather, action profile(s) 188 are hosted outside the VM(s) 170i-170 M .
- the profile selector 184 is deployed as part of the VMM 172.
- the profile selector 184 may be adapted to provision the UI framework component 186 within the VM 170i and perhaps UI framework components within other VMs (e.g., VM 170M).
- FIGs. 3A and 3B exemplary block diagrams of operational flows for the UI control logic 182 within the virtual run-time environment 164 is shown.
- the UI control logic 182 comprises (1) the profile selector 184 and (2) the UI framework 186.
- the UI framework 186 comprises (a) actuation logic 340 and (b) simulation logic 350, which includes (i) active UI simulation logic 360;
- the object 147 and metadata 148 are provided to the VM 170i.
- the profile selector 184 selects an action profile (herein the "selected action profile" 300i) within the action profile(s) 188, namely a plurality of action profiles 300I-300R (R>2) that may be hosted in the VM 170i (as shown) or outside the VM 170i within the virtual run-time environment. This selection may be based, at least in part, on metadata identifying the object type.
- other metadata may be used by the profile selector 184 to better identify the object 147 in order to choose the selected action profile 300i best suited for the particular object under analysis.
- metadata include, but are not limited or restricted to the following: (i) data identifying whether the object 147 is encrypted and/or its type of encryption scheme, (ii) data identifying whether the object 147 is or contains an embedded object,
- each "action profile” is a collection of instructions and/or commands that performs UI functionality in accordance with a set of rules prescribed for that action profile.
- the selected action profile 300i is configured for use in controlling UI functionality during analysis of the object 147.
- the object 147 is identified as a Microsoft® Excel® spreadsheet
- the selected action profile 300i may conduct different UI functions (e.g., select tabs, add text to certain cells, scroll down a certain number of cell rows, etc.) than another action profile 300R for controlling UI functionality during analysis of a PDF document (e.g., scroll pages of the document, etc.).
- the profile selector 184 upon selection of the action profile, provides signaling 310 to identify the selected action profile 300i that is part of the pre-stored action profile(s) 188.
- the content 320 of the selected action profile 300i may be passed to the simulation logic 350 for use by the active UI simulation logic 360, the passive UI simulation logic 370, and the device control simulation logic 380.
- the active UI simulation logic 360 the passive UI simulation logic 370
- the device control simulation logic 380 According to another embodiment of the disclosure, as shown in FIG.
- the profile selector 184 upon choosing the selected action profile 300i, the profile selector 184 passes an identifier 330 of the selected action profile 3001 to the simulation logic 350 (active UI simulation logic 360, passive UI simulation logic 370, and device control simulation logic 380) to allow the simulation logic 350 to poll and retrieve information 335 (e.g., commands, instructions, rules and/or parameters) from the selected action profile 300i.
- information 335 e.g., commands, instructions, rules and/or parameters
- addressing information e.g., a pointer, memory storage location, etc.
- the addressing information may be used for accessing a sequence of commands and/or instructions that conducting operations suitable for launching a particular object type.
- the actuation logic 340 is responsible for launching the object 147.
- the particular implementation of the actuation logic 340 may vary depending on the object type. For instance, where the object 147 is a document type (e.g., Microsoft® Word® document, PDF document, etc.), the actuation logic 340 may be customized logic which supports launching (in this case, opening) of the object 147 (or concurrent launching of the object 147 by different versions of) the application and/or OS (e.g., Windows® 7 and Office® 2013; Windows® 7, Office® 2010, etc.).
- the object 147 is a document type (e.g., Microsoft® Word® document, PDF document, etc.)
- the actuation logic 340 may be customized logic which supports launching (in this case, opening) of the object 147 (or concurrent launching of the object 147 by different versions of) the application and/or OS (e.g., Windows® 7 and Office® 2013; Windows® 7, Office® 2010, etc.).
- the actuation logic 340 may be a software module (e.g., script, etc.) that copies the object 147 to a file system storage location and subsequently calls an operating system (OS) function, such as
- OS operating system
- the actuation logic 340 Upon launching the object 147, the actuation logic 340 provides a launch notification 345 to the simulation logic 350, namely the active UI simulation logic 360, the passive UI simulation logic 370 and the device control simulation logic 380.
- the launch notification 345 may cause the simulation logic 350 to poll for data 347.
- the data 347 may include (i) an identifier for the object 147; (ii) an identifier as to a type of actuation logic (e.g., particular software module) used to launch the object 147; and/or (iii) the time that the object 147 was launched.
- the data 347 may be provided as part of the launch notification 345.
- the identifier of the object 147 and/or the identifier of the actuation logic 340 may be used to verify that the con-ect selected action profile 300i has been passed to the simulation logic 350 for use at the correct time(s) during processing of the object 147.
- the launch time may be used to synchronize the active UI simulation logic 360, the passive UI simulation logic 370 and the device control simulation logic 380 with each other.
- the launch time also establishes a reference time for use when the passive UI simulation logic 370 is conducting time- based simulated human, and/or the device control simulation logic 380 is conducting time-based simulated device control interaction in accordance with the selected action profile 300i.
- the synchronization is especially relevant for actions conducted by the passive UI simulation logic 370 and the device control simulation logic 380 in accordance with the selected action profile 3001 , as illustrated in FIG. 4 A, and adds intelligence and predictability to the user interaction. Therefore, it is contemplated that most or all of the UI simulation logic 360/370/380 is in communication with the same (or synchronized) timing circuitry (e.g., real time clock, counter, etc.). [0072] As further shown in FIG. 3 A and FIG.
- the active UI simulation logic 360, the passive UI simulation logic 370 and the device control simulation logic 380 are instantiated with or are instantiated to access content within the selected action profile 300i, which controls the simulated human and device control interactions conducted by the UI framework 186 during analysis of the object 147.
- the simulation logic 350 conducts particular actions (e.g., expected user interface interactions and/or methods of activation) during particular operating states at which such actions are expected (e.g., in predetermined sequence (order) and/or at or within a predetermined period of time).
- actions e.g., expected user interface interactions and/or methods of activation
- two or more actions may be conducted concurrently (at least partially overlapping at the same time).
- the active UI simulation logic 360 is a first type of simulated user interaction which is configured to detect input requests (e.g., password request, an attempt to display a dialog or text box for selection of a radio button or text input, etc.) initiated by the object 147 that require "active" human interaction. In response, based on the contents of the selected action profile 300i, the active UI simulation logic 360 determines whether to provide a response and, where appropriate, the type of response that simulates the requested human interaction. For instance, the selected action profile 300i may cause the active UI simulation logic 360 to provide signaling that simulates human interaction responsive to the input request initiated by the launched object 147.
- input requests e.g., password request, an attempt to display a dialog or text box for selection of a radio button or text input, etc.
- the active UI simulation logic 360 determines whether to provide a response and, where appropriate, the type of response that simulates the requested human interaction. For instance, the selected action profile 300i may cause the active UI simulation logic 360 to provide signaling that simulates
- the signaling may simulate the user closing a dialog box that requires dismissal before continuing or simulate the user selecting a particular radio button that closes the dialog box and opens another dialog box for handling.
- Such signaling may be intentionally delayed by a prescribed or random period of time to further simulate human interaction.
- This response and/or responses to subsequent input requests may trigger the object 147 to commence a malicious attack, which could only have been activated by such simulated human interactions.
- the passive UI simulation logic 370 is a second type of simulated user interaction which provides "passive" simulated human interaction.
- the "passive" simulated human interaction is in accordance with the selected action profile, but it is not responsive to an input request by the launched object 147 (e.g., a behavior of the launched object that requiring user action).
- the simulated human interaction is in response to a prescribed level of inactivity by the object.
- the "passive" simulated human interaction may include any simulated operations that, without prompting, may be conducted by the user on the object such as moving to a particular page in a Microsoft® Office Word document (object) or switching to a particular tab in a Microsoft® Office Excel document (object).
- object has an object-type of a Microsoft® Office Excel document
- experiential knowledge of typical placement of exploit/malicious code (e.g., through machine learning techniques) in a Microsoft® Office Excel document may result in instructions in the selected action profile for the passive UI simulation logic 370 to switch to the second sheet of the Microsoft® Office® Excel document at a
- the device control simulation logic 380 is a third type of simulated user interaction that may be performed during virtual analysis of the suspect object 147.
- the device control simulation logic 380 simulates device control interactions that are object- type agnostic.
- the device control simulation logic 380 may receive instructions from the selected action profile 3001 to simulate certain device control interactions, such as simulate particular keystrokes and/or particular mouse movements, in an attempt to detonate a malicious object that is awaiting user interaction before conducting a malicious attack.
- the UI framework log 176 records the activities conducted by the simulation logic 350. As discussed above, the UI framework log 176 may record any suspicious activity and/or malicious activity as well as any actions taken, or refrained from being taken, any requested input and timestamps for all actions and requested input. Upon completion of the dynamic analysis, the information recorded in the UI framework log 176 may be accessible to the score determination logic 168 and/or the classification engine 190.
- the action profile(s) 188 may be updated through a configuration file that may be propagated to the MDS 110i over a network 125 of FIG. 2.
- the action profile update may be provided by the management system 220 over network 125 via machine learning engine 122, which receives information associated with malicious objects as reported by reporting engine 195 based on content within the UI framework log 176.
- the machine learning engine 122 receives information associated with Ul-dependent malicious objects as reported by other MDSes (e.g., MDS 110 2 or MDS 110 3 ).
- the machine learning engine 122 utilizes this information, and information from third party sources, to develop action profile updates.
- the action profile update may include revised rules, new instructions or commands, and/or altered parameters that may provide improved malware detection by targeting new characteristics in an object- type and/or targeting newly identified malware inclusive of exploits, suspicious code and/or malicious code or other data that assists in conducting a malicious attack on a network or network device.
- the action profile update may be provided by over the network 105 (for example through a download using the cloud computing services 228 and/or manual installation through the use of a storage device such as flash storage).
- FIG. 4A a flowchart illustrating an exemplary method conducted by the passive UI simulation logic and the device control simulation logic for detecting malware is shown.
- Each block illustrated in FIG. 4A represents an operation performed in accordance with a selected action profile for providing targeted, simulated user interaction during analysis of the object 147 within a virtual run-time environment.
- These operations are conducted by the MDS 100i in efforts to automatically, without human interaction, detect malicious objects that commence a malicious attack in response to human interaction.
- "active" simulated human interaction responsive to input requests from the object is assigned the highest priority, while “passive" simulated human interactions and simulated device control interactions are assigned lesser priority.
- a first determination is made as to whether the object has been launched by the actuation logic (block 400). If not, the UI framework does not receive a launch notification from the actuation logic, and thus, the simulation logic remains in an idle state. However, once an object is launched, the simulation logic receives a launch notification from the actuation logic, which causes the simulation logic to reference the selected action profile.
- a first determination is made as to whether user interaction is currently being requested based on resultant behaviors of the object during analysis (block 405). Stated differently, a determination is made as to whether the object process has initiated an input request, where timely "active" simulated human interaction is necessary. This determination may be conducted by monitoring system calls and other signaling that is directed to generation of a dialog box, text box, window or other perceivable element that would require user interaction.
- the passive UI simulation logic is currently conducting "passive" simulated human interactions and/or the device control simulation logic is currently conducting simulated device control interactions in accordance with rules outlined in the selected action profile
- these simulated operations are paused for a prescribed duration.
- the prescribed duration may be set by the rules set forth in the selected action profile that identify the amount of time necessary to complete a particular type of "active" simulated human interaction.
- the "paused" simulated operations are time- stamped and placed in a wait queue for subsequent processing after the active UI simulation logic has completed its simulated human interaction.
- the selected action profile triggers the active UI simulation logic to conduct a particular "active" simulated human interaction and store the activity in the UI framework log. Thereafter, the simulation logic determines if the analysis of the object has completed, and if not, cycles back to determine whether the object is actively requesting user interaction (blocks 410- 425).
- a prescribed wait duration e.g., difference between current time and the time- stamp is greater than or equal to the prescribed duration.
- the simulation logic may return to determine if the analysis of the object has completed, and if not, cycles back to determine whether the object is actively requesting certain user interaction (blocks 450, 420 and 405).
- the prescribed level of UI simulated activity may be measured by a variety of ways. For instance, the prescribed level of UI simulated activity may be determined based on whether simulated human interactions have occurred for a certain percentage of the run-time since the object was launched. Alternatively, the process may determine the number of "active" simulated human interactions or the number of active/passive simulated human interactions that have been completed since the object was launched.
- the device control simulation logic accesses the selected action profile to determine what simulated device control interactions are requested by the selection action profile, and thereafter, the selected action profile triggers the device control simulation logic to simulate such device controls and store such activity in the UI framework log.
- the simulation logic returns to determine if the analysis of the object has completed, and if not, cycles back to determine whether the object is actively requesting user interaction (blocks 450, 420 and 405).
- the UI control logic is adapted to prioritize "active" simulated human interaction above "passive" simulated human interaction and the simulated device control interaction.
- simulated human interaction and simulated device control interactions may be temporarily halted to direct resources to respond to an activity initiated by the object.
- some types of "passive" simulated human interactions and simulated device control interactions may continue despite detection of an input request by the object. This may be done to maintain perceived consistency in simulated operations to avoid sophisticated malware to detect abnormally prompt changes in operation.
- FIG. 4B a flowchart illustrating an exemplary method conducted by the active UI simulation logic for detecting malware is shown.
- a first determination is made as to whether the object has been launched by the actuation logic (block 470). If not, the active UI simulation logic remains in an idle state. However, once an object is launched, the active UI simulation logic receives a notification from the actuation logic, where the simulation logic determines whether the suspect object is currently requesting some sort of active user interaction such as a dialog box is opened that required dismissal before the object continues its operation for example (block 475).
- the active UI simulation logic notifies the passive UI simulation and the device control simulation logic of an imminent active user interaction (block 480). This notification prompts the passive UI simulation and the device control simulation logic to pause any current operations as described in FIG. 4A. Thereafter, the active UI simulation logic performs a human simulation operation in accordance with rules set forth in the selected action profile and such activity is stored in the UI framework logic (block 485).
- the active UI simulation logic determines whether the analysis of the suspect object has completed. If not, the active UI simulation logic initiates another iterative cycle awaiting a requested user interaction (block 490).
- the MDS 110i comprises one or more processors 500 (hereinafter "processor(s)”), which is coupled to a first communication interface logic 510 via a first transmission medium 520.
- the first communication interface logic 510 may provide a communicative coupling with the network interface 136 of FIG. 1.
- the processor(s) 500 may be communicatively coupled to a second communication interface logic 530 via a second transmission medium 540, which may provide communications with other MDSes 110 2 -1 I O3 and management system 120 of FIG. 1.
- the first communication interface logic 510 and/or the second communication interface logic 530 may be implemented as a physical interface including one or more ports for wired connectors. Additionally, or in the alternative, the first communication interface logic 510 and/or the second communication interface logic 530 may be implemented with one or more radio units for supporting wireless communications with other network devices.
- the processor(s) 500 are further coupled to the persistent storage 550 via the transmission medium 560.
- the persistent storage 550 may be configured to store software components associated with the static analysis engine 145, the dynamic analysis engine 160, the classification engine 190 and the reporting engine 195.
- software components associated with the static analysis engine 145 may include the static analysis logic 152, the metadata extraction logic 154 and/or the object-type determination logic 156.
- the persistent storage 550 may be further configured to store software components associated with the dynamic analysis engine 160, which includes the VMM 172 along with the VMs 170i- 170M. All or some of the VMs 170I-170M may be provisioned with the UI control logic 182, which may include the profile selector 184, UI framework 186 and/or action profile(s) 188.
- the persistent storage 550 may include the magic number database 158 that is accessed by the object-type determination logic 156 (described above) and data stores 159 and 164 that may operate, at least part, as data buffers.
Abstract
According to one embodiment, a malware detection system is integrated with at least a static analysis engine and a dynamic analysis engine. The static analysis engine is configured to automatically determine an object type of a received object. The dynamic analysis engine is configured to automatically launch the object after selecting an action profile based on the object type. The dynamic analysis engine is further configured to, provide simulated user interaction to the object based on the selected action profile either in response to detecting a request for human interaction or as a result of a lapse of time since a previous simulated human interaction was provided.
Description
INTELLIGENT CONTEXT AWARE USER INTERACTION FOR MALWARE
DETECTION
FIELD
[001] Embodiments of the disclosure relate to the field of cyber security. More specifically, one embodiment of the disclosure relates to a system, apparatus and method for detecting malware.
GENERAL BACKROUND
[002] Over the last decade, malicious software (malware) has become a pervasive problem for Internet users. Often malware exploits vulnerabilities in networked resources. For instance, over the past few years, more and more vulnerabilities are being discovered in software that is loaded onto network devices, such as vulnerabilities within operating systems for example. While some vulnerabilities continue to be addressed through software patches, prior to the release of such software patches, network devices will continue to be targeted for attack by exploits that use malicious computer code. The malware may attempt to acquire sensitive information or adversely influence or attack normal operations of a network device or the entire enterprise network.
[003] Currently, in malware detection systems, one or more virtual machines may be used to process objects, which may include, for example, content from network traffic and/or files retrieved from a storage location, in order to activate, observe, and thereby detect malicious software. However, this processing may require user interaction, for example, in the form of an input initiated by an input device such as a graphical user interface (GUI), mouse, keyboard, keypad or the like. Based on an inability to provide the necessary user input, current malware detection systems may fail to activate the malicious content within the objects. One reason is that sophisticated malware often has a self-defense mechanism, which attempts to detect whether it is running in a virtual environment of a malware detection system rather than the intended environment of a client device under user control. One type of self-defense mechanism involves the
malware monitoring whether user input expected by an application is supplied at the appropriate time. If it is not, the malware may simply hibernate (not activate), and thus not present itself for detection by the malware detection system.
[004] Some conventional malware detection systems apply generic, static patterns of simulated input device controls in a viitual run-time environment in the absence of actual human interaction. However, malware creators have been able to identify these patterns. As a result, they have been able to equip their malware to identify such static simulated device controls, and upon detection, cause the malware to refrain from activating the malicious code in order to remain undetected. As a consequence, some conventional malware detection systems may experience unacceptable levels of false negatives or be forced to deploy a multitude of pattern detection schemes that will increase the rate of false positives.
BRIEF DESCRIPTION OF THE DRAWINGS
[005] Embodiments of the disclosure are illustrated by way of example and not by way of limitation in the figures of the accompanying drawings, in which like references indicate similar elements and in which:
[006] FIG. 1 is an exemplary block diagram of a first embodiment of a malware detection system (MDS) which features user interaction (UI) control logic deployed as part of a virtual run-time environment to provide simulated user interaction to detonate a malicious object.
[007] FIG. 2 is an exemplary block diagram of a second embodiment of the MDS which features a second architecture scheme of the UI control logic deployed as part of the virtual run-time environment.
[008] FIG. 3A is an exemplary block diagram of a first operational flow for the UI control logic operating within the virtual ran-time environment.
[009] FIG. 3B is an exemplary block diagram of a second operational flow for the UI control logic operating within the virtual run-time environment.
[0010] FIG. 4A is a flowchart illustrating an exemplary process conducted by passive UI simulation logic and device control simulation logic that are operating in accordance with a selected action profile and are conducting simulated user interactions to increase the likelihood in accurately detecting a malicious object.
[0011] FIG. 4B is a flowchart illustrating an exemplary process conducted by the active UI simulation logic that is operating in accordance with the selected action profile and is conducting simulated user interactions to increase the likelihood in accurately detecting a malicious object.
[0012] FIG. 5 is an exemplary block diagram of the logical architecture associated with the MDS of FIG. 1.
DETAILED DESCRIPTION
[0013] Various embodiments of the disclosure are directed to a system and method for determining whether or not an object is associated with a malicious attack through, at least, a dynamic analysis of the object within a virtual run-time environment. Herein, the virtual run-time environment features one or more virtual machine instances (VMs), which are provisioned with a guest image associated with a prescribed software profile. The guest image may include a software application in addition to an operating system (OS) along with monitors, namely software components that are configured to observe and capture run-time behavior of an object under analysis during processing within the virtual machine. With this VM configuration, in order to effectively detect a malicious object, the object needs to be "launched" and subsequently "detonated" within the virtual run-time. Herein, the term "launch" (and other tenses) represents performance of one or more events that starts activation of an object under analysis while the phrase "detonate" (and other tenses) represents performance of one or more events that trigger a malicious attack by the activated object. Additionally, the contents of related application, U.S. Patent Application No. 13/801,532 filed on March 13, 2013 is incoiporated by reference herein.
[0014] In some cases, however, objects are detonated only in response to some sort of user interaction (e.g., one or more user inputs responsive to an event actuated by the object or user-initiated inputs during normal use of the object, etc.). According to one embodiment of the disclosure, user interaction (UI) control logic may be deployed as part of the virtual run-time environment in order to provide simulated user interaction needed to detonate certain types of malicious objects within a VM. Embodiments of the invention provide simulated user interaction tailored to the type of object (and, in some embodiments, other features related to the object) being processed in the virtual run-time environment. The UI control logic comprises a plurality of components, including (1) a profile selector and (2) a UI framework, as described herein.
[0015] Herein, the UI control logic may feature multiple implementations. For instance, the UI control logic may be provisioned as components of a VM. As an alternative
embodiment, the UI framework may be provisioned as a component of the VM, but the profile selector may be deployed as part of a virtual machine monitor (VMM), which may be deployed, according to one embodiment of the disclosure, as part of a "hosted hypervisor" (e.g., software that runs on top of a host operating system) or as an intermediary operation layer between the hardware and the VMs. When deployed as part of the VMM, the profile selector may be adapted to provision the UI framework component within the VM and perhaps multiple UI framework components within multiple VMs.
[0016] According to one embodiment of the disclosure, the profile selector selects an action profile from a plurality of action profiles that may be hosted in the VM or outside the VM within the virtual run-time environment. This selection may be based, at least in part, on metadata associated with an object under analysis. Herein, the metadata defines, at least in part, the context for determining the action profile that governs the simulated user interaction. The metadata further determines the software appropriate to launch the object in the run-time environment. Of course, the selection of the action profile also may be based on a type of network device deploying (hosting) the VM (e.g., security appliance that analyzes network traffic, files within a file storage system, etc.) or other information from the static analysis of the object. According to this action profile selection scheme, the dynamic analysis of the object is "context aware".
[0017] Herein, the metadata may include data that identifies the type of object under analysis. Of course, it is contemplated that, besides object type, other metadata may be used by the profile selector for selecting the particular action profile. Examples of other metadata that may be used by the profile selector to select a particular action profile for controlling the simulation of user interactions with the object launched in the VM may include, but are not limited or restricted to information related to the following: (i) whether the object is enciypted and/or its type of encryption scheme, (ii) whether the object is an embedded object, (iii) the type of application needed for processing the object, and/or (iv) transmission protocol used in delivery of network content including the object.
[0018] Each "action profile" is a collection of instructions and/or commands that performs UI functionality in accordance with a set of rules prescribed for that action profile. As a result, each action profile is configured for use in dynamically controlling UI actions associated with a certain type of object in contrast to the use of patterns perse. For instance, the action profile associated with a Microsoft® Excel® spreadsheet may conduct different UI actions (e.g., select tabs, add text to certain cells, scroll down a certain number of cell rows, etc.) than a PDF document (e.g., scroll pages of the document, etc.) and such actions may be conducted at different times depending on the behavior of the object under analysis.
[0019] As described herein, the UI framework comprises (i) the actuation logic, (ii) active UI simulation logic; (iii) passive UI simulation logic; and (iv) device control simulation logic. According to one embodiment of the disclosure, the actuation logic is a software component that is implemented as part of a software profile that provisions the VM and is responsible for launching the object under analysis. The particular implementation of the actuation logic may vary depending on the object type. Upon the actuation logic launching the object, the active UI simulation logic, the passive UI simulation logic and the device control simulation logic are instantiated with or are instantiated to access content within the selected action profile. Operating in accordance with the selected action profile, the simulation logic within the UI framework conducts particular actions (e.g., expected user interface interactions and/or methods of activation) during particular operating states at which such actions are expected if the object was running on a targeted endpoint. These particular actions may be conducted in accordance with a predetermined sequence (order) and/or at (or within) predeteimined periods of time. Furthermore, two or more of these particular actions may be conducted concurrently (at least partially overlapping at the same time) or such actions may be performed sequentially.
[0020] Operating as part of the UI framework, the active UI simulation logic detects input requests (e.g., password request, opening of a dialog box that requires dismissal prior to continuing, opening of a text box that requires text entry, etc.), which require
human interaction that directly responds to the input request. This type of simulated human interaction is referred to herein as "active" simulated human interaction. In response, the active UI simulation logic operates in accordance with the selected action profile to determine whether to provide a response and the type of response, where appropriate.
[0021] The passive UI simulation logic operates in accordance with the selected action profile and, in certain cases, provides simulated human interaction in response to a prescribed level of inactivity by the object and/or a prescribed period of time after the suspect object has launched has elapsed. The passive UI simulation logic is in communication with timing circuitry (e.g., real time clock, counter, etc.), where the monitored time plays a factor in determining when to conduct prescribed simulated human interactions that are triggered by a period of inactivity by the object and/or an elapsed time from when the suspect object was launched.
[0022] Responsive to detecting a prescribed period of inactivity for example, the passive UI simulation logic simulates user-initiated interactions on the object such as moving to a particular page in a Microsoft® Office Word document (object), switching to a particular tab in a Microsoft® Office Excel document (object), or switching to a different PowerPoint™ slide in accordance with the object-specific action profile. As an example, assuming the object is a Microsoft® Office Excel document, experiential knowledge of typical placement of exploit/malicious code (e.g., through machine learning techniques) in a Microsoft® Office Excel document may result in instructions by the selected action profile for the passive UI simulation logic to simulate human interaction by switching to the second sheet of the Microsoft® Office Excel document at a predetermined time after the actuation logic launches the object.
[0023] The device control simulation logic operates in accordance with the selected action profile and provides simulated device controls that are agnostic to object type, which may occur in response to yet another level of prescribed inactivity. For example, the device control simulation logic may receive instructions from the selected action profile to simulate certain device control interactions, such as simulate particular
keystrokes and/or particular mouse movements, in an attempt to trigger a malicious attack by the object.
[0024] Embodiments of the disclosure may be employed by or take the form of a network device, including a cyber-security appliance that features a malware detection system (MDS). The MDS includes a static analysis engine and a dynamic analysis engine, or, in another embodiment, only a dynamic analysis engine. In some
embodiments, the MDS may be implemented as a server or client device or other system (any of which may be referred to as an "endpoint") connectable to a network. The dynamic analysis engine may include a virtual run-time environment that automatically analyzes, without user assistance, objects from the received network traffic and simulates human interaction to detonate and detect malicious objects during virtual processing. The results of the analysis may be reported to network administrators or other personnel for further analysis and action.
I. TERMINOLOGY
[0025] In the following description, certain terminology is used to describe features of the invention. For example, in certain situations, the terms "logic", "component", and "engine" are representative of hardware, firmware and/or software that is configured to perform one or more functions. As hardware, logic (or component or engine) may include circuitry having data processing or storage functionality. Examples of such circuitry may include, but are not limited or restricted to a microprocessor, one or more processors and/or processor cores, a programmable gate array, a microcontroller, an application specific integrated circuit, semiconductor memory, or combinatorial logic.
[0026] Logic (or component or engine) may be software in the form of one or more software modules, such as executable code in the form of an executable application, an application programming interface (API), a subroutine, a function, a procedure, an applet, a servlet, a routine, source code, object code, a shared library/dynamic load library, or one or more instructions. These software modules may be stored in any type of a suitable non-transitory storage medium, or transitory storage medium (e.g.,
electrical, optical, acoustical or other form of propagated signals such as carrier waves, infrared signals, or digital signals). Examples of non-transitory storage medium may include, but are not limited or restricted to a programmable circuit; a semiconductor memory; non-persistent storage such as volatile memory (e.g., any type of random access memory "RAM"); persistent storage such as non-volatile memory (e.g., read-only memory "ROM", power-backed RAM, flash memory, phase-change memory, etc.), a solid-state drive, hard disk drive, an optical disc drive, or a portable memory device. As firmware, the executable code may be stored in persistent storage.
[0027] The term "object" generally refers to a collection of data, whether in transit (e.g., over a network) or at rest (e.g., stored), often having a logical structure or organization that enables it to be classified for purposes of analysis. During analysis, for example, the object may exhibit a set of expected characteristics and, during processing, a set of expected behaviors. The object may also exhibit a set of unexpected characteristics and a set of unexpected behaviors that may evidence the presence of malware and potentially allow the object to be classified as part of a malicious attack.
[0028] Examples of objects may include one or more flows or a self-contained element within a flow itself. A "flow" generally refers to related packets that are received, transmitted, or exchanged within a communication session. For convenience, a packet is broadly referred to as a series of bits or bytes having a prescribed format, which may, according to one embodiment, include packets, frames, or cells. Further, an "object" may also refer to collective payloads of a number of related packets, e.g., a single webpage received over a network. Moreover, an object may be a file or document retrieved from a storage location over a transmission medium.
[0029] As a self-contained element, the object may be an executable (e.g., an
application, program, segment of code, dynamically link library "DLL", etc.) or a nonexecutable. Examples of non-executables may include a document (e.g., a Portable Document Format "PDF" document, Microsoft® Office® document, Microsoft®
Excel® spreadsheet, etc.), an electronic mail (email), downloaded web page, or the like.
[0030] The term "transmission medium" may be construed as a physical or logical communication path between two or more network devices (e.g., any devices with data processing and network connectivity such as, for example, a security appliance, a server, a mainframe, a computer such as a desktop or laptop, netbook, tablet, firewall, smart phone, router, switch, bridge, etc.) or between components within a network device. For instance, as a physical communication path, wired and/or wireless interconnects in the form of electrical wiring, optical fiber, cable, bus trace, or a wireless channel using infrared, radio frequency (RF), may be used.
[0031] The term "network device" should be construed as any electronic device with the capability of connecting to a network. Such a network may be a public network such as the Internet or a private network such as a wireless data telecommunication network, wide area network, a type of local area network (LAN), or a combination of networks. Examples of a network device may include, but are not limited or restricted to, a laptop, a mobile phone, a tablet, a computer, a security appliance, or the like.
[0032] The term "computerized" generally represents that any corresponding operations are conducted by hardware in combination with software and/or firmware. Also, the terms "compare" or "comparison" generally mean determining if a match (e.g., a certain level of correlation) is achieved between two items where one of the items may include a particular signature pattern.
[0033] The term "action profile" should be interpreted as a plurality of instructions and/or commands that provision logic to conduct, in accordance with a set of rules prescribed for that particular action profile, different types of simulated user interactions. The simulated user interactions may include "active" simulated human interactions; "passive" simulated human interactions and simulated device control interactions.
[0034] An active simulated human interaction includes simulated actions that may be performed by a user in response to an event initiated by a suspect object under analysis. In some situations, the simulated action may be required before any further activities are conducted by the object. Examples of an active simulated human interaction include
closing a window or dialog box; selecting a particular radio button; and/or entering characters into a text box).
[0035] A passive simulated human interaction includes simulated actions that are normally performed by a user during activation of the object, but such actions are not responsive to a particular behavior by the object. Examples of passive simulated human interaction include scrolling pages of a document (e.g., PDF or Word® document), browser, or other type of displayed image; selecting certain tabs of an Excel®
spreadsheet; and/or accessing certain menu options.
[0036] A simulated device control interaction includes simulated input from an input device for an endpoint. Examples of a simulated device control interaction include keystrokes, mouse movement or clicks, and/or detected activation of certain area or areas of a touch screen.
[0037] Lastly, the terms "or" and "and/or" as used herein are to be interpreted as inclusive or meaning any one or any combination. Therefore, "A, B or C" or "A, B and/or C" mean "any of the following: A; B; C; A and B; A and C; B and C; A, B and C." An exception to this definition will occur only when a combination of elements, functions, steps or acts are in some way inherently mutually exclusive.
[0038] The invention may be utilized for detection, verification and/or prioritization of malware, which may include malicious content, in particular, through providing object- type specific simulated human interaction to an object activated in a virtual run-time environment. As this invention is susceptible to embodiments of many different forms, it is intended that the present disclosure is to be considered as an example of the principles of the invention and not intended to limit the invention to the specific embodiments shown and described.
II. GENERAL ARCHITECTURE OF THE MALWARE DETECTION SYSTEM
[0039] Referring to FIG. 1, an exemplary block diagram of a network 100 deploying a plurality of malware detection systems (MDS) 1 lOi-l 10N (N>1, where N=3 for this
embodiment) communicatively coupled to a management system 120 via a network 125 is shown. In general, the management system 120 is adapted to manage each MDS 110i- 1 Kb. For instance, the management system 120 may be configured to perform content updates (e.g., upload new rules or modified rules, delete rules, modify parameters that are utilized by the rules and/or upload metadata) within logic operating as part of a communication interface 140, a static analysis engine 145, a dynamic analysis engine 160, a classification engine 190, and/or a reporting engine 195 with an optional user interface capability (e.g., for purposes of initial system set up and configuration). In particular, the management system 120 is configured to propagate updates to one or more action profiles (hereinafter "action profile(s)") via action profile update logic 174. The action profile(s) 188 are used to control the simulation of human interactions with and/or device controls for the object during analysis, as described below.
[0040] As shown in FIG. 1, a first malware detection system (MDS) 11 Oi is an electronic device that is adapted to analyze information associated with incoming data (e.g., network traffic, input data over a communication network 105, input data from another type of transmission medium, etc.) from/to one or more endpoints 132. As this illustrative embodiment, the communication network 105 may include a private network such as a wireless data telecommunication network, wide area network, a type of local area network (LAN), or a combination of networks. Other embodiments may include incoming data (files from a file store) being retrieved from a file storage location (e.g., a hard disk drive (HDD) or a flash drive storage) for malware detection. Herein, the first MDS 1 lOi is communicatively coupled with the communication network 105 via an interface 136 and/or an operational firewall 134.
[0041] In general, the interface 136 may operate as a data capturing device that is configured to receive at least a portion of network traffic propagating to/from one or more endpoints 132 and provide information associated with the received portion of the network traffic to the first MDS 110L This information may include an object, namely multiple packets collectively forming an executable or a non-executable (e.g., a document embedded within an email message or a web page). Alternatively, although
not shown, the interface 136 may be configured to receive files or other objects that are not provided over a network. For instance, as an example, the interface 136 may be a data capturing device that automatically (or on command) accesses data stored in a storage system or another type of interface, such as a port, for receiving objects manually provided via a suitable dedicated communication link or from storage media such as portable flash drives.
[0042] In general terms, the interface 136 may be configured to capture data typically directed to the endpoint 132, where the captured data includes at least one object 147 for analysis and its corresponding metadata 148. The metadata 148 may be used, at least in part, to determine protocols, application types and other information that may be subsequently used by logic, such as a scheduler 150 for example, to configure one or more VMs 170I-170M (M>1) with selected software profiles. For instance, the metadata 148 may be used to determine which software images (e.g., application(s)), if any, in addition to operating systems to be fetched a storage device 151 for configuring operability of the VMs 170i-170Min order to process the subject object 147 at a desired time, for a desired period of time, and/or in a desired order. Additionally, as one feature of the invention, the metadata 148 associated with the suspect object 147 may be used by the profile selector 184, implemented in the VM(s) itself (e.g. VM 170i) or in the virtual machine monitor (VMM) 172 as described below, to select which action profile(s) 188 for controlling simulated user interaction with the suspect object 147 in efforts to detonate the suspect object 147 within one or more of the VM 170I-170M.
[0043] In some embodiments, although not shown, interface 136 may be contained within the first MDS 110i. In other embodiments, the interface 136 can be integrated into an intermediary device in the communication path (e.g., a firewall, router, switch or other networked electronic device) or can be a standalone component, such as an appropriate commercially available network tap as shown.
[0044] As further shown in FIG. 1, the first MDS 110i comprises the communication interface 140, the static analysis engine 145, the dynamic analysis engine 160, the classification engine 190 and the reporting engine 195. Herein, the communication
interface 140 receives an object from the interface 136 and converts that object into a format, as needed or appropriate, on which analysis by the static analysis engine 145 may be conducted. This conversion may involve decompression of the object, decompilation of the object, extraction of specific data associated with the object, and/or emulation of the extracted data (like Javascript™). The communication interface 140, in some embodiments, may be integrated into the interface 136.
[0045] Referring still to FIG. 1, the static analysis engine 145 may include one or more controllers (e.g., processing circuitry such as one or more processors) that feature static analysis logic 152, metadata extraction logic 154, and object-type determination logic 156 for accessing magic number database 158 and/or data store 159. The data store 159 may be used to store the analyzed object 147 and/or extracted metadata 148 prior to transmission to the data analysis engine 160 upon determining that the object 147 is "suspicious" and requires further analysis to determine whether that object 147 is associated with a malicious attack.
[0046] Refemng still to FIG. 1, the static analysis logic 152 includes one or more software modules that, when executed by the controller(s), analyzes characteristics associated with the suspect object 147, which may be a portion of network traffic (or downloaded data) according to this embodiment of the disclosure. Such static analysis may include one or more checks being conducted on the object without its execution. Examples of the checks may include (i) heuristics, which is based on rules or policies as applied to the object 147 and may determine whether one or more portions of the object 147 is associated with anomalous or suspicious characteristics (e.g., a particular URL associated with known exploits, or a particular source or destination address etc.) associated with known exploits; or (ii) determinative rule-based analysis that may include blacklist or whitelist checking.
[0047] The metadata extraction logic 154 is responsible for extracting and/or generating metadata 148 contained as part of and/or associated with the suspect object 147. The extraction and/or generation of the metadata 148 may occur after the object 147 is determined by the static analysis logic 152 to feature anomalous or suspicious
characteristics. Of course, alternatively, the metadata extraction logic 154 may extract and/or generate the metadata 148 prior to or concurrently with the operations conducted by static analysis logic 152.
[0048] The metadata 148 may be identified as being associated with the suspect object 147, and is stored accordingly. Examples of metadata 148 may include, but are not restricted or limited to, information that identifies the type of object 147. For example, a particular document (e.g., Microsoft® Excel spreadsheet) is an example of an object type, which may be in the form of a non-executable. This metadata 148 may be subsequently used by the profile selector 184 to select at least one particular action profile for controlling simulated user interaction conducted during analysis of the object 147 within one or more VMs 170i-l 70M of the virtual run- time environment 164, as described below.
[0049] In addition to, or in lieu of the metadata associated with the source of the object 147, it is contemplated that other metadata may be captured by metadata extraction logic 154. For instance, other metadata which may be used by the profile selector 184 for selecting the particular action profile. This metadata may include, but is not limited or restricted to the following: (i) data identifying whether the object is encrypted and/or its type of encryption scheme, (ii) data identifying whether the object is an embedded object, (iii) data identifying the type of application needed for processing the object, and/or (iv) data identifying the transmission protocol used in delivery of network content including the object. These and potentially other features related to the object are stored for later use.
[0050] From the extracted metadata, the object-type determination logic 156 may determine object type. For instance, the object-type determination logic 156 may analyze content within the object 147, which may identify the object type. For instance, as an illustrative example, the object-type determination logic 156 may identify a predetermined number of bytes at the beginning of the object 147 (sometimes referred to as the "magic numbers" for the object) and compare the values associated with these bytes with stored values within the magic number database 158. Upon a successful
comparison, the object-type determination logic 156 has identified the object type.
[0051] For instance, as an illustrative embodiment, the first few bytes of the object 147 may, in certain cases, be used to determine the object-type or at least infer the object type based on the communication protocol in use. As an example, the object-type
determination logic 156 may determine that the object 147 starts with the hexadecimal string value "4D5 A" which, upon comparison with entries within the magic number database 158, identifies that the object 147 is an executable. Similar, the object-type determination logic 156 may determine that the object 147 starts with a hexadecimal string value of "25 50 44 46" and, upon comparing this value with stored data within the magic number database 158, determines that the object 147 is a PDF document.
[0052] As discussed above, the static analysis engine 145 may route the suspect object 147 along with the metadata 148 (inclusive of any object type information generated by the object-type determination logic 156) to the virtual run-time environment 164 within the dynamic analysis engine 160. The results of the static analysis may be used to establish an order of processing of objects in the virtual run-time environment 164 based on the level of "suspiciousness" of the objects (e.g., as established by a relative suspiciousness score). The static analysis engine 145 may also filter benign objects from further analysis. In one embodiment, if the object 147 does not appear suspicious and/or malicious based on a static analysis, the static analysis engine 145 may simply denote that the object 147 is non-malicious and may refrain from subjecting the object 147 to further analysis. However, upon determining that the object 147 includes characteristics that are suspicious, extracting the metadata 148 associated with the suspect object 147 and determining the object type, the static analysis engine 145 may pass this suspect object 147 along with the metadata 148 to the dynamic analysis engine 160 for more in- depth analysis in a VM-based operating environment. All or portions of the static analysis engine 145 may be integrated into the interface 136 or into other devices, such as a firewall or another network device, such as a network device located at the periphery of a network to be protected so as to capture and examine objects contained in ingress content.
[0053] The dynamic analysis engine 160 may include processing logic 162, a virtual runtime environment 164, a data store 166, and/or a score determination logic 168.
According to one embodiment, processing logic 162 may be configured to control interoperability between components within the dynamic analysis engine 160. For instance, the processing logic 162 may control the buffering of the passed objects and their corresponding metadata into the data store 166 and the loading of the objects and corresponding metadata into the VM(s) 170I-170M directly or into the VMM 172 for supply to the VMs 170i-170M.
[0054] The virtual run-time environment 164 provides for virtual processing of the object 147 through one or more VMs 170I-170M managed by a virtual machine monitor (VMM) 172. The VMM 172 manages reconfiguration of the one or more VMs 170i- 170M before conducting the virtual analysis based on externally provided configuration updates, namely software profiles (e.g., OS and/or application instances), action profiles, or the like. As shown, the VMM 172 features action profile update logic 174, which is responsible for updating rales, parameters, instructions, and/or other data maintained by the action profile(s) 188 hosted in VM 170i, as shown. Of course, the action profile update logic 174 may update action profile(s) 188 hosted in other VMs (e.g., VM 170M) or hosted outside the VM (e.g., within storage device 151, within data store 166, or within storage within the virtual run-time environment (not shown)). For clarity sake, the operations of VM 170i are described, although all or some of the other VMs 170M or VMs 1702-170M may operate in a similar manner.
[0055] As shown, the VM 170i may be provisioned with an operation system (OS) and, dependent on the object type, one or more applications 180, along with the monitoring logic 181 and user interaction (UI) control logic 182. The monitoring logic 181 monitors run-time behaviors of the object 147 when launched in the VM 170i . The UI control logic 182 provides simulated user interactions to detonate a malicious object that is loaded into the VM 170i and requires some sort of user interaction to initiate a malicious attack. According to one embodiment of the disclosure, the UI control logic 182 comprises a plurality of components, which include (1) a profile selector 184 and (2) UI
framework 186.
[0056] According to one embodiment of the disclosure, the profile selector 184 selects an action profile from the action profile(s) 188 that are shown as being hosted in the VM 170i. This selection may be based, at least in part, on the metadata 148 associated with the suspect object 147. For example, the metadata 148 may include data produced by the object-type deteraiination logic 156 that identifies an object type for the object 147. As described above, the metadata 148 may include other data that is uncovered during parsing of the object 147 by the static analysis engine 145 (e.g., password protected fields, password in an email message that included the object 147, etc.), which may be relied upon for selecting a particular action profile within the action profile(s) 188.
[0057] As further shown in FIG. 3 A and FIG. 3B, the UI framework 186 comprises (1) the actuation logic 340 and (2) different types of user interaction (UI) simulation logic 350, where the different UI simulation logic implemented within the UI framework 186 as described below. Herein, the actuation logic 340 is a software component which is implemented as part of the software profile that provisions the VM 170i and is responsible for "launching" the suspect object 147. The object may be "launched" by starting a process that starts the object 147 (when the object 147 is an executable or script) or starting a process that manipulates the object 147 (e.g., opens the object 147 using Adobe® Acrobat® Reader application when the object 147 is a PDF document; opens the object 147 using Microsoft® Office® application when the object 147 is an Excel® (.xls) file, etc.).
[0058] When launching the object 147, the actuation logic 340 notifies the UI simulation logic 350 of the launched object. In response, logic within the simulation logic 350 is instantiated with or is instantiated to access the selected action profile, which controls the simulated user interaction conducted by the UI framework 186 during analysis of the object 147. The simulated user interaction may include signaling that simulates a particular action during a particular operating state of the object 147 at which such an action is expected if running on a targeted endpoint (client device). These particular
actions may be order dependent (sequenced) and/or time dependent (e.g., occur at a particular time, occur at a particular time after a previous action, etc.).
[0059] Referring back to FIG. 1, the monitoring logic 181 and UI framework log 176 collectively operate to record, while the object 147 is launched in the VM 170! , the requests for input by the object 147. The monitoring logic 181 and the UI framework log 176 also monitor and log any "active" simulated human interactions provided to the suspect object 147 in response to the input request, any responses to the simulated human interactions by the suspect object 147, "passive" simulated human interactions that are not responsive to behaviors by the suspect object 147, and/or simulated device control interactions. The data recorded by the UI framework log 176 may be referenced by the score determination logic 168, which determines a probability (score) that is used, at least in part by the classification engine 190, to determine (i) whether the suspect object 147 is associated with a malicious attack and (ii) severity of the malicious attack. The contents of the UI framework log 176 may also provide an ability to correlate, for reporting purposes, malicious objects that are detonated in response to certain type(s) of user interaction.
[0060] For instance, when a submitted object 147 is classified as malicious, the UI framework log 176 can provide information for understanding which simulation logic caused or helped a successful detonation. In other words, from data within the UI framework logic 176, a determination can be made as to the efficacy of action profiles and the UI framework. Such feedback can be used to "fine-tune" action profiles.
Additionally, by use of data within the UI framework logic, malwares can be classified based on user interaction(s) necessary for detonation. This classification and details of user interaction(s) can augment the Threat Intelligence aspects such as forensic analysis of malwares and incidence response. Similarly, when the object 147 is classified as suspicious, the UI framework logic 176 provides information for understanding the shortcomings in the set of user interactions the UI framework 186 provides (e.g., a new feature might be required in UI framework 186 or new rales or parameters may be needed for the selected action profile). On the other hand, if a user interaction performed
by the UI framework obstructs object detonation, it can be rectified in subsequent action profile update.
[0061] As shown in FIG. 1, the reporting engine 195 is adapted to receive information from the classification engine 190 via transmission medium 189 and generate alerts (e.g., various types of messages including text messages and email messages, display images, or other types of information over a wired or wireless transmission medium) that identify to a network administrator that the suspect object 147 is associated with a malicious attack and is user-interaction dependent.
[0062] Although FIG. 1 illustrates the MDS 110i as a dedicated network device and the discussion of FIG. 1 explains examples based on an object received over the network interface 136, the MDS 110i may be implemented on an endpoint, such as the client device 132. In such an embodiment, prior to actual execution of the object, the MDS 1 10i may launch the object in a sandboxed environment and conduct simulated user interactions, which may include simulated human interactions and simulated device controls. Responsive to non-anomalous behaviors by the object 147, the endpoint 132 is allowed to utilize the object. In addition, the MDS 110i may be implemented in the cloud computing services 138, where the above described simulated human and device control interactions may be fully or partially conducted therein.
[0063] Referring now to FIG. 2, a block diagram of a second embodiment of the MDS 110i employed within a network 200 is shown. According to this embodiment of the disclosure, the dynamic analysis engine 160 includes processing logic 162, virtual run-time environment 164, data store 166 and/or score determination logic 168.
However, the VM(s) 170I-170M are not provisioned with action profile(s) 188 as shown in FIG. 1. Rather, action profile(s) 188 are hosted outside the VM(s) 170i-170M.
Furthermore, the profile selector 184 is deployed as part of the VMM 172. For this implementation, the profile selector 184 may be adapted to provision the UI framework component 186 within the VM 170i and perhaps UI framework components within other VMs (e.g., VM 170M).
III. OPERATION FLOW OF THE UI CONTROL LOGIC
[0064] Referring to FIGs. 3A and 3B, exemplary block diagrams of operational flows for the UI control logic 182 within the virtual run-time environment 164 is shown. In particular, one embodiment of the UI control logic 182 operating within the VM 170i is illustrated. Herein, the UI control logic 182 comprises (1) the profile selector 184 and (2) the UI framework 186. As shown, the UI framework 186 comprises (a) actuation logic 340 and (b) simulation logic 350, which includes (i) active UI simulation logic 360;
(ii) passive UI simulation logic 370; and (iii) device control simulation logic 380.
[0065] According to one embodiment of the disclosure, the object 147 and metadata 148 are provided to the VM 170i. Based on the metadata 148, the profile selector 184 selects an action profile (herein the "selected action profile" 300i) within the action profile(s) 188, namely a plurality of action profiles 300I-300R (R>2) that may be hosted in the VM 170i (as shown) or outside the VM 170i within the virtual run-time environment. This selection may be based, at least in part, on metadata identifying the object type. Of course, it is contemplated that, besides object type, other metadata may be used by the profile selector 184 to better identify the object 147 in order to choose the selected action profile 300i best suited for the particular object under analysis. Examples of other metadata that may be used include, but are not limited or restricted to the following: (i) data identifying whether the object 147 is encrypted and/or its type of encryption scheme, (ii) data identifying whether the object 147 is or contains an embedded object,
(iii) data identifying whether the object 147 includes password-protected fields and information associated with the password; (iv) data identifying the type of application needed for processing the object 147, and/or (v) data identifying the transmission protocol used in delivery of network content including the object 147.
[0066] Herein, according to one embodiment of the disclosure, each "action profile" is a collection of instructions and/or commands that performs UI functionality in accordance with a set of rules prescribed for that action profile. As a result, the selected action profile 300i is configured for use in controlling UI functionality during analysis of the object 147. For instance, where the object 147 is identified as a Microsoft® Excel®
spreadsheet, the selected action profile 300i may conduct different UI functions (e.g., select tabs, add text to certain cells, scroll down a certain number of cell rows, etc.) than another action profile 300R for controlling UI functionality during analysis of a PDF document (e.g., scroll pages of the document, etc.).
[0067] According to a first embodiment, as shown in FIG. 3A, upon selection of the action profile, the profile selector 184 provides signaling 310 to identify the selected action profile 300i that is part of the pre-stored action profile(s) 188. In response, according to one embodiment of the disclosure, the content 320 of the selected action profile 300i may be passed to the simulation logic 350 for use by the active UI simulation logic 360, the passive UI simulation logic 370, and the device control simulation logic 380. According to another embodiment of the disclosure, as shown in FIG. 3B, upon choosing the selected action profile 300i, the profile selector 184 passes an identifier 330 of the selected action profile 3001 to the simulation logic 350 (active UI simulation logic 360, passive UI simulation logic 370, and device control simulation logic 380) to allow the simulation logic 350 to poll and retrieve information 335 (e.g., commands, instructions, rules and/or parameters) from the selected action profile 300i.
[0068] As an optional feature, although not shown, addressing information (e.g., a pointer, memory storage location, etc.) may be provided to the actuation logic 340 associated with that particular object type. The addressing information may be used for accessing a sequence of commands and/or instructions that conducting operations suitable for launching a particular object type.
[0069] Referring to both FIGs. 3A and 3B, implemented as part of a software profile that provisions the VM 170i, the actuation logic 340 is responsible for launching the object 147. The particular implementation of the actuation logic 340 may vary depending on the object type. For instance, where the object 147 is a document type (e.g., Microsoft® Word® document, PDF document, etc.), the actuation logic 340 may be customized logic which supports launching (in this case, opening) of the object 147 (or concurrent launching of the object 147 by different versions of) the application and/or OS (e.g., Windows® 7 and Office® 2013; Windows® 7, Office® 2010, etc.).
Alternatively, where the object 147 is an executable, the actuation logic 340 may be a software module (e.g., script, etc.) that copies the object 147 to a file system storage location and subsequently calls an operating system (OS) function, such as
"CreateProcessO" for example, to process the object 147.
[0070] Upon launching the object 147, the actuation logic 340 provides a launch notification 345 to the simulation logic 350, namely the active UI simulation logic 360, the passive UI simulation logic 370 and the device control simulation logic 380.
According to one embodiment, the launch notification 345 may cause the simulation logic 350 to poll for data 347. According to one embodiment of the disclosure, the data 347 may include (i) an identifier for the object 147; (ii) an identifier as to a type of actuation logic (e.g., particular software module) used to launch the object 147; and/or (iii) the time that the object 147 was launched. Of course, in accordance with a "push" communication scheme, the data 347 may be provided as part of the launch notification 345.
[0071] According to this embodiment, the identifier of the object 147 and/or the identifier of the actuation logic 340 may be used to verify that the con-ect selected action profile 300i has been passed to the simulation logic 350 for use at the correct time(s) during processing of the object 147. The launch time may be used to synchronize the active UI simulation logic 360, the passive UI simulation logic 370 and the device control simulation logic 380 with each other. The launch time also establishes a reference time for use when the passive UI simulation logic 370 is conducting time- based simulated human, and/or the device control simulation logic 380 is conducting time-based simulated device control interaction in accordance with the selected action profile 300i. The synchronization is especially relevant for actions conducted by the passive UI simulation logic 370 and the device control simulation logic 380 in accordance with the selected action profile 3001 , as illustrated in FIG. 4 A, and adds intelligence and predictability to the user interaction. Therefore, it is contemplated that most or all of the UI simulation logic 360/370/380 is in communication with the same (or synchronized) timing circuitry (e.g., real time clock, counter, etc.).
[0072] As further shown in FIG. 3 A and FIG. 3B, the active UI simulation logic 360, the passive UI simulation logic 370 and the device control simulation logic 380 are instantiated with or are instantiated to access content within the selected action profile 300i, which controls the simulated human and device control interactions conducted by the UI framework 186 during analysis of the object 147. Collectively, in accordance with the rules outlined in the selected action profile 300i, the simulation logic 350 conducts particular actions (e.g., expected user interface interactions and/or methods of activation) during particular operating states at which such actions are expected (e.g., in predetermined sequence (order) and/or at or within a predetermined period of time). Furthermore, although described as being conducted in sequentially, it is contemplated that two or more actions may be conducted concurrently (at least partially overlapping at the same time).
[0073] Operating as part the UI framework 186, the active UI simulation logic 360 is a first type of simulated user interaction which is configured to detect input requests (e.g., password request, an attempt to display a dialog or text box for selection of a radio button or text input, etc.) initiated by the object 147 that require "active" human interaction. In response, based on the contents of the selected action profile 300i, the active UI simulation logic 360 determines whether to provide a response and, where appropriate, the type of response that simulates the requested human interaction. For instance, the selected action profile 300i may cause the active UI simulation logic 360 to provide signaling that simulates human interaction responsive to the input request initiated by the launched object 147. For example, the signaling may simulate the user closing a dialog box that requires dismissal before continuing or simulate the user selecting a particular radio button that closes the dialog box and opens another dialog box for handling. Such signaling may be intentionally delayed by a prescribed or random period of time to further simulate human interaction. This response and/or responses to subsequent input requests may trigger the object 147 to commence a malicious attack, which could only have been activated by such simulated human interactions.
[0074] The passive UI simulation logic 370 is a second type of simulated user interaction which provides "passive" simulated human interaction. The "passive" simulated human interaction is in accordance with the selected action profile, but it is not responsive to an input request by the launched object 147 (e.g., a behavior of the launched object that requiring user action). In some cases, the simulated human interaction is in response to a prescribed level of inactivity by the object.
[0075] Herein, the "passive" simulated human interaction may include any simulated operations that, without prompting, may be conducted by the user on the object such as moving to a particular page in a Microsoft® Office Word document (object) or switching to a particular tab in a Microsoft® Office Excel document (object). As an illustrative example, assuming the object has an object-type of a Microsoft® Office Excel document, experiential knowledge of typical placement of exploit/malicious code (e.g., through machine learning techniques) in a Microsoft® Office Excel document may result in instructions in the selected action profile for the passive UI simulation logic 370 to switch to the second sheet of the Microsoft® Office® Excel document at a
predetermined time after the actuation logic launches the object.
[0076] The device control simulation logic 380 is a third type of simulated user interaction that may be performed during virtual analysis of the suspect object 147. The device control simulation logic 380 simulates device control interactions that are object- type agnostic. For example, the device control simulation logic 380 may receive instructions from the selected action profile 3001 to simulate certain device control interactions, such as simulate particular keystrokes and/or particular mouse movements, in an attempt to detonate a malicious object that is awaiting user interaction before conducting a malicious attack.
[0077] Additionally, the UI framework log 176 records the activities conducted by the simulation logic 350. As discussed above, the UI framework log 176 may record any suspicious activity and/or malicious activity as well as any actions taken, or refrained from being taken, any requested input and timestamps for all actions and requested input. Upon completion of the dynamic analysis, the information recorded in the UI framework
log 176 may be accessible to the score determination logic 168 and/or the classification engine 190.
[0078] It is contemplated that the action profile(s) 188 may be updated through a configuration file that may be propagated to the MDS 110i over a network 125 of FIG. 2. For example, the action profile update may be provided by the management system 220 over network 125 via machine learning engine 122, which receives information associated with malicious objects as reported by reporting engine 195 based on content within the UI framework log 176. Additionally, the machine learning engine 122 receives information associated with Ul-dependent malicious objects as reported by other MDSes (e.g., MDS 1102 or MDS 1103). The machine learning engine 122 utilizes this information, and information from third party sources, to develop action profile updates. The action profile update may include revised rules, new instructions or commands, and/or altered parameters that may provide improved malware detection by targeting new characteristics in an object- type and/or targeting newly identified malware inclusive of exploits, suspicious code and/or malicious code or other data that assists in conducting a malicious attack on a network or network device.
[0079] Alternatively, the action profile update may be provided by over the network 105 (for example through a download using the cloud computing services 228 and/or manual installation through the use of a storage device such as flash storage).
IV. USER INTERACTION CONDUCTED BY THE SIMULATION LOGIC
[0080] Referring now to FIG. 4A, a flowchart illustrating an exemplary method conducted by the passive UI simulation logic and the device control simulation logic for detecting malware is shown. Each block illustrated in FIG. 4A represents an operation performed in accordance with a selected action profile for providing targeted, simulated user interaction during analysis of the object 147 within a virtual run-time environment. These operations are conducted by the MDS 100i in efforts to automatically, without human interaction, detect malicious objects that commence a malicious attack in response to human interaction. For this embodiment, with the selected active profile, "active" simulated human interaction responsive to input requests from the object is
assigned the highest priority, while "passive" simulated human interactions and simulated device control interactions are assigned lesser priority.
[0081] Herein, a first determination is made as to whether the object has been launched by the actuation logic (block 400). If not, the UI framework does not receive a launch notification from the actuation logic, and thus, the simulation logic remains in an idle state. However, once an object is launched, the simulation logic receives a launch notification from the actuation logic, which causes the simulation logic to reference the selected action profile. A first determination is made as to whether user interaction is currently being requested based on resultant behaviors of the object during analysis (block 405). Stated differently, a determination is made as to whether the object process has initiated an input request, where timely "active" simulated human interaction is necessary. This determination may be conducted by monitoring system calls and other signaling that is directed to generation of a dialog box, text box, window or other perceivable element that would require user interaction.
[0082] In event that the passive UI simulation logic is currently conducting "passive" simulated human interactions and/or the device control simulation logic is currently conducting simulated device control interactions in accordance with rules outlined in the selected action profile, these simulated operations are paused for a prescribed duration. The prescribed duration may be set by the rules set forth in the selected action profile that identify the amount of time necessary to complete a particular type of "active" simulated human interaction. Furthermore, the "paused" simulated operations are time- stamped and placed in a wait queue for subsequent processing after the active UI simulation logic has completed its simulated human interaction. The selected action profile triggers the active UI simulation logic to conduct a particular "active" simulated human interaction and store the activity in the UI framework log. Thereafter, the simulation logic determines if the analysis of the object has completed, and if not, cycles back to determine whether the object is actively requesting user interaction (blocks 410- 425).
[0083] In the event that active user interaction is not needed at this time, a determination
is made as to whether there are any "paused" passive simulated human interactions and/or simulated device control interactions (blocks 405 and 430). This determination may be accomplished by analysis of the wait queue and/or determining whether a prescribed wait duration has elapsed (e.g., difference between current time and the time- stamp is greater than or equal to the prescribed duration). If so, these paused simulated operations are resumed (block 435). However, if there are no paused passive simulated human interactions and/or the simulated device control interactions, a determination is made as to whether there are any "passive" simulated human interactions that, according to the selected action profile, should be initiated (block 440). If so, the selected action profile triggers the passive UI simulation logic to conduct a particular "passive" simulated human interaction and store the activity in the UI framework log (block 445).
[0084] In the event that there has been at least a predetermined level of UI simulated activity thus far, the simulation logic may return to determine if the analysis of the object has completed, and if not, cycles back to determine whether the object is actively requesting certain user interaction (blocks 450, 420 and 405). The prescribed level of UI simulated activity may be measured by a variety of ways. For instance, the prescribed level of UI simulated activity may be determined based on whether simulated human interactions have occurred for a certain percentage of the run-time since the object was launched. Alternatively, the process may determine the number of "active" simulated human interactions or the number of active/passive simulated human interactions that have been completed since the object was launched.
[0085] In the event that the predetermined level of UI simulated activity has not been met, the device control simulation logic accesses the selected action profile to determine what simulated device control interactions are requested by the selection action profile, and thereafter, the selected action profile triggers the device control simulation logic to simulate such device controls and store such activity in the UI framework log.
Thereafter, the simulation logic returns to determine if the analysis of the object has completed, and if not, cycles back to determine whether the object is actively requesting user interaction (blocks 450, 420 and 405).
[0086] According to these operations, the UI control logic is adapted to prioritize "active" simulated human interaction above "passive" simulated human interaction and the simulated device control interaction. Hence, in some cases as described herein, simulated human interaction and simulated device control interactions may be temporarily halted to direct resources to respond to an activity initiated by the object. Of course, it is contemplated that some types of "passive" simulated human interactions and simulated device control interactions may continue despite detection of an input request by the object. This may be done to maintain perceived consistency in simulated operations to avoid sophisticated malware to detect abnormally prompt changes in operation.
[0087] Referring now to FIG. 4B, a flowchart illustrating an exemplary method conducted by the active UI simulation logic for detecting malware is shown. As previously described, a first determination is made as to whether the object has been launched by the actuation logic (block 470). If not, the active UI simulation logic remains in an idle state. However, once an object is launched, the active UI simulation logic receives a notification from the actuation logic, where the simulation logic determines whether the suspect object is currently requesting some sort of active user interaction such as a dialog box is opened that required dismissal before the object continues its operation for example (block 475).
[0088] If so, the active UI simulation logic notifies the passive UI simulation and the device control simulation logic of an imminent active user interaction (block 480). This notification prompts the passive UI simulation and the device control simulation logic to pause any current operations as described in FIG. 4A. Thereafter, the active UI simulation logic performs a human simulation operation in accordance with rules set forth in the selected action profile and such activity is stored in the UI framework logic (block 485).
[0089] If the active UI simulation logic determines that the suspect object under analysis is not currently requesting active user interaction or responsive simulated human interactions have been provided, the active UI simulation logic determines whether the
analysis of the suspect object has completed. If not, the active UI simulation logic initiates another iterative cycle awaiting a requested user interaction (block 490).
V. SOFTWARE DEPLOYMENT OF THE MPS
[0090] Referring now to FIG. 5, an exemplary block diagram of logic associated with the MDS 110i of FIG. 1 is shown. The MDS 110i comprises one or more processors 500 (hereinafter "processor(s)"), which is coupled to a first communication interface logic 510 via a first transmission medium 520. The first communication interface logic 510 may provide a communicative coupling with the network interface 136 of FIG. 1. Additionally, the processor(s) 500 may be communicatively coupled to a second communication interface logic 530 via a second transmission medium 540, which may provide communications with other MDSes 1102-1 I O3 and management system 120 of FIG. 1.
[0091] According to one embodiment of the disclosure, the first communication interface logic 510 and/or the second communication interface logic 530 may be implemented as a physical interface including one or more ports for wired connectors. Additionally, or in the alternative, the first communication interface logic 510 and/or the second communication interface logic 530 may be implemented with one or more radio units for supporting wireless communications with other network devices.
[0092] The processor(s) 500 are further coupled to the persistent storage 550 via the transmission medium 560. According to one embodiment of the disclosure, the persistent storage 550 may be configured to store software components associated with the static analysis engine 145, the dynamic analysis engine 160, the classification engine 190 and the reporting engine 195. As shown, software components associated with the static analysis engine 145 may include the static analysis logic 152, the metadata extraction logic 154 and/or the object-type determination logic 156. The persistent storage 550 may be further configured to store software components associated with the dynamic analysis engine 160, which includes the VMM 172 along with the VMs 170i- 170M. All or some of the VMs 170I-170M may be provisioned with the UI control logic 182, which may include the profile selector 184, UI framework 186 and/or action
profile(s) 188.
[0093] Additionally, the persistent storage 550 may include the magic number database 158 that is accessed by the object-type determination logic 156 (described above) and data stores 159 and 164 that may operate, at least part, as data buffers.
[0094] In the foregoing description, the invention is described with reference to specific exemplary embodiments thereof. It will, however, be evident that various modifications and changes may be made thereto without departing from the broader spirit and scope of the invention as set forth in the appended claims.
Claims
1. A non-transitory computer readable storage medium having stored thereon logic that, upon execution by one or more processors implemented within a network device, performs operations comprising: launching, by an actuation logic, an object within a virtual run-time environment; and selecting, by a control logic, one or more simulated user interactions with the object based on metadata associated with the object, the metadata includes data identifying an object type corresponding to the object launched by the actuation logic.
2. The non-transitory computer readable storage medium of Claim 1, wherein the launching of the object further comprises selecting the actuation logic, which is a software component implemented as part of a software profile that provisions one or more virtual machines operating within the virtual run-time environment, based on the metadata.
3. The non-transitory computer readable storage medium of Claim 2 further comprising: responsive to determining a first user interaction is being requested by the object, triggering a first simulated human interaction to occur, the first simulated human interaction being part of the one or more simulated user interactions; responsive to determining no user interaction is being requested by the object, resuming a second simulated human interaction, the second simulated human interaction having been previously triggered and paused upon determining the first user interaction is being requested.
4. The computer readable storage medium of Claim 3, wherein the first simulated human interaction comprises a simulated action that is responsive to a behavior by the object having been launched by the actuation logic in the one or more virtual machines, the behavior represents an operating state of the object where the object is actively waiting for user input.
5. The computer readable storage medium of Claim 4, wherein the first simulated human interaction comprises at least one of (i) a simulated action of closing a window or a dialog box, (ii) a simulated action of selecting a particular radio button, and (iii) a simulated action of entering one or more characters into a text box.
6. The computer readable storage medium of Claim 4, wherein the second simulated human interaction comprises a simulated action that is initiated by a user during virtual analysis of the launched object.
7. The computer readable storage medium of Claim 6, wherein the second simulated human interaction comprises at least one of (i) a simulated action of scrolling a page of a document corresponding to the object, (ii) a simulated action of selecting a certain tab of a spreadsheet corresponding to the object, (iii) a simulated action of selecting a particular page of the document, and (iv) a simulated action of accessing one or more menu options.
8. The computer readable storage medium of Claim 4, wherein the second simulated human interaction comprises simulated device control for an input device that controls operations of an endpoint targeted to receive data including the object.
9. The computer readable storage medium of Claim 8, wherein the simulated device control comprises at least one of (i) a simulated action of a keystroke for a keyboard corresponding to the input device, (ii) a simulated action of a movement of a mouse corresponding to the input device, (iii) a simulated action of a click of a button on the mouse, and (iv) a simulated action of an area of a touch screen corresponding to the input device.
10. The computer readable storage medium of Claim 3, wherein the first simulated human interaction is controlled by a first user interaction (UI) simulation logic and the second simulated human interaction is controlled by a second UI simulation logic, the second UI simulation logic is aware of the first simulated human interaction being performed by the first UI simulation logic and pauses the second simulated human interaction in favor of the first simulated human interaction for later resumption of the second simulated human interaction.
11. The computer readable storage medium of Claim 1 further comprising: prior to launching the object within the virtual run-time environment, selecting an action profile by a profile selector based on the received metadata associated with the object, the action profile comprises a plurality of rules that dynamically control the one or more simulated user interactions.
12. The computer readable storage medium of Claim 11, wherein the action profile is selected by the profile selector provisioned within one or more virtual machines operating within the virtual run-time environment.
13. The computer readable storage medium of Claim 11, wherein the action profile is selected by the profile selector implemented within a virtual machine monitor (VMM) communicatively coupled to one or more virtual machines operating within the virtual run-time environment.
14. An apparatus for detecting malware with an object, the apparatus comprising: one or more action profiles, each action profile of the one or more action profiles being a collection of instructions or commands that performs user interaction (UI) activity in accordance with a set of rules prescribed for the corresponding action profile;
a profile selector for selecting an action profile from the one or more action profiles based on metadata associated with the object, the metadata includes data identifying a type of the object; and a UI framework logic that, in response to the object being launched within a virtual machine, performs simulated user interactions with the object in accordance with the set of rules prescribed in the selected action profile, the UI framework logic including (i) an actuation logic to launch the object, and (ii) simulation logic to dynamically control the simulated user interactions conducted on the launched object.
15. The apparatus of Claim 14, wherein the simulation logic comprises (i) an active UI simulation logic, (ii) a passive UI simulation logic, and (iii) a device control simulation logic.
16. The apparatus of Claim 15, wherein the active UI simulation logic is configured to: detect an input request initiated by the launched object, and responsive to detecting the input request initiated by the launched object, determine a response based on contents of the selected action profile.
17. The apparatus of Claim 16, wherein the input request includes an attempted display of a dialog box.
18. The apparatus of Claim 17, wherein the response comprises at least one of (i) a simulated action of closing the dialog box, and (ii) a simulated action of selecting a particular radio button associated with the dialog box.
19. The apparatus of Claim 15, wherein the passive UI simulation logic is configured to provide a simulated human interaction during virtual analysis of the launched object, the simulated human interaction represents user-initiated simulated actions.
20. The apparatus of Claim 15, wherein the device control simulation logic is configured to simulate device control interactions that are object-type agnostic.
21. The apparatus of Claim 14 further comprising a log including data so that, when the launched object is classified as malware, the data is used to update the one or more action profiles by indicating a set of simulated user interactions that lead to successful triggering of malicious behavior by the launched object.
22. The apparatus of Claim 14 further comprising logic to transmit the data within the log to a cloud infrastructure when the launched object is classified as suspicious as a result of virtual analysis, wherein the one or more action profiles are updated based on a lack of detonation of malware within the launched object or an obstruction of the detonation of malware within the launched object.
23. A computerized method implemented with a network device for detecting malware, comprising: launching, by an actuation logic within the network device, an object within a virtual run-time environment; and selecting, by a profile selector, an action profile based on metadata associated with the object, wherein the metadata comprises data identifying an object type corresponding to the object and the action profile comprises a set of rules that dynamic control one or more simulated user interactions with the launched object.
24. The method of Claim 23, wherein the launching of the object further comprises selecting the actuation logic based on the metadata.
25. The method of Claim 23, wherein the simulated user interactions comprising: responsive to determining a first user interaction is being requested by the launched object, triggering a first simulated human interaction to occur, the first simulated human interaction being part of the one or more simulated user interactions;
responsive to detemiining no user interaction is being requested by the object, resuming a second simulated human interaction, the second simulated human interaction having been previously triggered and paused upon detemiining the first user interaction is being requested.
26. The method of Claim 25, wherein the first simulated human interaction comprises a simulated action that is responsive to a behavior by the launched object in one or more virtual machines that are part of the run-time virtual environment, the behavior represents an operating state of the launched object where the launched object is actively waiting for user input.
27. The method of Claim 25, wherein the second simulated human interaction comprises a simulated action that is initiated by a user during virtual analysis of the launched object.
28. The method of Claim 25, wherein the second simulated human interaction comprises simulated device control for an input device that controls operations of an endpoint targeted to receive data including the object.
29. The method of Claim 25, wherein the first simulated human interaction is controlled by a first user interaction (UI) simulation logic and the second simulated human interaction is controlled by a second UI simulation logic, the second UI simulation logic is aware of the first simulated human interaction being performed by the first UI simulation logic and pauses the second simulated human interaction in favor of the first simulated human interaction for later resumption of the second simulated human interaction.
30. The method of Claim 23, wherein the action profile is selected from a plurality of action profiles by the profile selector provisioned within one or more virtual machines operating within the virtual run-time environment.
31. The method of Claim 30, wherein the plurality of action profiles are updated via network delivered updates to modify instractions, parameters or rules within an action profile to be updated
32. The method of Claim 23, wherein the action profile is selected from a plurality of action profiles by the profile selector implemented within a virtual machine monitor (VMM) communicatively coupled to one or more virtual machines operating within the virtual run-time environment.
33. The method of Claim 25 further comprising: recording, in a log, selection of the action profile, determination of the first user interaction requested by the object, triggering of the first simulated human interaction, and triggering of the second simulated human interaction.
34. The method of Claim 33, wherein data stored within the log is subsequently used to update a plurality of action profiles including the selected action profile by indicating whether certain simulated user interactions detonated malware within the object.
Priority Applications (2)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
JP2017535823A JP6702983B2 (en) | 2014-12-30 | 2015-12-21 | Intelligent and context-aware user interaction for malware detection |
EP15823116.7A EP3245609A1 (en) | 2014-12-30 | 2015-12-21 | Intelligent context aware user interaction for malware detection |
Applications Claiming Priority (2)
Application Number | Priority Date | Filing Date | Title |
---|---|---|---|
US14/586,233 | 2014-12-30 | ||
US14/586,233 US9838417B1 (en) | 2014-12-30 | 2014-12-30 | Intelligent context aware user interaction for malware detection |
Publications (1)
Publication Number | Publication Date |
---|---|
WO2016109283A1 true WO2016109283A1 (en) | 2016-07-07 |
Family
ID=55080234
Family Applications (1)
Application Number | Title | Priority Date | Filing Date |
---|---|---|---|
PCT/US2015/067082 WO2016109283A1 (en) | 2014-12-30 | 2015-12-21 | Intelligent context aware user interaction for malware detection |
Country Status (4)
Country | Link |
---|---|
US (2) | US9838417B1 (en) |
EP (1) | EP3245609A1 (en) |
JP (1) | JP6702983B2 (en) |
WO (1) | WO2016109283A1 (en) |
Cited By (6)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US10169585B1 (en) | 2016-06-22 | 2019-01-01 | Fireeye, Inc. | System and methods for advanced malware detection through placement of transition events |
WO2019046166A1 (en) * | 2017-08-29 | 2019-03-07 | Symantec Corporation | Systems and methods for preventing malicious applications from exploiting application services |
KR20190064264A (en) * | 2017-11-30 | 2019-06-10 | 건국대학교 산학협력단 | Ransomware dectecting method and apparatus based on machine learning through hybrid analysis |
WO2019142398A1 (en) * | 2018-01-17 | 2019-07-25 | 日本電信電話株式会社 | Interpretation device, interpretation method and interpretation program |
EP3611643A1 (en) * | 2018-08-13 | 2020-02-19 | Juniper Networks, Inc. | Malware detection based on user interactions |
US20220292191A1 (en) * | 2019-08-29 | 2022-09-15 | Nec Corporation | Backdoor inspection apparatus, backdoor inspection method, and non-transitory computer readable medium |
Families Citing this family (127)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US8171553B2 (en) | 2004-04-01 | 2012-05-01 | Fireeye, Inc. | Heuristic based capture with replay to virtual machine |
US8793787B2 (en) | 2004-04-01 | 2014-07-29 | Fireeye, Inc. | Detecting malicious network content using virtual environment components |
US7587537B1 (en) | 2007-11-30 | 2009-09-08 | Altera Corporation | Serializer-deserializer circuits formed from input-output circuit registers |
US9106694B2 (en) | 2004-04-01 | 2015-08-11 | Fireeye, Inc. | Electronic message analysis for malware detection |
US8528086B1 (en) | 2004-04-01 | 2013-09-03 | Fireeye, Inc. | System and method of detecting computer worms |
US8881282B1 (en) | 2004-04-01 | 2014-11-04 | Fireeye, Inc. | Systems and methods for malware attack detection and identification |
US8832829B2 (en) | 2009-09-30 | 2014-09-09 | Fireeye, Inc. | Network-based binary file extraction and analysis for malware detection |
US20130173642A1 (en) | 2011-12-30 | 2013-07-04 | Nokia Corporation | Method and apparatus for consent document management |
US10572665B2 (en) | 2012-12-28 | 2020-02-25 | Fireeye, Inc. | System and method to create a number of breakpoints in a virtual machine via virtual machine trapping events |
US9195829B1 (en) | 2013-02-23 | 2015-11-24 | Fireeye, Inc. | User interface with real-time visual playback along with synchronous textual analysis log display and event/time index for anomalous behavior detection in applications |
US9104867B1 (en) | 2013-03-13 | 2015-08-11 | Fireeye, Inc. | Malicious content analysis using simulated user interaction without user involvement |
US9626509B1 (en) | 2013-03-13 | 2017-04-18 | Fireeye, Inc. | Malicious content analysis with multi-version application support within single operating environment |
US9311479B1 (en) | 2013-03-14 | 2016-04-12 | Fireeye, Inc. | Correlation and consolidation of analytic data for holistic view of a malware attack |
US9413781B2 (en) | 2013-03-15 | 2016-08-09 | Fireeye, Inc. | System and method employing structured intelligence to verify and contain threats at endpoints |
US10713358B2 (en) | 2013-03-15 | 2020-07-14 | Fireeye, Inc. | System and method to extract and utilize disassembly features to classify software intent |
US9495180B2 (en) | 2013-05-10 | 2016-11-15 | Fireeye, Inc. | Optimized resource allocation for virtual machines within a malware content detection system |
US9635039B1 (en) | 2013-05-13 | 2017-04-25 | Fireeye, Inc. | Classifying sets of malicious indicators for detecting command and control communications associated with malware |
US9300686B2 (en) | 2013-06-28 | 2016-03-29 | Fireeye, Inc. | System and method for detecting malicious links in electronic messages |
US9628507B2 (en) | 2013-09-30 | 2017-04-18 | Fireeye, Inc. | Advanced persistent threat (APT) detection center |
US10515214B1 (en) | 2013-09-30 | 2019-12-24 | Fireeye, Inc. | System and method for classifying malware within content created during analysis of a specimen |
US9171160B2 (en) | 2013-09-30 | 2015-10-27 | Fireeye, Inc. | Dynamically adaptive framework and method for classifying malware using intelligent static, emulation, and dynamic analyses |
US9736179B2 (en) | 2013-09-30 | 2017-08-15 | Fireeye, Inc. | System, apparatus and method for using malware analysis results to drive adaptive instrumentation of virtual machines to improve exploit detection |
US9690936B1 (en) | 2013-09-30 | 2017-06-27 | Fireeye, Inc. | Multistage system and method for analyzing obfuscated content for malware |
US9747446B1 (en) | 2013-12-26 | 2017-08-29 | Fireeye, Inc. | System and method for run-time object classification |
US9756074B2 (en) | 2013-12-26 | 2017-09-05 | Fireeye, Inc. | System and method for IPS and VM-based detection of suspicious objects |
US9507935B2 (en) | 2014-01-16 | 2016-11-29 | Fireeye, Inc. | Exploit detection system with threat-aware microvisor |
US9262635B2 (en) | 2014-02-05 | 2016-02-16 | Fireeye, Inc. | Detection efficacy of virtual machine-based analysis with application specific events |
US10242185B1 (en) | 2014-03-21 | 2019-03-26 | Fireeye, Inc. | Dynamic guest image creation and rollback |
US9591015B1 (en) | 2014-03-28 | 2017-03-07 | Fireeye, Inc. | System and method for offloading packet processing and static analysis operations |
US9223972B1 (en) | 2014-03-31 | 2015-12-29 | Fireeye, Inc. | Dynamically remote tuning of a malware content detection system |
US10084813B2 (en) | 2014-06-24 | 2018-09-25 | Fireeye, Inc. | Intrusion prevention and remedy system |
US10805340B1 (en) | 2014-06-26 | 2020-10-13 | Fireeye, Inc. | Infection vector and malware tracking with an interactive user display |
US10002252B2 (en) | 2014-07-01 | 2018-06-19 | Fireeye, Inc. | Verification of trusted threat-aware microvisor |
US10027689B1 (en) | 2014-09-29 | 2018-07-17 | Fireeye, Inc. | Interactive infection visualization for improved exploit detection and signature generation for malware and malware families |
US9690933B1 (en) | 2014-12-22 | 2017-06-27 | Fireeye, Inc. | Framework for classifying an object as malicious with machine learning for deploying updated predictive models |
US9934376B1 (en) | 2014-12-29 | 2018-04-03 | Fireeye, Inc. | Malware detection appliance architecture |
US9838417B1 (en) | 2014-12-30 | 2017-12-05 | Fireeye, Inc. | Intelligent context aware user interaction for malware detection |
US10148693B2 (en) | 2015-03-25 | 2018-12-04 | Fireeye, Inc. | Exploit detection system |
US10417031B2 (en) | 2015-03-31 | 2019-09-17 | Fireeye, Inc. | Selective virtualization for security threat detection |
US10474813B1 (en) | 2015-03-31 | 2019-11-12 | Fireeye, Inc. | Code injection technique for remediation at an endpoint of a network |
US9654485B1 (en) | 2015-04-13 | 2017-05-16 | Fireeye, Inc. | Analytics-based security monitoring system and method |
US10454950B1 (en) | 2015-06-30 | 2019-10-22 | Fireeye, Inc. | Centralized aggregation technique for detecting lateral movement of stealthy cyber-attacks |
US10395029B1 (en) | 2015-06-30 | 2019-08-27 | Fireeye, Inc. | Virtual system and method with threat protection |
US10726127B1 (en) | 2015-06-30 | 2020-07-28 | Fireeye, Inc. | System and method for protecting a software component running in a virtual machine through virtual interrupts by the virtualization layer |
US10642753B1 (en) | 2015-06-30 | 2020-05-05 | Fireeye, Inc. | System and method for protecting a software component running in virtual machine using a virtualization layer |
US10216927B1 (en) | 2015-06-30 | 2019-02-26 | Fireeye, Inc. | System and method for protecting memory pages associated with a process using a virtualization layer |
US11113086B1 (en) | 2015-06-30 | 2021-09-07 | Fireeye, Inc. | Virtual system and method for securing external network connectivity |
US10715542B1 (en) | 2015-08-14 | 2020-07-14 | Fireeye, Inc. | Mobile application risk analysis |
US10176321B2 (en) | 2015-09-22 | 2019-01-08 | Fireeye, Inc. | Leveraging behavior-based rules for malware family classification |
US10033759B1 (en) | 2015-09-28 | 2018-07-24 | Fireeye, Inc. | System and method of threat detection under hypervisor control |
US10033747B1 (en) | 2015-09-29 | 2018-07-24 | Fireeye, Inc. | System and method for detecting interpreter-based exploit attacks |
US10601865B1 (en) | 2015-09-30 | 2020-03-24 | Fireeye, Inc. | Detection of credential spearphishing attacks using email analysis |
US9825989B1 (en) | 2015-09-30 | 2017-11-21 | Fireeye, Inc. | Cyber attack early warning system |
US10817606B1 (en) | 2015-09-30 | 2020-10-27 | Fireeye, Inc. | Detecting delayed activation malware using a run-time monitoring agent and time-dilation logic |
US10210329B1 (en) | 2015-09-30 | 2019-02-19 | Fireeye, Inc. | Method to detect application execution hijacking using memory protection |
US10706149B1 (en) | 2015-09-30 | 2020-07-07 | Fireeye, Inc. | Detecting delayed activation malware using a primary controller and plural time controllers |
US10284575B2 (en) | 2015-11-10 | 2019-05-07 | Fireeye, Inc. | Launcher for setting analysis environment variations for malware detection |
US10846117B1 (en) | 2015-12-10 | 2020-11-24 | Fireeye, Inc. | Technique for establishing secure communication between host and guest processes of a virtualization architecture |
US10447728B1 (en) | 2015-12-10 | 2019-10-15 | Fireeye, Inc. | Technique for protecting guest processes using a layered virtualization architecture |
US10108446B1 (en) | 2015-12-11 | 2018-10-23 | Fireeye, Inc. | Late load technique for deploying a virtualization layer underneath a running operating system |
US10133866B1 (en) | 2015-12-30 | 2018-11-20 | Fireeye, Inc. | System and method for triggering analysis of an object for malware in response to modification of that object |
US10050998B1 (en) | 2015-12-30 | 2018-08-14 | Fireeye, Inc. | Malicious message analysis system |
US10565378B1 (en) | 2015-12-30 | 2020-02-18 | Fireeye, Inc. | Exploit of privilege detection framework |
US10581874B1 (en) | 2015-12-31 | 2020-03-03 | Fireeye, Inc. | Malware detection system with contextual analysis |
US11552986B1 (en) | 2015-12-31 | 2023-01-10 | Fireeye Security Holdings Us Llc | Cyber-security framework for application of virtual features |
US10601863B1 (en) | 2016-03-25 | 2020-03-24 | Fireeye, Inc. | System and method for managing sensor enrollment |
US10616266B1 (en) | 2016-03-25 | 2020-04-07 | Fireeye, Inc. | Distributed malware detection system and submission workflow thereof |
US10785255B1 (en) * | 2016-03-25 | 2020-09-22 | Fireeye, Inc. | Cluster configuration within a scalable malware detection system |
US10671721B1 (en) | 2016-03-25 | 2020-06-02 | Fireeye, Inc. | Timeout management services |
US10893059B1 (en) | 2016-03-31 | 2021-01-12 | Fireeye, Inc. | Verification and enhancement using detection systems located at the network periphery and endpoint devices |
US10826933B1 (en) | 2016-03-31 | 2020-11-03 | Fireeye, Inc. | Technique for verifying exploit/malware at malware detection appliance through correlation with endpoints |
US10462173B1 (en) | 2016-06-30 | 2019-10-29 | Fireeye, Inc. | Malware detection verification and enhancement by coordinating endpoint and malware detection systems |
US10592678B1 (en) | 2016-09-09 | 2020-03-17 | Fireeye, Inc. | Secure communications between peers using a verified virtual trusted platform module |
US10491627B1 (en) | 2016-09-29 | 2019-11-26 | Fireeye, Inc. | Advanced malware detection using similarity analysis |
US10795991B1 (en) | 2016-11-08 | 2020-10-06 | Fireeye, Inc. | Enterprise search |
US10587647B1 (en) | 2016-11-22 | 2020-03-10 | Fireeye, Inc. | Technique for malware detection capability comparison of network security devices |
US10552610B1 (en) | 2016-12-22 | 2020-02-04 | Fireeye, Inc. | Adaptive virtual machine snapshot update framework for malware behavioral analysis |
US10581879B1 (en) | 2016-12-22 | 2020-03-03 | Fireeye, Inc. | Enhanced malware detection for generated objects |
US10523609B1 (en) | 2016-12-27 | 2019-12-31 | Fireeye, Inc. | Multi-vector malware detection and analysis |
US10904286B1 (en) | 2017-03-24 | 2021-01-26 | Fireeye, Inc. | Detection of phishing attacks using similarity analysis |
US10798112B2 (en) | 2017-03-30 | 2020-10-06 | Fireeye, Inc. | Attribute-controlled malware detection |
US10902119B1 (en) | 2017-03-30 | 2021-01-26 | Fireeye, Inc. | Data extraction system for malware analysis |
US10848397B1 (en) | 2017-03-30 | 2020-11-24 | Fireeye, Inc. | System and method for enforcing compliance with subscription requirements for cyber-attack detection service |
US10791138B1 (en) | 2017-03-30 | 2020-09-29 | Fireeye, Inc. | Subscription-based malware detection |
US10503904B1 (en) | 2017-06-29 | 2019-12-10 | Fireeye, Inc. | Ransomware detection and mitigation |
US10855700B1 (en) | 2017-06-29 | 2020-12-01 | Fireeye, Inc. | Post-intrusion detection of cyber-attacks during lateral movement within networks |
US10601848B1 (en) | 2017-06-29 | 2020-03-24 | Fireeye, Inc. | Cyber-security system and method for weak indicator detection and correlation to generate strong indicators |
US10893068B1 (en) | 2017-06-30 | 2021-01-12 | Fireeye, Inc. | Ransomware file modification prevention technique |
US10747872B1 (en) | 2017-09-27 | 2020-08-18 | Fireeye, Inc. | System and method for preventing malware evasion |
US10805346B2 (en) | 2017-10-01 | 2020-10-13 | Fireeye, Inc. | Phishing attack detection |
US11108809B2 (en) | 2017-10-27 | 2021-08-31 | Fireeye, Inc. | System and method for analyzing binary code for malware classification using artificial neural network techniques |
US11005860B1 (en) | 2017-12-28 | 2021-05-11 | Fireeye, Inc. | Method and system for efficient cybersecurity analysis of endpoint events |
US11240275B1 (en) | 2017-12-28 | 2022-02-01 | Fireeye Security Holdings Us Llc | Platform and method for performing cybersecurity analyses employing an intelligence hub with a modular architecture |
US11271955B2 (en) | 2017-12-28 | 2022-03-08 | Fireeye Security Holdings Us Llc | Platform and method for retroactive reclassification employing a cybersecurity-based global data store |
US10826931B1 (en) | 2018-03-29 | 2020-11-03 | Fireeye, Inc. | System and method for predicting and mitigating cybersecurity system misconfigurations |
US11003773B1 (en) | 2018-03-30 | 2021-05-11 | Fireeye, Inc. | System and method for automatically generating malware detection rule recommendations |
US10956477B1 (en) | 2018-03-30 | 2021-03-23 | Fireeye, Inc. | System and method for detecting malicious scripts through natural language processing modeling |
US11558401B1 (en) | 2018-03-30 | 2023-01-17 | Fireeye Security Holdings Us Llc | Multi-vector malware detection data sharing system for improved detection |
US11314859B1 (en) | 2018-06-27 | 2022-04-26 | FireEye Security Holdings, Inc. | Cyber-security system and method for detecting escalation of privileges within an access token |
US11075930B1 (en) | 2018-06-27 | 2021-07-27 | Fireeye, Inc. | System and method for detecting repetitive cybersecurity attacks constituting an email campaign |
US11228491B1 (en) | 2018-06-28 | 2022-01-18 | Fireeye Security Holdings Us Llc | System and method for distributed cluster configuration monitoring and management |
US11316900B1 (en) | 2018-06-29 | 2022-04-26 | FireEye Security Holdings Inc. | System and method for automatically prioritizing rules for cyber-threat detection and mitigation |
US11182473B1 (en) | 2018-09-13 | 2021-11-23 | Fireeye Security Holdings Us Llc | System and method for mitigating cyberattacks against processor operability by a guest process |
US11763004B1 (en) | 2018-09-27 | 2023-09-19 | Fireeye Security Holdings Us Llc | System and method for bootkit detection |
US11093620B2 (en) * | 2018-11-02 | 2021-08-17 | ThreatConnect, Inc. | Ahead of time application launching for cybersecurity threat intelligence of network security events |
US11743290B2 (en) | 2018-12-21 | 2023-08-29 | Fireeye Security Holdings Us Llc | System and method for detecting cyberattacks impersonating legitimate sources |
US11176251B1 (en) | 2018-12-21 | 2021-11-16 | Fireeye, Inc. | Determining malware via symbolic function hash analysis |
US11368475B1 (en) | 2018-12-21 | 2022-06-21 | Fireeye Security Holdings Us Llc | System and method for scanning remote services to locate stored objects with malware |
US11601444B1 (en) | 2018-12-31 | 2023-03-07 | Fireeye Security Holdings Us Llc | Automated system for triage of customer issues |
US11550908B2 (en) * | 2019-03-15 | 2023-01-10 | Paul J Long | Method and apparatus for producing a machine learning system for malware prediction in low complexity sensor networks |
US11196766B2 (en) | 2019-03-21 | 2021-12-07 | Red Hat, Inc. | Detecting denial of service attacks in serverless computing |
US11310238B1 (en) | 2019-03-26 | 2022-04-19 | FireEye Security Holdings, Inc. | System and method for retrieval and analysis of operational data from customer, cloud-hosted virtual resources |
US11677786B1 (en) | 2019-03-29 | 2023-06-13 | Fireeye Security Holdings Us Llc | System and method for detecting and protecting against cybersecurity attacks on servers |
US11636198B1 (en) | 2019-03-30 | 2023-04-25 | Fireeye Security Holdings Us Llc | System and method for cybersecurity analyzer update and concurrent management system |
US11714905B2 (en) * | 2019-05-10 | 2023-08-01 | Sophos Limited | Attribute relevance tagging in malware recognition |
JP7131704B2 (en) * | 2019-05-28 | 2022-09-06 | 日本電信電話株式会社 | Extraction device, extraction method and extraction program |
US11258806B1 (en) | 2019-06-24 | 2022-02-22 | Mandiant, Inc. | System and method for automatically associating cybersecurity intelligence to cyberthreat actors |
US11556640B1 (en) | 2019-06-27 | 2023-01-17 | Mandiant, Inc. | Systems and methods for automated cybersecurity analysis of extracted binary string sets |
US11392700B1 (en) | 2019-06-28 | 2022-07-19 | Fireeye Security Holdings Us Llc | System and method for supporting cross-platform data verification |
US11886585B1 (en) | 2019-09-27 | 2024-01-30 | Musarubra Us Llc | System and method for identifying and mitigating cyberattacks through malicious position-independent code execution |
US11637862B1 (en) | 2019-09-30 | 2023-04-25 | Mandiant, Inc. | System and method for surfacing cyber-security threats with a self-learning recommendation engine |
DE102019134590A1 (en) * | 2019-12-16 | 2021-06-17 | Thomas Schmalz | Device for collecting IT forensically potentially relevant data, methods, computer program product and storage unit |
US11838300B1 (en) | 2019-12-24 | 2023-12-05 | Musarubra Us Llc | Run-time configurable cybersecurity system |
US11522884B1 (en) | 2019-12-24 | 2022-12-06 | Fireeye Security Holdings Us Llc | Subscription and key management system |
US11436327B1 (en) | 2019-12-24 | 2022-09-06 | Fireeye Security Holdings Us Llc | System and method for circumventing evasive code for cyberthreat detection |
US11863573B2 (en) | 2020-03-06 | 2024-01-02 | ThreatConnect, Inc. | Custom triggers for a network security event for cybersecurity threat intelligence |
CN113138966B (en) * | 2021-05-08 | 2023-06-06 | 贵州全安密灵科技有限公司 | Method, device, storage medium and equipment for reproducing detonation operation scene |
Citations (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20110167494A1 (en) * | 2009-12-31 | 2011-07-07 | Bowen Brian M | Methods, systems, and media for detecting covert malware |
Family Cites Families (634)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
DE2851871C2 (en) | 1978-11-30 | 1984-06-07 | Siemens AG, 1000 Berlin und 8000 München | Circuit arrangement for damping power fluctuations in networks |
GB9003890D0 (en) | 1990-02-21 | 1990-04-18 | Rodime Plc | Method and apparatus for controlling access to and corruption of information in computer systems |
US5319776A (en) | 1990-04-19 | 1994-06-07 | Hilgraeve Corporation | In transit detection of computer virus with safeguard |
US5175732A (en) | 1991-02-15 | 1992-12-29 | Standard Microsystems Corp. | Method and apparatus for controlling data communication operations within stations of a local-area network |
US5278901A (en) | 1992-04-30 | 1994-01-11 | International Business Machines Corporation | Pattern-oriented intrusion-detection system and method |
US5390325A (en) | 1992-12-23 | 1995-02-14 | Taligent, Inc. | Automated testing system |
US5440723A (en) | 1993-01-19 | 1995-08-08 | International Business Machines Corporation | Automatic immune system for computers and computer networks |
JP2501771B2 (en) | 1993-01-19 | 1996-05-29 | インターナショナル・ビジネス・マシーンズ・コーポレイション | Method and apparatus for obtaining multiple valid signatures of an unwanted software entity |
DE69511556D1 (en) | 1994-06-01 | 1999-09-23 | Quantum Leap Innovations Inc | COMPUTER VIRUS TRAP |
US5889973A (en) | 1995-03-31 | 1999-03-30 | Motorola, Inc. | Method and apparatus for selectively controlling interrupt latency in a data processing system |
GB2303947A (en) | 1995-07-31 | 1997-03-05 | Ibm | Boot sector virus protection in computer systems |
US7058822B2 (en) | 2000-03-30 | 2006-06-06 | Finjan Software, Ltd. | Malicious mobile code runtime monitoring system and methods |
US6154844A (en) | 1996-11-08 | 2000-11-28 | Finjan Software, Ltd. | System and method for attaching a downloadable security profile to a downloadable |
US6167520A (en) | 1996-11-08 | 2000-12-26 | Finjan Software, Inc. | System and method for protecting a client during runtime from hostile downloadables |
US6424627B1 (en) | 1997-02-24 | 2002-07-23 | Metrobility Optical Systems | Full-duplex medium tap apparatus and system |
US5960170A (en) | 1997-03-18 | 1999-09-28 | Trend Micro, Inc. | Event triggered iterative virus detection |
US6094677A (en) | 1997-05-30 | 2000-07-25 | International Business Machines Corporation | Methods, systems and computer program products for providing insertions during delays in interactive systems |
US5978917A (en) | 1997-08-14 | 1999-11-02 | Symantec Corporation | Detection and elimination of macro viruses |
US5983348A (en) | 1997-09-10 | 1999-11-09 | Trend Micro Incorporated | Computer network malicious code scanner |
US6357008B1 (en) | 1997-09-23 | 2002-03-12 | Symantec Corporation | Dynamic heuristic method for detecting computer viruses using decryption exploration and evaluation phases |
IL121898A0 (en) | 1997-10-07 | 1998-03-10 | Cidon Israel | A method and apparatus for active testing and fault allocation of communication networks |
US6417774B1 (en) | 1997-10-30 | 2002-07-09 | Fireeye Development Inc. | System and method for identifying unsafe temperature conditions |
US6118382A (en) | 1997-10-30 | 2000-09-12 | Fireeye Development, Incorporated | System and method for alerting safety personnel of unsafe air temperature conditions |
US6108799A (en) | 1997-11-21 | 2000-08-22 | International Business Machines Corporation | Automated sample creation of polymorphic and non-polymorphic marcro viruses |
US6088803A (en) | 1997-12-30 | 2000-07-11 | Intel Corporation | System for virus-checking network data during download to a client device |
US6088804A (en) | 1998-01-12 | 2000-07-11 | Motorola, Inc. | Adaptive system and method for responding to computer network security attacks |
US6279113B1 (en) | 1998-03-16 | 2001-08-21 | Internet Tools, Inc. | Dynamic signature inspection-based network intrusion detection |
US6298445B1 (en) | 1998-04-30 | 2001-10-02 | Netect, Ltd. | Computer security |
US7711714B2 (en) | 1998-09-22 | 2010-05-04 | Hitachi, Ltd. | Method and a device for sterilizing downloaded files |
US6550012B1 (en) | 1998-12-11 | 2003-04-15 | Network Associates, Inc. | Active firewall system and methodology |
US20060095274A1 (en) | 2004-05-07 | 2006-05-04 | Mark Phillips | Execution engine for business processes |
US6487666B1 (en) | 1999-01-15 | 2002-11-26 | Cisco Technology, Inc. | Intrusion detection signature analysis using regular expressions and logical operators |
US6484315B1 (en) | 1999-02-01 | 2002-11-19 | Cisco Technology, Inc. | Method and system for dynamically distributing updates in a network |
US20030191957A1 (en) | 1999-02-19 | 2003-10-09 | Ari Hypponen | Distributed computer virus detection and scanning |
US7240368B1 (en) | 1999-04-14 | 2007-07-03 | Verizon Corporate Services Group Inc. | Intrusion and misuse deterrence system employing a virtual network |
US6430691B1 (en) | 1999-06-21 | 2002-08-06 | Copytele, Inc. | Stand-alone telecommunications security device |
US6442696B1 (en) | 1999-10-05 | 2002-08-27 | Authoriszor, Inc. | System and method for extensible positive client identification |
US6493756B1 (en) | 1999-10-28 | 2002-12-10 | Networks Associates, Inc. | System and method for dynamically sensing an asynchronous network event within a modular framework for network event processing |
US7249175B1 (en) | 1999-11-23 | 2007-07-24 | Escom Corporation | Method and system for blocking e-mail having a nonexistent sender address |
US6775657B1 (en) | 1999-12-22 | 2004-08-10 | Cisco Technology, Inc. | Multilayered intrusion detection system and method |
GB2353372B (en) | 1999-12-24 | 2001-08-22 | F Secure Oyj | Remote computer virus scanning |
US6832367B1 (en) | 2000-03-06 | 2004-12-14 | International Business Machines Corporation | Method and system for recording and replaying the execution of distributed java programs |
US20010047326A1 (en) | 2000-03-14 | 2001-11-29 | Broadbent David F. | Interface system for a mortgage loan originator compliance engine |
US20040006473A1 (en) | 2002-07-02 | 2004-01-08 | Sbc Technology Resources, Inc. | Method and system for automated categorization of statements |
JP4944338B2 (en) | 2000-03-31 | 2012-05-30 | ユナイテッド ビデオ プロパティーズ インク | System and method for reducing cut-off in recording a program |
US6831893B1 (en) | 2000-04-03 | 2004-12-14 | P-Cube, Ltd. | Apparatus and method for wire-speed classification and pre-processing of data packets in a full duplex network |
US7080396B2 (en) | 2000-04-14 | 2006-07-18 | Lg Electronics Inc. | Event overrun and downstream event shift technology |
US7054943B1 (en) | 2000-04-28 | 2006-05-30 | International Business Machines Corporation | Method and apparatus for dynamically adjusting resources assigned to plurality of customers, for meeting service level agreements (slas) with minimal resources, and allowing common pools of resources to be used across plural customers on a demand basis |
EP1290558A1 (en) | 2000-05-19 | 2003-03-12 | Self Repairing Computers, Inc. | A computer with switchable components |
US7240364B1 (en) | 2000-05-20 | 2007-07-03 | Ciena Corporation | Network device identity authentication |
US6907396B1 (en) | 2000-06-01 | 2005-06-14 | Networks Associates Technology, Inc. | Detecting computer viruses or malicious software by patching instructions into an emulator |
US6971097B1 (en) | 2000-06-09 | 2005-11-29 | Sun Microsystems, Inc. | Method and apparatus for implementing concurrently running jobs on an extended virtual machine using different heaps managers |
US9444785B2 (en) | 2000-06-23 | 2016-09-13 | Cloudshield Technologies, Inc. | Transparent provisioning of network access to an application |
US7080407B1 (en) | 2000-06-27 | 2006-07-18 | Cisco Technology, Inc. | Virus detection and removal system and method for network-based systems |
US7093239B1 (en) | 2000-07-14 | 2006-08-15 | Internet Security Systems, Inc. | Computer immune system and method for detecting unwanted code in a computer system |
JP2002035109A (en) | 2000-07-21 | 2002-02-05 | Tadashi Kokubo | Anti-thrombotic material and method for manufacturing the same |
US6981279B1 (en) | 2000-08-17 | 2005-12-27 | International Business Machines Corporation | Method and apparatus for replicating and analyzing worm programs |
US20020038430A1 (en) | 2000-09-13 | 2002-03-28 | Charles Edwards | System and method of data collection, processing, analysis, and annotation for monitoring cyber-threats and the notification thereof to subscribers |
GB0022485D0 (en) | 2000-09-13 | 2000-11-01 | Apl Financial Services Oversea | Monitoring network activity |
US7496960B1 (en) | 2000-10-30 | 2009-02-24 | Trend Micro, Inc. | Tracking and reporting of computer virus information |
US20020091819A1 (en) | 2001-01-05 | 2002-07-11 | Daniel Melchione | System and method for configuring computer applications and devices using inheritance |
US20060047665A1 (en) | 2001-01-09 | 2006-03-02 | Tim Neil | System and method for simulating an application for subsequent deployment to a device in communication with a transaction server |
US20020095607A1 (en) | 2001-01-18 | 2002-07-18 | Catherine Lin-Hendel | Security protection for computers and computer-networks |
US7290283B2 (en) | 2001-01-31 | 2007-10-30 | Lancope, Inc. | Network port profiling |
GB0103416D0 (en) | 2001-02-12 | 2001-03-28 | Nokia Networks Oy | Message authentication |
US7281267B2 (en) | 2001-02-20 | 2007-10-09 | Mcafee, Inc. | Software audit system |
US20020166063A1 (en) | 2001-03-01 | 2002-11-07 | Cyber Operations, Llc | System and method for anti-network terrorism |
US20030074206A1 (en) | 2001-03-23 | 2003-04-17 | Restaurant Services, Inc. | System, method and computer program product for utilizing market demand information for generating revenue |
US7770223B2 (en) | 2001-04-12 | 2010-08-03 | Computer Associates Think, Inc. | Method and apparatus for security management via vicarious network devices |
CN1147795C (en) | 2001-04-29 | 2004-04-28 | 北京瑞星科技股份有限公司 | Method, system and medium for detecting and clearing known and anknown computer virus |
US7328453B2 (en) | 2001-05-09 | 2008-02-05 | Ecd Systems, Inc. | Systems and methods for the prevention of unauthorized use and manipulation of digital content |
US7043757B2 (en) | 2001-05-22 | 2006-05-09 | Mci, Llc | System and method for malicious code detection |
US20020194490A1 (en) | 2001-06-18 | 2002-12-19 | Avner Halperin | System and method of virus containment in computer networks |
US7657419B2 (en) | 2001-06-19 | 2010-02-02 | International Business Machines Corporation | Analytical virtual machine |
US7028179B2 (en) | 2001-07-03 | 2006-04-11 | Intel Corporation | Apparatus and method for secure, automated response to distributed denial of service attacks |
US20030021728A1 (en) | 2001-07-26 | 2003-01-30 | Sharpe Richard R. | Method of and apparatus for object-oriented real-time mechanical control of automated chemistry instruments |
US7861303B2 (en) | 2001-08-01 | 2010-12-28 | Mcafee, Inc. | Malware scanning wireless service agent system and method |
US20030033463A1 (en) | 2001-08-10 | 2003-02-13 | Garnett Paul J. | Computer system storage |
US8438241B2 (en) | 2001-08-14 | 2013-05-07 | Cisco Technology, Inc. | Detecting and protecting against worm traffic on a network |
US7356736B2 (en) | 2001-09-25 | 2008-04-08 | Norman Asa | Simulated computer system for monitoring of software performance |
US7107617B2 (en) | 2001-10-15 | 2006-09-12 | Mcafee, Inc. | Malware scanning of compressed computer files |
US20030074578A1 (en) | 2001-10-16 | 2003-04-17 | Richard Ford | Computer virus containment |
US7007107B1 (en) | 2001-10-22 | 2006-02-28 | United Electronic Industries | Methods and apparatus for performing data acquisition and control |
US20030084318A1 (en) | 2001-10-31 | 2003-05-01 | Schertz Richard L. | System and method of graphically correlating data for an intrusion protection system |
US7320142B1 (en) | 2001-11-09 | 2008-01-15 | Cisco Technology, Inc. | Method and system for configurable network intrusion detection |
US20030101381A1 (en) | 2001-11-29 | 2003-05-29 | Nikolay Mateev | System and method for virus checking software |
US7080408B1 (en) | 2001-11-30 | 2006-07-18 | Mcafee, Inc. | Delayed-delivery quarantining of network communications having suspicious contents |
US7512980B2 (en) | 2001-11-30 | 2009-03-31 | Lancope, Inc. | Packet sampling flow-based detection of network intrusions |
US7062553B2 (en) | 2001-12-04 | 2006-06-13 | Trend Micro, Inc. | Virus epidemic damage control system and method for network environment |
US6895550B2 (en) | 2001-12-05 | 2005-05-17 | I2 Technologies Us, Inc. | Computer-implemented PDF document management |
US7093002B2 (en) | 2001-12-06 | 2006-08-15 | Mcafee, Inc. | Handling of malware scanning of files stored within a file storage device of a computer network |
NZ516346A (en) | 2001-12-21 | 2004-09-24 | Esphion Ltd | A device for evaluating traffic on a computer network to detect traffic abnormalities such as a denial of service attack |
US7607171B1 (en) | 2002-01-17 | 2009-10-20 | Avinti, Inc. | Virus detection by executing e-mail code in a virtual machine |
US7100201B2 (en) | 2002-01-24 | 2006-08-29 | Arxceo Corporation | Undetectable firewall |
US7448084B1 (en) | 2002-01-25 | 2008-11-04 | The Trustees Of Columbia University In The City Of New York | System and methods for detecting intrusions in a computer system by monitoring operating system registry accesses |
JP4593926B2 (en) | 2002-02-19 | 2010-12-08 | ポスティーニ インク | Email management service |
US7069316B1 (en) | 2002-02-19 | 2006-06-27 | Mcafee, Inc. | Automated Internet Relay Chat malware monitoring and interception |
JP3713491B2 (en) | 2002-02-28 | 2005-11-09 | 株式会社エヌ・ティ・ティ・ドコモ | Server apparatus and information processing method |
US7458098B2 (en) | 2002-03-08 | 2008-11-25 | Secure Computing Corporation | Systems and methods for enhancing electronic communication security |
US7693947B2 (en) | 2002-03-08 | 2010-04-06 | Mcafee, Inc. | Systems and methods for graphically displaying messaging traffic |
US20030172291A1 (en) | 2002-03-08 | 2003-09-11 | Paul Judge | Systems and methods for automated whitelisting in monitored communications |
US20030188190A1 (en) | 2002-03-26 | 2003-10-02 | Aaron Jeffrey A. | System and method of intrusion detection employing broad-scope monitoring |
US20040111632A1 (en) | 2002-05-06 | 2004-06-10 | Avner Halperin | System and method of virus containment in computer networks |
US7237008B1 (en) | 2002-05-10 | 2007-06-26 | Mcafee, Inc. | Detecting malware carried by an e-mail message |
US7370360B2 (en) | 2002-05-13 | 2008-05-06 | International Business Machines Corporation | Computer immune system and method for detecting unwanted code in a P-code or partially compiled native-code program executing within a virtual machine |
US6995665B2 (en) | 2002-05-17 | 2006-02-07 | Fireeye Development Incorporated | System and method for identifying, monitoring and evaluating equipment, environmental and physiological conditions |
GB2394382A (en) | 2002-10-19 | 2004-04-21 | Hewlett Packard Co | Monitoring the propagation of viruses through an Information Technology network |
US7415723B2 (en) | 2002-06-11 | 2008-08-19 | Pandya Ashish A | Distributed network security system and a hardware processor therefor |
US20060190561A1 (en) | 2002-06-19 | 2006-08-24 | Watchfire Corporation | Method and system for obtaining script related information for website crawling |
US8539580B2 (en) | 2002-06-19 | 2013-09-17 | International Business Machines Corporation | Method, system and program product for detecting intrusion of a wireless network |
US8423374B2 (en) | 2002-06-27 | 2013-04-16 | Siebel Systems, Inc. | Method and system for processing intelligence information |
US7124327B2 (en) | 2002-06-29 | 2006-10-17 | Intel Corporation | Control over faults occurring during the operation of guest software in the virtual-machine architecture |
US8788650B1 (en) | 2002-07-19 | 2014-07-22 | Fortinet, Inc. | Hardware based detection devices for detecting network traffic content and methods of using the same |
US7418729B2 (en) | 2002-07-19 | 2008-08-26 | Symantec Corporation | Heuristic detection of malicious computer code by page tracking |
US7487543B2 (en) | 2002-07-23 | 2009-02-03 | International Business Machines Corporation | Method and apparatus for the automatic determination of potentially worm-like behavior of a program |
JP3794491B2 (en) | 2002-08-20 | 2006-07-05 | 日本電気株式会社 | Attack defense system and attack defense method |
US20040047356A1 (en) | 2002-09-06 | 2004-03-11 | Bauer Blaine D. | Network traffic monitoring |
US7467408B1 (en) | 2002-09-09 | 2008-12-16 | Cisco Technology, Inc. | Method and apparatus for capturing and filtering datagrams for network security monitoring |
GB0220907D0 (en) | 2002-09-10 | 2002-10-16 | Ingenia Holdings Ltd | Security device and system |
US8909926B2 (en) | 2002-10-21 | 2014-12-09 | Rockwell Automation Technologies, Inc. | System and methodology providing automation security analysis, validation, and learning in an industrial controller environment |
US7159149B2 (en) | 2002-10-24 | 2007-01-02 | Symantec Corporation | Heuristic detection and termination of fast spreading network worm attacks |
US8090809B2 (en) | 2002-11-04 | 2012-01-03 | Riverbed Technology, Inc. | Role grouping |
US20050033989A1 (en) | 2002-11-04 | 2005-02-10 | Poletto Massimiliano Antonio | Detection of scanning attacks |
US7774839B2 (en) | 2002-11-04 | 2010-08-10 | Riverbed Technology, Inc. | Feedback mechanism to minimize false assertions of a network intrusion |
US8504879B2 (en) | 2002-11-04 | 2013-08-06 | Riverbed Technology, Inc. | Connection based anomaly detection |
US7353539B2 (en) | 2002-11-04 | 2008-04-01 | Hewlett-Packard Development Company, L.P. | Signal level propagation mechanism for distribution of a payload to vulnerable systems |
US7363656B2 (en) | 2002-11-04 | 2008-04-22 | Mazu Networks, Inc. | Event detection/anomaly correlation heuristics |
US7454499B2 (en) | 2002-11-07 | 2008-11-18 | Tippingpoint Technologies, Inc. | Active network defense system and method |
US20040111531A1 (en) | 2002-12-06 | 2004-06-10 | Stuart Staniford | Method and system for reducing the rate of infection of a communications network by a software worm |
US7428300B1 (en) | 2002-12-09 | 2008-09-23 | Verizon Laboratories Inc. | Diagnosing fault patterns in telecommunication networks |
US20040128355A1 (en) | 2002-12-25 | 2004-07-01 | Kuo-Jen Chao | Community-based message classification and self-amending system for a messaging system |
US7519057B2 (en) | 2003-02-18 | 2009-04-14 | Broadcom Corporation | System and method for communicating using a multiserver platform |
US7546638B2 (en) | 2003-03-18 | 2009-06-09 | Symantec Corporation | Automated identification and clean-up of malicious computer code |
US6898632B2 (en) | 2003-03-31 | 2005-05-24 | Finisar Corporation | Network security tap for use with intrusion detection system |
US7949785B2 (en) | 2003-03-31 | 2011-05-24 | Inpro Network Facility, Llc | Secure virtual community network system |
US7607010B2 (en) | 2003-04-12 | 2009-10-20 | Deep Nines, Inc. | System and method for network edge data protection |
US8640234B2 (en) | 2003-05-07 | 2014-01-28 | Trustwave Holdings, Inc. | Method and apparatus for predictive and actual intrusion detection on a network |
US7464404B2 (en) | 2003-05-20 | 2008-12-09 | International Business Machines Corporation | Method of responding to a truncated secure session attack |
US7308716B2 (en) | 2003-05-20 | 2007-12-11 | International Business Machines Corporation | Applying blocking measures progressively to malicious network traffic |
US7543051B2 (en) | 2003-05-30 | 2009-06-02 | Borland Software Corporation | Method of non-intrusive analysis of secure and non-secure web application traffic in real-time |
US7231667B2 (en) | 2003-05-29 | 2007-06-12 | Computer Associates Think, Inc. | System and method for computer virus detection utilizing heuristic analysis |
US20050108562A1 (en) | 2003-06-18 | 2005-05-19 | Khazan Roger I. | Technique for detecting executable malicious code using a combination of static and dynamic analyses |
JP4734240B2 (en) | 2003-06-18 | 2011-07-27 | インテリシンク コーポレイション | System and method for providing notification to a remote device |
US8627457B2 (en) | 2003-06-30 | 2014-01-07 | Verizon Business Global Llc | Integrated security system |
US7392543B2 (en) | 2003-06-30 | 2008-06-24 | Symantec Corporation | Signature extraction system and method |
US20070256132A2 (en) | 2003-07-01 | 2007-11-01 | Securityprofiling, Inc. | Vulnerability and remediation database |
US20050050337A1 (en) | 2003-08-29 | 2005-03-03 | Trend Micro Incorporated, A Japanese Corporation | Anti-virus security policy enforcement |
US7392542B2 (en) | 2003-08-29 | 2008-06-24 | Seagate Technology Llc | Restoration of data corrupted by viruses using pre-infected copy of data |
KR100432675B1 (en) | 2003-09-19 | 2004-05-27 | 주식회사 아이앤아이맥스 | Method of controlling communication between equipments on a network and apparatus for the same |
US7644441B2 (en) | 2003-09-26 | 2010-01-05 | Cigital, Inc. | Methods for identifying malicious software |
WO2006109236A2 (en) | 2005-04-13 | 2006-10-19 | Netmask (El-Mar) Internet Technologies Ltd. | Dynamic content conversion |
US7496961B2 (en) | 2003-10-15 | 2009-02-24 | Intel Corporation | Methods and apparatus to provide network traffic support and physical security support |
US7694328B2 (en) | 2003-10-21 | 2010-04-06 | Google Inc. | Systems and methods for secure client applications |
US7584455B2 (en) | 2003-10-23 | 2009-09-01 | Microsoft Corporation | Predicate-based test coverage and generation |
JP4051020B2 (en) | 2003-10-28 | 2008-02-20 | 富士通株式会社 | Worm determination program, computer-readable storage medium storing worm determination program, worm determination method, and worm determination device |
US7421689B2 (en) | 2003-10-28 | 2008-09-02 | Hewlett-Packard Development Company, L.P. | Processor-architecture for facilitating a virtual machine monitor |
JP3999188B2 (en) | 2003-10-28 | 2007-10-31 | 富士通株式会社 | Unauthorized access detection device, unauthorized access detection method, and unauthorized access detection program |
WO2005050369A2 (en) | 2003-11-12 | 2005-06-02 | The Trustees Of Columbia University In The City Ofnew York | Apparatus method and medium for detecting payload anomaly using n-gram distribution of normal data |
US20050114710A1 (en) | 2003-11-21 | 2005-05-26 | Finisar Corporation | Host bus adapter for secure network devices |
US20050201297A1 (en) | 2003-12-12 | 2005-09-15 | Cyrus Peikari | Diagnosis of embedded, wireless mesh networks with real-time, flexible, location-specific signaling |
US7325251B1 (en) | 2003-12-16 | 2008-01-29 | Symantec Corporation | Method and system to prevent peer-to-peer (P2P) worms |
WO2005071923A1 (en) | 2004-01-20 | 2005-08-04 | Intrusic, Inc | Systems and methods for monitoring data transmissions to detect a compromised network |
ATE526628T1 (en) | 2004-01-22 | 2011-10-15 | Nec Lab America Inc | SYSTEM AND METHOD FOR MODELING, ABSTRACTING AND ANALYZING SOFTWARE |
US7610627B1 (en) | 2004-01-23 | 2009-10-27 | Acxiom Corporation | Secure data exchange technique |
US8220055B1 (en) | 2004-02-06 | 2012-07-10 | Symantec Corporation | Behavior blocking utilizing positive behavior system and method |
US7530104B1 (en) | 2004-02-09 | 2009-05-05 | Symantec Corporation | Threat analysis |
US20050183143A1 (en) | 2004-02-13 | 2005-08-18 | Anderholm Eric J. | Methods and systems for monitoring user, application or device activity |
US20060064721A1 (en) | 2004-03-10 | 2006-03-23 | Techfoundries, Inc. | Method and apparatus for implementing a synchronized electronic program guide application |
US9106694B2 (en) | 2004-04-01 | 2015-08-11 | Fireeye, Inc. | Electronic message analysis for malware detection |
US8881282B1 (en) | 2004-04-01 | 2014-11-04 | Fireeye, Inc. | Systems and methods for malware attack detection and identification |
US8566946B1 (en) | 2006-04-20 | 2013-10-22 | Fireeye, Inc. | Malware containment on connection |
US8375444B2 (en) | 2006-04-20 | 2013-02-12 | Fireeye, Inc. | Dynamic signature creation and enforcement |
US7587537B1 (en) | 2007-11-30 | 2009-09-08 | Altera Corporation | Serializer-deserializer circuits formed from input-output circuit registers |
US8793787B2 (en) | 2004-04-01 | 2014-07-29 | Fireeye, Inc. | Detecting malicious network content using virtual environment components |
US8561177B1 (en) | 2004-04-01 | 2013-10-15 | Fireeye, Inc. | Systems and methods for detecting communication channels of bots |
US8549638B2 (en) | 2004-06-14 | 2013-10-01 | Fireeye, Inc. | System and method of containing computer worms |
US8528086B1 (en) | 2004-04-01 | 2013-09-03 | Fireeye, Inc. | System and method of detecting computer worms |
US8898788B1 (en) | 2004-04-01 | 2014-11-25 | Fireeye, Inc. | Systems and methods for malware attack prevention |
US8006305B2 (en) | 2004-06-14 | 2011-08-23 | Fireeye, Inc. | Computer worm defense system and method |
US8204984B1 (en) | 2004-04-01 | 2012-06-19 | Fireeye, Inc. | Systems and methods for detecting encrypted bot command and control communication channels |
US8539582B1 (en) | 2004-04-01 | 2013-09-17 | Fireeye, Inc. | Malware containment and security analysis on connection |
US9027135B1 (en) | 2004-04-01 | 2015-05-05 | Fireeye, Inc. | Prospective client identification using malware attack detection |
US8584239B2 (en) | 2004-04-01 | 2013-11-12 | Fireeye, Inc. | Virtual machine with dynamic data flow analysis |
US8171553B2 (en) | 2004-04-01 | 2012-05-01 | Fireeye, Inc. | Heuristic based capture with replay to virtual machine |
US7966658B2 (en) | 2004-04-08 | 2011-06-21 | The Regents Of The University Of California | Detecting public network attacks using signatures and fast content analysis |
US7533415B2 (en) | 2004-04-21 | 2009-05-12 | Trend Micro Incorporated | Method and apparatus for controlling traffic in a computer network |
US20050240781A1 (en) | 2004-04-22 | 2005-10-27 | Gassoway Paul A | Prioritizing intrusion detection logs |
US7779463B2 (en) | 2004-05-11 | 2010-08-17 | The Trustees Of Columbia University In The City Of New York | Systems and methods for correlating and distributing intrusion alert information among collaborating computer systems |
WO2005114955A1 (en) | 2004-05-21 | 2005-12-01 | Computer Associates Think, Inc. | Systems and methods of computer security |
US7441272B2 (en) | 2004-06-09 | 2008-10-21 | Intel Corporation | Techniques for self-isolation of networked devices |
US20050278178A1 (en) | 2004-06-10 | 2005-12-15 | International Business Machines Corporation | System and method for intrusion decision-making in autonomic computing environments |
US7908653B2 (en) | 2004-06-29 | 2011-03-15 | Intel Corporation | Method of improving computer security through sandboxing |
US20060010495A1 (en) | 2004-07-06 | 2006-01-12 | Oded Cohen | Method for protecting a computer from suspicious objects |
US20070271446A1 (en) | 2004-07-16 | 2007-11-22 | Tomonori Nakamura | Application Execution Device and Application Execution Device Application Execution Method |
US20060015715A1 (en) | 2004-07-16 | 2006-01-19 | Eric Anderson | Automatically protecting network service from network attack |
US7444521B2 (en) | 2004-07-16 | 2008-10-28 | Red Hat, Inc. | System and method for detecting computer virus |
US7603715B2 (en) | 2004-07-21 | 2009-10-13 | Microsoft Corporation | Containment of worms |
US20060031476A1 (en) | 2004-08-05 | 2006-02-09 | Mathes Marvin L | Apparatus and method for remotely monitoring a computer network |
US7949849B2 (en) | 2004-08-24 | 2011-05-24 | Mcafee, Inc. | File system for a capture system |
US8214901B2 (en) | 2004-09-17 | 2012-07-03 | Sri International | Method and apparatus for combating malicious code |
US7434261B2 (en) | 2004-09-27 | 2008-10-07 | Microsoft Corporation | System and method of identifying the source of an attack on a computer network |
US7478428B1 (en) | 2004-10-12 | 2009-01-13 | Microsoft Corporation | Adapting input to find integer overflows |
US7849506B1 (en) | 2004-10-12 | 2010-12-07 | Avaya Inc. | Switching device, method, and computer program for efficient intrusion detection |
US20060101516A1 (en) | 2004-10-12 | 2006-05-11 | Sushanthan Sudaharan | Honeynet farms as an early warning system for production networks |
US7610375B2 (en) | 2004-10-28 | 2009-10-27 | Cisco Technology, Inc. | Intrusion detection in a data center environment |
US20060101517A1 (en) | 2004-10-28 | 2006-05-11 | Banzhof Carl E | Inventory management-based computer vulnerability resolution system |
CA2585145A1 (en) | 2004-11-04 | 2007-01-04 | Telcordia Technologies, Inc. | Detecting exploit code in network flows |
US20060101277A1 (en) | 2004-11-10 | 2006-05-11 | Meenan Patrick A | Detecting and remedying unauthorized computer programs |
US7540025B2 (en) | 2004-11-18 | 2009-05-26 | Cisco Technology, Inc. | Mitigating network attacks using automatic signature generation |
US7784097B1 (en) | 2004-11-24 | 2010-08-24 | The Trustees Of Columbia University In The City Of New York | Systems and methods for correlating and distributing intrusion alert information among collaborating computer systems |
US20060117385A1 (en) | 2004-11-30 | 2006-06-01 | Mester Michael L | Monitoring propagation protection within a network |
US7941856B2 (en) | 2004-12-06 | 2011-05-10 | Wisconsin Alumni Research Foundation | Systems and methods for testing and evaluating an intrusion detection system |
US7987272B2 (en) | 2004-12-06 | 2011-07-26 | Cisco Technology, Inc. | Performing message payload processing functions in a network element on behalf of an application |
US20060161989A1 (en) | 2004-12-13 | 2006-07-20 | Eran Reshef | System and method for deterring rogue users from attacking protected legitimate users |
US7937761B1 (en) | 2004-12-17 | 2011-05-03 | Symantec Corporation | Differential threat detection processing |
US20060143709A1 (en) | 2004-12-27 | 2006-06-29 | Raytheon Company | Network intrusion prevention |
US7725938B2 (en) | 2005-01-20 | 2010-05-25 | Cisco Technology, Inc. | Inline intrusion detection |
US20060164199A1 (en) | 2005-01-26 | 2006-07-27 | Lockdown Networks, Inc. | Network appliance for securely quarantining a node on a network |
US7676841B2 (en) | 2005-02-01 | 2010-03-09 | Fmr Llc | Network intrusion mitigation |
US7668962B2 (en) | 2005-02-07 | 2010-02-23 | Symantec Operating Corporation | System and method for connection failover using redirection |
US7904518B2 (en) | 2005-02-15 | 2011-03-08 | Gytheion Networks Llc | Apparatus and method for analyzing and filtering email and for providing web related services |
US7784099B2 (en) | 2005-02-18 | 2010-08-24 | Pace University | System for intrusion detection and vulnerability assessment in a computer network using simulation and machine learning |
US7836504B2 (en) | 2005-03-01 | 2010-11-16 | Microsoft Corporation | On-access scan of memory for malware |
JP2006270193A (en) | 2005-03-22 | 2006-10-05 | Fuji Xerox Co Ltd | Image forming system and method, and image forming apparatus |
US7650639B2 (en) | 2005-03-31 | 2010-01-19 | Microsoft Corporation | System and method for protecting a limited resource computer from malware |
JP4630706B2 (en) | 2005-03-31 | 2011-02-09 | 富士通株式会社 | Service device, client device connection destination switching control method and program by service device |
US20060221956A1 (en) | 2005-03-31 | 2006-10-05 | Narayan Harsha L | Methods for performing packet classification via prefix pair bit vectors |
US7568233B1 (en) | 2005-04-01 | 2009-07-28 | Symantec Corporation | Detecting malicious software through process dump scanning |
WO2006107712A2 (en) | 2005-04-04 | 2006-10-12 | Bae Systems Information And Electronic Systems Integration Inc. | Method and apparatus for defending against zero-day worm-based attacks |
EP1872222A1 (en) | 2005-04-18 | 2008-01-02 | The Trustees of Columbia University in the City of New York | Systems and methods for detecting and inhibiting attacks using honeypots |
US7603712B2 (en) | 2005-04-21 | 2009-10-13 | Microsoft Corporation | Protecting a computer that provides a Web service from malware |
US8069250B2 (en) | 2005-04-28 | 2011-11-29 | Vmware, Inc. | One-way proxy system |
US7480773B1 (en) | 2005-05-02 | 2009-01-20 | Sprint Communications Company L.P. | Virtual machine use and optimization of hardware configurations |
US7493602B2 (en) | 2005-05-02 | 2009-02-17 | International Business Machines Corporation | Methods and arrangements for unified program analysis |
EP1877905B1 (en) | 2005-05-05 | 2014-10-22 | Cisco IronPort Systems LLC | Identifying threats in electronic messages |
US7930738B1 (en) | 2005-06-02 | 2011-04-19 | Adobe Systems Incorporated | Method and apparatus for secure execution of code |
ATE459184T1 (en) | 2005-06-06 | 2010-03-15 | Ibm | SYSTEM AND METHOD FOR DETECTING INTRUSIONS INTO A COMPUTER NETWORK |
US7490355B2 (en) | 2005-06-16 | 2009-02-10 | Chung Shan Institute Of Science And Technology | Method of detecting network worms |
US20060288417A1 (en) | 2005-06-21 | 2006-12-21 | Sbc Knowledge Ventures Lp | Method and apparatus for mitigating the effects of malicious software in a communication network |
US7877803B2 (en) | 2005-06-27 | 2011-01-25 | Hewlett-Packard Development Company, L.P. | Automated immune response for a computer |
US7636938B2 (en) | 2005-06-30 | 2009-12-22 | Microsoft Corporation | Controlling network access |
US20070016951A1 (en) | 2005-07-13 | 2007-01-18 | Piccard Paul L | Systems and methods for identifying sources of malware |
JP2007025422A (en) | 2005-07-20 | 2007-02-01 | Alps Electric Co Ltd | Wavelength branching filter and optical communication module |
US7984493B2 (en) | 2005-07-22 | 2011-07-19 | Alcatel-Lucent | DNS based enforcement for confinement and detection of network malicious activities |
US7818800B1 (en) | 2005-08-05 | 2010-10-19 | Symantec Corporation | Method, system, and computer program product for blocking malicious program behaviors |
US7797387B2 (en) | 2005-08-15 | 2010-09-14 | Cisco Technology, Inc. | Interactive text communication system |
US8468604B2 (en) | 2005-08-16 | 2013-06-18 | Emc Corporation | Method and system for detecting malware |
WO2007025279A2 (en) | 2005-08-25 | 2007-03-01 | Fortify Software, Inc. | Apparatus and method for analyzing and supplementing a program to provide security |
US8117045B2 (en) | 2005-09-12 | 2012-02-14 | Mymedicalrecords.Com, Inc. | Method and system for providing online medical records |
US7739740B1 (en) | 2005-09-22 | 2010-06-15 | Symantec Corporation | Detecting polymorphic threats |
US7725737B2 (en) | 2005-10-14 | 2010-05-25 | Check Point Software Technologies, Inc. | System and methodology providing secure workspace environment |
US7730011B1 (en) | 2005-10-19 | 2010-06-01 | Mcafee, Inc. | Attributes of captured objects in a capture system |
CN100428157C (en) | 2005-10-19 | 2008-10-22 | 联想(北京)有限公司 | A computer system and method to check completely |
US7971256B2 (en) | 2005-10-20 | 2011-06-28 | Cisco Technology, Inc. | Mechanism to correlate the presence of worms in a network |
US9055093B2 (en) | 2005-10-21 | 2015-06-09 | Kevin R. Borders | Method, system and computer program product for detecting at least one of security threats and undesirable computer files |
WO2007050244A2 (en) | 2005-10-27 | 2007-05-03 | Georgia Tech Research Corporation | Method and system for detecting and responding to attacking networks |
KR100735411B1 (en) | 2005-12-07 | 2007-07-04 | 삼성전기주식회사 | Method For Forming Printed Wiring Board and Printed Wiring Board Thus Obtained |
US7698548B2 (en) | 2005-12-08 | 2010-04-13 | Microsoft Corporation | Communications traffic segregation for security purposes |
US7577424B2 (en) | 2005-12-19 | 2009-08-18 | Airdefense, Inc. | Systems and methods for wireless vulnerability analysis |
US20070143827A1 (en) | 2005-12-21 | 2007-06-21 | Fiberlink | Methods and systems for intelligently controlling access to computing resources |
US20080018122A1 (en) | 2005-12-28 | 2008-01-24 | Robert Zierler | Rifle Sling and Method of Use Thereof |
US7849143B2 (en) | 2005-12-29 | 2010-12-07 | Research In Motion Limited | System and method of dynamic management of spam |
US8533680B2 (en) | 2005-12-30 | 2013-09-10 | Microsoft Corporation | Approximating finite domains in symbolic state exploration |
US8255996B2 (en) | 2005-12-30 | 2012-08-28 | Extreme Networks, Inc. | Network threat detection and mitigation |
WO2007076624A1 (en) | 2005-12-30 | 2007-07-12 | Intel Corporation | Virtual machine to detect malicious code |
US8209667B2 (en) | 2006-01-11 | 2012-06-26 | International Business Machines Corporation | Software verification using hybrid explicit and symbolic model checking |
US7450005B2 (en) | 2006-01-18 | 2008-11-11 | International Business Machines Corporation | System and method of dynamically weighted analysis for intrusion decision-making |
US8196205B2 (en) | 2006-01-23 | 2012-06-05 | University Of Washington Through Its Center For Commercialization | Detection of spyware threats within virtual machine |
US8018845B2 (en) | 2006-01-25 | 2011-09-13 | Cisco Technology, Inc | Sampling rate-limited traffic |
US20070192858A1 (en) | 2006-02-16 | 2007-08-16 | Infoexpress, Inc. | Peer based network access control |
US20070192500A1 (en) | 2006-02-16 | 2007-08-16 | Infoexpress, Inc. | Network access control including dynamic policy enforcement point |
US8176480B1 (en) | 2006-02-27 | 2012-05-08 | Symantec Operating Corporation | Adaptive instrumentation through dynamic recompilation |
US8381299B2 (en) | 2006-02-28 | 2013-02-19 | The Trustees Of Columbia University In The City Of New York | Systems, methods, and media for outputting a dataset based upon anomaly detection |
US7774459B2 (en) | 2006-03-01 | 2010-08-10 | Microsoft Corporation | Honey monkey network exploration |
JP4897520B2 (en) | 2006-03-20 | 2012-03-14 | 株式会社リコー | Information distribution system |
US8443446B2 (en) | 2006-03-27 | 2013-05-14 | Telecom Italia S.P.A. | Method and system for identifying malicious messages in mobile communication networks, related network and computer program product therefor |
US9171157B2 (en) | 2006-03-28 | 2015-10-27 | Blue Coat Systems, Inc. | Method and system for tracking access to application data and preventing data exploitation by malicious programs |
US7757112B2 (en) | 2006-03-29 | 2010-07-13 | Lenovo (Singapore) Pte. Ltd. | System and method for booting alternate MBR in event of virus attack |
US8479174B2 (en) | 2006-04-05 | 2013-07-02 | Prevx Limited | Method, computer program and computer for analyzing an executable computer file |
WO2007117567A2 (en) | 2006-04-06 | 2007-10-18 | Smobile Systems Inc. | Malware detection system and method for limited access mobile platforms |
US8510827B1 (en) | 2006-05-18 | 2013-08-13 | Vmware, Inc. | Taint tracking mechanism for computer security |
US8261344B2 (en) | 2006-06-30 | 2012-09-04 | Sophos Plc | Method and system for classification of software using characteristics and combinations of such characteristics |
US8365286B2 (en) | 2006-06-30 | 2013-01-29 | Sophos Plc | Method and system for classification of software using characteristics and combinations of such characteristics |
US8020206B2 (en) | 2006-07-10 | 2011-09-13 | Websense, Inc. | System and method of analyzing web content |
DE202006011850U1 (en) | 2006-08-02 | 2006-10-05 | Harting Electric Gmbh & Co. Kg | Contact element for screened plug connector linking screen of electric cable to plug connector has sectionally openable conductive wall segment of cable support part in free section |
US7870612B2 (en) | 2006-09-11 | 2011-01-11 | Fujian Eastern Micropoint Info-Tech Co., Ltd | Antivirus protection system and method for computers |
US8291198B2 (en) | 2006-09-11 | 2012-10-16 | Samsung Electronics Co., Ltd. | Apparatus and method for regulating bursty data in a signal processing pipeline |
US8789172B2 (en) | 2006-09-18 | 2014-07-22 | The Trustees Of Columbia University In The City Of New York | Methods, media, and systems for detecting attack on a digital processing device |
US20080077793A1 (en) | 2006-09-21 | 2008-03-27 | Sensory Networks, Inc. | Apparatus and method for high throughput network security systems |
US8533819B2 (en) | 2006-09-29 | 2013-09-10 | At&T Intellectual Property Ii, L.P. | Method and apparatus for detecting compromised host computers |
CN101542452B (en) | 2006-10-04 | 2016-04-20 | 特科2000国际有限公司 | The authentication method of External memory equipment, equipment and system |
DE102006047979B4 (en) | 2006-10-10 | 2009-07-16 | OCé PRINTING SYSTEMS GMBH | A data processing system, method and computer program product for executing a test routine in conjunction with an operating system |
US7832008B1 (en) | 2006-10-11 | 2010-11-09 | Cisco Technology, Inc. | Protection of computer resources |
US8234640B1 (en) | 2006-10-17 | 2012-07-31 | Manageiq, Inc. | Compliance-based adaptations in managed virtual systems |
US8949826B2 (en) | 2006-10-17 | 2015-02-03 | Managelq, Inc. | Control and management of virtual systems |
US8042184B1 (en) | 2006-10-18 | 2011-10-18 | Kaspersky Lab, Zao | Rapid analysis of data stream for malware presence |
US20080141376A1 (en) | 2006-10-24 | 2008-06-12 | Pc Tools Technology Pty Ltd. | Determining maliciousness of software |
US8656495B2 (en) | 2006-11-17 | 2014-02-18 | Hewlett-Packard Development Company, L.P. | Web application assessment based on intelligent generation of attack strings |
KR100922579B1 (en) | 2006-11-30 | 2009-10-21 | 한국전자통신연구원 | Apparatus and method for detecting network attack |
GB2444514A (en) | 2006-12-04 | 2008-06-11 | Glasswall | Electronic file re-generation |
KR101206542B1 (en) | 2006-12-18 | 2012-11-30 | 주식회사 엘지씨엔에스 | Apparatus and method of securing network of supporting detection and interception of dynamic attack based hardware |
US8904535B2 (en) | 2006-12-20 | 2014-12-02 | The Penn State Research Foundation | Proactive worm containment (PWC) for enterprise networks |
EP1936532B1 (en) | 2006-12-21 | 2009-07-29 | Telefonaktiebolaget LM Ericsson (publ) | Obfuscating computer program code |
CN101573653B (en) | 2006-12-26 | 2011-03-16 | 夏普株式会社 | Backlight device, display, and TV receiver |
US7996836B1 (en) | 2006-12-29 | 2011-08-09 | Symantec Corporation | Using a hypervisor to provide computer security |
US8380987B2 (en) | 2007-01-25 | 2013-02-19 | Microsoft Corporation | Protection agents and privilege modes |
US8069484B2 (en) | 2007-01-25 | 2011-11-29 | Mandiant Corporation | System and method for determining data entropy to identify malware |
US8391288B2 (en) | 2007-01-31 | 2013-03-05 | Hewlett-Packard Development Company, L.P. | Security system for protecting networks from vulnerability exploits |
US7908660B2 (en) | 2007-02-06 | 2011-03-15 | Microsoft Corporation | Dynamic risk management |
US20080201778A1 (en) | 2007-02-21 | 2008-08-21 | Matsushita Electric Industrial Co., Ltd. | Intrusion detection using system call monitors on a bayesian network |
US9021590B2 (en) | 2007-02-28 | 2015-04-28 | Microsoft Technology Licensing, Llc | Spyware detection mechanism |
US20080222729A1 (en) | 2007-03-05 | 2008-09-11 | Songqing Chen | Containment of Unknown and Polymorphic Fast Spreading Worms |
US8392997B2 (en) | 2007-03-12 | 2013-03-05 | University Of Southern California | Value-adaptive security threat modeling and vulnerability ranking |
US20080320594A1 (en) | 2007-03-19 | 2008-12-25 | Xuxian Jiang | Malware Detector |
US9083712B2 (en) | 2007-04-04 | 2015-07-14 | Sri International | Method and apparatus for generating highly predictive blacklists |
US8955122B2 (en) | 2007-04-04 | 2015-02-10 | Sri International | Method and apparatus for detecting malware infection |
US7904961B2 (en) | 2007-04-20 | 2011-03-08 | Juniper Networks, Inc. | Network attack detection using partial deterministic finite automaton pattern matching |
US20080295172A1 (en) | 2007-05-22 | 2008-11-27 | Khushboo Bohacek | Method, system and computer-readable media for reducing undesired intrusion alarms in electronic communications systems and networks |
IL183390A0 (en) | 2007-05-24 | 2007-09-20 | Deutsche Telekom Ag | Distributed system for the detection |
US8402529B1 (en) | 2007-05-30 | 2013-03-19 | M86 Security, Inc. | Preventing propagation of malicious software during execution in a virtual machine |
GB2449852A (en) | 2007-06-04 | 2008-12-10 | Agilent Technologies Inc | Monitoring network attacks using pattern matching |
US7853689B2 (en) | 2007-06-15 | 2010-12-14 | Broadcom Corporation | Multi-stage deep packet inspection for lightweight devices |
US20090007100A1 (en) | 2007-06-28 | 2009-01-01 | Microsoft Corporation | Suspending a Running Operating System to Enable Security Scanning |
US8135007B2 (en) | 2007-06-29 | 2012-03-13 | Extreme Networks, Inc. | Method and mechanism for port redirects in a network switch |
US8584094B2 (en) | 2007-06-29 | 2013-11-12 | Microsoft Corporation | Dynamically computing reputation scores for objects |
US7836502B1 (en) | 2007-07-03 | 2010-11-16 | Trend Micro Inc. | Scheduled gateway scanning arrangement and methods thereof |
US20090013405A1 (en) | 2007-07-06 | 2009-01-08 | Messagelabs Limited | Heuristic detection of malicious code |
US20090013408A1 (en) | 2007-07-06 | 2009-01-08 | Messagelabs Limited | Detection of exploits in files |
US8448161B2 (en) | 2007-07-30 | 2013-05-21 | Adobe Systems Incorporated | Application tracking for application execution environment |
US8060074B2 (en) | 2007-07-30 | 2011-11-15 | Mobile Iron, Inc. | Virtual instance architecture for mobile device management systems |
US8621610B2 (en) | 2007-08-06 | 2013-12-31 | The Regents Of The University Of Michigan | Network service for the detection, analysis and quarantine of malicious and unwanted files |
US8763115B2 (en) | 2007-08-08 | 2014-06-24 | Vmware, Inc. | Impeding progress of malicious guest software |
US8695097B1 (en) | 2007-08-28 | 2014-04-08 | Wells Fargo Bank, N.A. | System and method for detection and prevention of computer fraud |
US8601451B2 (en) | 2007-08-29 | 2013-12-03 | Mcafee, Inc. | System, method, and computer program product for determining whether code is unwanted based on the decompilation thereof |
KR101377014B1 (en) | 2007-09-04 | 2014-03-26 | 삼성전자주식회사 | System and Method of Malware Diagnosis Mechanism Based on Immune Database |
US8689330B2 (en) | 2007-09-05 | 2014-04-01 | Yahoo! Inc. | Instant messaging malware protection |
US9387402B2 (en) * | 2007-09-18 | 2016-07-12 | Disney Enterprises, Inc. | Method and system for converting a computer virtual environment into a real-life simulation environment |
US8307443B2 (en) | 2007-09-28 | 2012-11-06 | Microsoft Corporation | Securing anti-virus software with virtualization |
US7620992B2 (en) | 2007-10-02 | 2009-11-17 | Kaspersky Lab Zao | System and method for detecting multi-component malware |
US8019700B2 (en) | 2007-10-05 | 2011-09-13 | Google Inc. | Detecting an intrusive landing page |
US20090113111A1 (en) | 2007-10-30 | 2009-04-30 | Vmware, Inc. | Secure identification of execution contexts |
US8302080B2 (en) | 2007-11-08 | 2012-10-30 | Ntt Docomo, Inc. | Automated test input generation for web applications |
US8045458B2 (en) | 2007-11-08 | 2011-10-25 | Mcafee, Inc. | Prioritizing network traffic |
KR100942795B1 (en) | 2007-11-21 | 2010-02-18 | 한국전자통신연구원 | A method and a device for malware detection |
US7797748B2 (en) | 2007-12-12 | 2010-09-14 | Vmware, Inc. | On-access anti-virus mechanism for virtual machine architecture |
US7996904B1 (en) | 2007-12-19 | 2011-08-09 | Symantec Corporation | Automated unpacking of executables packed by multiple layers of arbitrary packers |
US8510828B1 (en) | 2007-12-31 | 2013-08-13 | Symantec Corporation | Enforcing the execution exception to prevent packers from evading the scanning of dynamically created code |
US8225288B2 (en) | 2008-01-29 | 2012-07-17 | Intuit Inc. | Model-based testing using branches, decisions, and options |
US8949257B2 (en) | 2008-02-01 | 2015-02-03 | Mandiant, Llc | Method and system for collecting and organizing data corresponding to an event |
US9106630B2 (en) | 2008-02-01 | 2015-08-11 | Mandiant, Llc | Method and system for collaboration during an event |
US7937387B2 (en) | 2008-02-01 | 2011-05-03 | Mandiant | System and method for data preservation and retrieval |
US8566476B2 (en) | 2008-02-01 | 2013-10-22 | Mandiant Corporation | Method and system for analyzing data related to an event |
US20100031353A1 (en) | 2008-02-04 | 2010-02-04 | Microsoft Corporation | Malware Detection Using Code Analysis and Behavior Monitoring |
US8595834B2 (en) | 2008-02-04 | 2013-11-26 | Samsung Electronics Co., Ltd | Detecting unauthorized use of computing devices based on behavioral patterns |
US9256898B2 (en) * | 2008-02-11 | 2016-02-09 | International Business Machines Corporation | Managing shared inventory in a virtual universe |
US8201246B1 (en) | 2008-02-25 | 2012-06-12 | Trend Micro Incorporated | Preventing malicious codes from performing malicious actions in a computer system |
US8805947B1 (en) | 2008-02-27 | 2014-08-12 | Parallels IP Holdings GmbH | Method and system for remote device access in virtual environment |
US20090228233A1 (en) | 2008-03-06 | 2009-09-10 | Anderson Gary F | Rank-based evaluation |
US8407784B2 (en) | 2008-03-19 | 2013-03-26 | Websense, Inc. | Method and system for protection against information stealing software |
US9264441B2 (en) | 2008-03-24 | 2016-02-16 | Hewlett Packard Enterprise Development Lp | System and method for securing a network from zero-day vulnerability exploits |
US8239944B1 (en) | 2008-03-28 | 2012-08-07 | Symantec Corporation | Reducing malware signature set size through server-side processing |
US8782615B2 (en) * | 2008-04-14 | 2014-07-15 | Mcafee, Inc. | System, method, and computer program product for simulating at least one of a virtual environment and a debugging environment to prevent unwanted code from executing |
US8549486B2 (en) | 2008-04-21 | 2013-10-01 | Microsoft Corporation | Active property checking |
US8316445B2 (en) | 2008-04-23 | 2012-11-20 | Trusted Knight Corporation | System and method for protecting against malware utilizing key loggers |
US9123027B2 (en) | 2010-10-19 | 2015-09-01 | QinetiQ North America, Inc. | Social engineering protection appliance |
US8844033B2 (en) | 2008-05-27 | 2014-09-23 | The Trustees Of Columbia University In The City Of New York | Systems, methods, and media for detecting network anomalies using a trained probabilistic model |
US8732825B2 (en) | 2008-05-28 | 2014-05-20 | Symantec Corporation | Intelligent hashes for centralized malware detection |
US8516478B1 (en) | 2008-06-12 | 2013-08-20 | Mcafee, Inc. | Subsequent processing of scanning task utilizing subset of virtual machines predetermined to have scanner process and adjusting amount of subsequest VMs processing based on load |
US8234709B2 (en) | 2008-06-20 | 2012-07-31 | Symantec Operating Corporation | Streaming malware definition updates |
US8087086B1 (en) | 2008-06-30 | 2011-12-27 | Symantec Corporation | Method for mitigating false positive generation in antivirus software |
US8381298B2 (en) | 2008-06-30 | 2013-02-19 | Microsoft Corporation | Malware detention for suspected malware |
US8850570B1 (en) | 2008-06-30 | 2014-09-30 | Symantec Corporation | Filter-based identification of malicious websites |
US7996475B2 (en) | 2008-07-03 | 2011-08-09 | Barracuda Networks Inc | Facilitating transmission of email by checking email parameters with a database of well behaved senders |
US8881271B2 (en) | 2008-08-01 | 2014-11-04 | Mandiant, Llc | System and method for forensic identification of elements within a computer system |
US10027688B2 (en) | 2008-08-11 | 2018-07-17 | Damballa, Inc. | Method and system for detecting malicious and/or botnet-related domain names |
JP5446167B2 (en) | 2008-08-13 | 2014-03-19 | 富士通株式会社 | Antivirus method, computer, and program |
US20100058474A1 (en) | 2008-08-29 | 2010-03-04 | Avg Technologies Cz, S.R.O. | System and method for the detection of malware |
JP4521456B2 (en) | 2008-09-05 | 2010-08-11 | 株式会社東芝 | Information processing system and control method of information processing system |
US8667583B2 (en) | 2008-09-22 | 2014-03-04 | Microsoft Corporation | Collecting and analyzing malware data |
US8931086B2 (en) | 2008-09-26 | 2015-01-06 | Symantec Corporation | Method and apparatus for reducing false positive detection of malware |
US8028338B1 (en) | 2008-09-30 | 2011-09-27 | Symantec Corporation | Modeling goodware characteristics to reduce false positive malware signatures |
US8171201B1 (en) | 2008-10-07 | 2012-05-01 | Vizioncore, Inc. | Systems and methods for improving virtual machine performance |
US20110173460A1 (en) | 2008-10-10 | 2011-07-14 | Takayuki Ito | Information processing device, method, program, and integrated circuit |
US9367680B2 (en) | 2008-10-21 | 2016-06-14 | Lookout, Inc. | System and method for mobile communication device application advisement |
US8347386B2 (en) | 2008-10-21 | 2013-01-01 | Lookout, Inc. | System and method for server-coupled malware prevention |
US8984628B2 (en) | 2008-10-21 | 2015-03-17 | Lookout, Inc. | System and method for adverse mobile application identification |
US8997219B2 (en) | 2008-11-03 | 2015-03-31 | Fireeye, Inc. | Systems and methods for detecting malicious PDF network content |
US8850571B2 (en) | 2008-11-03 | 2014-09-30 | Fireeye, Inc. | Systems and methods for detecting malicious network content |
US8484727B2 (en) | 2008-11-26 | 2013-07-09 | Kaspersky Lab Zao | System and method for computer malware detection |
US8161556B2 (en) | 2008-12-17 | 2012-04-17 | Symantec Corporation | Context-aware real-time computer-protection systems and methods |
US8635694B2 (en) | 2009-01-10 | 2014-01-21 | Kaspersky Lab Zao | Systems and methods for malware classification |
JP5324934B2 (en) | 2009-01-16 | 2013-10-23 | 株式会社ソニー・コンピュータエンタテインメント | Information processing apparatus and information processing method |
EP2211277A1 (en) | 2009-01-19 | 2010-07-28 | BRITISH TELECOMMUNICATIONS public limited company | Method and apparatus for generating an integrated view of multiple databases |
EP2222048A1 (en) | 2009-02-24 | 2010-08-25 | BRITISH TELECOMMUNICATIONS public limited company | Detecting malicious behaviour on a computer network |
US8233620B2 (en) | 2009-02-27 | 2012-07-31 | Inside Secure | Key recovery mechanism for cryptographic systems |
US8370835B2 (en) | 2009-03-12 | 2013-02-05 | Arend Erich Dittmer | Method for dynamically generating a configuration for a virtual machine with a virtual hard disk in an external storage device |
AU2010223925A1 (en) | 2009-03-13 | 2011-11-03 | Rutgers, The State University Of New Jersey | Systems and methods for the detection of malware |
CA2755286C (en) | 2009-03-13 | 2017-08-29 | Donald G. Peterson | Systems and methods for document management transformation and security |
US20100251104A1 (en) | 2009-03-27 | 2010-09-30 | Litera Technology Llc. | System and method for reflowing content in a structured portable document format (pdf) file |
US8935773B2 (en) | 2009-04-09 | 2015-01-13 | George Mason Research Foundation, Inc. | Malware detector |
US8555391B1 (en) | 2009-04-25 | 2013-10-08 | Dasient, Inc. | Adaptive scanning |
US8516590B1 (en) | 2009-04-25 | 2013-08-20 | Dasient, Inc. | Malicious advertisement detection and remediation |
US9154364B1 (en) | 2009-04-25 | 2015-10-06 | Dasient, Inc. | Monitoring for problems and detecting malware |
US8090797B2 (en) | 2009-05-02 | 2012-01-03 | Citrix Systems, Inc. | Methods and systems for launching applications into existing isolation environments |
US8954725B2 (en) | 2009-05-08 | 2015-02-10 | Microsoft Technology Licensing, Llc | Sanitization of packets |
US8370945B2 (en) | 2009-05-20 | 2013-02-05 | International Business Machines Corporation | Identifying security breaches caused by web-enabled software applications |
JP5459313B2 (en) | 2009-05-20 | 2014-04-02 | 日本電気株式会社 | Dynamic data flow tracking method, dynamic data flow tracking program, dynamic data flow tracking device |
US20100306825A1 (en) * | 2009-05-27 | 2010-12-02 | Lucid Ventures, Inc. | System and method for facilitating user interaction with a simulated object associated with a physical location |
US8527466B2 (en) | 2009-05-31 | 2013-09-03 | Red Hat Israel, Ltd. | Handling temporary files of a virtual machine |
US8233882B2 (en) | 2009-06-26 | 2012-07-31 | Vmware, Inc. | Providing security in mobile devices via a virtualization software layer |
US20100332593A1 (en) | 2009-06-29 | 2010-12-30 | Igor Barash | Systems and methods for operating an anti-malware network on a cloud computing platform |
US8225061B2 (en) | 2009-07-02 | 2012-07-17 | Apple Inc. | Method and apparatus for protected content data processing |
US8266091B1 (en) | 2009-07-21 | 2012-09-11 | Symantec Corporation | Systems and methods for emulating the behavior of a user in a computer-human interaction environment |
US8522348B2 (en) | 2009-07-29 | 2013-08-27 | Northwestern University | Matching with a large vulnerability signature ruleset for high performance network defense |
US8390454B2 (en) | 2009-07-31 | 2013-03-05 | Hewlett-Packard Development Company, L.P. | USB hosted sensor module |
US8789178B2 (en) | 2009-08-03 | 2014-07-22 | Barracuda Networks, Inc. | Method for detecting malicious javascript |
US20110041179A1 (en) | 2009-08-11 | 2011-02-17 | F-Secure Oyj | Malware detection |
WO2011027352A1 (en) | 2009-09-03 | 2011-03-10 | Mcafee, Inc. | Network access control |
US9009834B1 (en) * | 2009-09-24 | 2015-04-14 | Google Inc. | System policy violation detection |
US8832829B2 (en) | 2009-09-30 | 2014-09-09 | Fireeye, Inc. | Network-based binary file extraction and analysis for malware detection |
US7743419B1 (en) | 2009-10-01 | 2010-06-22 | Kaspersky Lab, Zao | Method and system for detection and prediction of computer virus-related epidemics |
US20110145934A1 (en) | 2009-10-13 | 2011-06-16 | Miron Abramovici | Autonomous distributed programmable logic for monitoring and securing electronic systems |
US8713681B2 (en) | 2009-10-27 | 2014-04-29 | Mandiant, Llc | System and method for detecting executable machine instructions in a data stream |
US8850428B2 (en) | 2009-11-12 | 2014-09-30 | Trustware International Limited | User transparent virtualization method for protecting computer programs and data from hostile code |
US20110113231A1 (en) | 2009-11-12 | 2011-05-12 | Daniel Kaminsky | System and method for providing secure reception and viewing of transmitted data over a network |
CA2781827C (en) | 2009-11-25 | 2016-05-24 | Lg Electronics Inc. | Method of processing epg metadata in network device and network device for controlling the same |
EP3002703B1 (en) | 2009-12-14 | 2017-08-30 | Citrix Systems Inc. | Methods and systems for communicating between trusted and non-trusted virtual machines |
US8893280B2 (en) | 2009-12-15 | 2014-11-18 | Intel Corporation | Sensitive data tracking using dynamic taint analysis |
US8479286B2 (en) | 2009-12-15 | 2013-07-02 | Mcafee, Inc. | Systems and methods for behavioral sandboxing |
US8307435B1 (en) | 2010-02-18 | 2012-11-06 | Symantec Corporation | Software object corruption detection |
US20110219449A1 (en) | 2010-03-04 | 2011-09-08 | St Neitzel Michael | Malware detection method, system and computer program product |
US8863279B2 (en) | 2010-03-08 | 2014-10-14 | Raytheon Company | System and method for malware detection |
US8468602B2 (en) | 2010-03-08 | 2013-06-18 | Raytheon Company | System and method for host-level malware detection |
US8938782B2 (en) | 2010-03-15 | 2015-01-20 | Symantec Corporation | Systems and methods for providing network access control in virtual environments |
US9501644B2 (en) | 2010-03-15 | 2016-11-22 | F-Secure Oyj | Malware protection |
US8566944B2 (en) | 2010-04-27 | 2013-10-22 | Microsoft Corporation | Malware investigation by analyzing computer memory |
US8914879B2 (en) | 2010-06-11 | 2014-12-16 | Trustwave Holdings, Inc. | System and method for improving coverage for web code |
US8260914B1 (en) | 2010-06-22 | 2012-09-04 | Narus, Inc. | Detecting DNS fast-flux anomalies |
US8627476B1 (en) | 2010-07-05 | 2014-01-07 | Symantec Corporation | Altering application behavior based on content provider reputation |
US8584234B1 (en) | 2010-07-07 | 2013-11-12 | Symantec Corporation | Secure network cache content |
RU2446459C1 (en) | 2010-07-23 | 2012-03-27 | Закрытое акционерное общество "Лаборатория Касперского" | System and method for checking web resources for presence of malicious components |
US20120023593A1 (en) | 2010-07-26 | 2012-01-26 | Puder George | System and method for filtering internet content & blocking undesired websites by secure network appliance |
US9356941B1 (en) | 2010-08-16 | 2016-05-31 | Symantec Corporation | Systems and methods for detecting suspicious web pages |
AU2011293160B2 (en) | 2010-08-26 | 2015-04-09 | Verisign, Inc. | Method and system for automatic detection and analysis of malware |
US8661544B2 (en) | 2010-08-31 | 2014-02-25 | Cisco Technology, Inc. | Detecting botnets |
US8869277B2 (en) | 2010-09-30 | 2014-10-21 | Microsoft Corporation | Realtime multiple engine selection and combining |
US8479291B1 (en) | 2010-10-28 | 2013-07-02 | Symantec Corporation | Systems and methods for identifying polymorphic malware |
RU2449348C1 (en) | 2010-11-01 | 2012-04-27 | Закрытое акционерное общество "Лаборатория Касперского" | System and method for virus-checking data downloaded from network at server side |
US8412984B2 (en) | 2010-11-12 | 2013-04-02 | Microsoft Corporation | Debugging in a cluster processing network |
US8682054B2 (en) | 2010-11-15 | 2014-03-25 | Siemens Aktiengesellschaft | Method and system for propagation of myocardial infarction from delayed enhanced cardiac imaging to cine magnetic resonance imaging using hybrid image registration |
AU2011336466C1 (en) | 2010-12-01 | 2017-01-19 | Cisco Technology, Inc. | Detecting malicious software through contextual convictions, generic signatures and machine learning techniques |
US8875286B2 (en) | 2010-12-01 | 2014-10-28 | Cisco Technology, Inc. | Method and apparatus for detecting malicious software using machine learning techniques |
US8763126B2 (en) | 2010-12-08 | 2014-06-24 | At&T Intellectual Property I, L.P. | Devices, systems, and methods for detecting proximity-based mobile propagation |
US8682812B1 (en) | 2010-12-23 | 2014-03-25 | Narus, Inc. | Machine learning based botnet detection using real-time extracted traffic features |
US8640245B2 (en) | 2010-12-24 | 2014-01-28 | Kaspersky Lab, Zao | Optimization of anti-malware processing by automated correction of detection rules |
US8479276B1 (en) | 2010-12-29 | 2013-07-02 | Emc Corporation | Malware detection using risk analysis based on file system and network activity |
US20120174196A1 (en) | 2010-12-30 | 2012-07-05 | Suresh Bhogavilli | Active validation for ddos and ssl ddos attacks |
US9118712B2 (en) | 2010-12-30 | 2015-08-25 | Everis, Inc. | Network communication system with improved security |
US8566648B2 (en) | 2011-02-02 | 2013-10-22 | Salesforce, Inc. | Automated testing on devices |
US9087199B2 (en) | 2011-03-31 | 2015-07-21 | Mcafee, Inc. | System and method for providing a secured operating system execution environment |
US8479295B2 (en) | 2011-03-30 | 2013-07-02 | Intel Corporation | Method and apparatus for transparently instrumenting an application program |
US8756693B2 (en) | 2011-04-05 | 2014-06-17 | The United States Of America As Represented By The Secretary Of The Air Force | Malware target recognition |
US8510842B2 (en) | 2011-04-13 | 2013-08-13 | International Business Machines Corporation | Pinpointing security vulnerabilities in computer software applications |
US8997233B2 (en) | 2011-04-13 | 2015-03-31 | Microsoft Technology Licensing, Llc | Detecting script-based malware using emulation and heuristics |
US8707437B1 (en) | 2011-04-18 | 2014-04-22 | Trend Micro Incorporated | Techniques for detecting keyloggers in computer systems |
US8806647B1 (en) | 2011-04-25 | 2014-08-12 | Twitter, Inc. | Behavioral scanning of mobile applications |
US20120278886A1 (en) | 2011-04-27 | 2012-11-01 | Michael Luna | Detection and filtering of malware based on traffic observations made in a distributed mobile traffic management system |
US9524179B2 (en) * | 2011-05-05 | 2016-12-20 | Microsoft Technology Licensing, Llc | Virtual-machine-deployment-action analysis |
US9047441B2 (en) | 2011-05-24 | 2015-06-02 | Palo Alto Networks, Inc. | Malware analysis system |
US8695096B1 (en) | 2011-05-24 | 2014-04-08 | Palo Alto Networks, Inc. | Automatic signature generation for malicious PDF files |
US9921860B1 (en) * | 2011-05-25 | 2018-03-20 | Bromium, Inc. | Isolation of applications within a virtual machine |
US8627473B2 (en) | 2011-06-08 | 2014-01-07 | At&T Intellectual Property I, L.P. | Peer-to-peer (P2P) botnet tracking at backbone level |
US8640246B2 (en) | 2011-06-27 | 2014-01-28 | Raytheon Company | Distributed malware detection |
US8769692B1 (en) | 2011-07-14 | 2014-07-01 | Mcafee, Inc. | System and method for detecting malware by transforming objects and analyzing different views of objects |
CN102339371B (en) | 2011-09-14 | 2013-12-25 | 奇智软件(北京)有限公司 | Method, device and virtual machine for detecting rogue program |
US9003532B2 (en) | 2011-09-15 | 2015-04-07 | Raytheon Company | Providing a network-accessible malware analysis |
US9672355B2 (en) | 2011-09-16 | 2017-06-06 | Veracode, Inc. | Automated behavioral and static analysis using an instrumented sandbox and machine learning classification for mobile security |
US8739280B2 (en) | 2011-09-29 | 2014-05-27 | Hewlett-Packard Development Company, L.P. | Context-sensitive taint analysis |
US8806639B2 (en) | 2011-09-30 | 2014-08-12 | Avaya Inc. | Contextual virtual machines for application quarantine and assessment method and system |
WO2013055807A1 (en) | 2011-10-10 | 2013-04-18 | Global Dataguard, Inc | Detecting emergent behavior in communications networks |
US8677487B2 (en) | 2011-10-18 | 2014-03-18 | Mcafee, Inc. | System and method for detecting a malicious command and control channel |
DE112012004368T5 (en) | 2011-10-21 | 2014-07-31 | Mitsubishi Electric Corp. | VIDEO IMAGE PLAY PROCEDURE AND VIDEO PLAY INFORMATION PLAYER |
US8782792B1 (en) | 2011-10-27 | 2014-07-15 | Symantec Corporation | Systems and methods for detecting malware on mobile platforms |
US9021587B2 (en) | 2011-10-27 | 2015-04-28 | Microsoft Technology Licensing, Llc | Detecting software vulnerabilities in an isolated computing environment |
US9519781B2 (en) | 2011-11-03 | 2016-12-13 | Cyphort Inc. | Systems and methods for virtualization and emulation assisted malware detection |
US9686293B2 (en) | 2011-11-03 | 2017-06-20 | Cyphort Inc. | Systems and methods for malware detection and mitigation |
KR20130051116A (en) | 2011-11-09 | 2013-05-20 | 한국전자통신연구원 | Apparatus for automatically inspecting security of applications and method thereof |
EP2592784B1 (en) | 2011-11-14 | 2013-09-18 | Alcatel Lucent | Apparatus, method and computer program for routing data packets |
US8590041B2 (en) | 2011-11-28 | 2013-11-19 | Mcafee, Inc. | Application sandboxing using a dynamic optimization framework |
US8533835B2 (en) | 2011-12-14 | 2013-09-10 | Mcafee, Inc. | Method and system for rapid signature search over encrypted content |
KR101296716B1 (en) | 2011-12-14 | 2013-08-20 | 한국인터넷진흥원 | System and method for detecting malicious code of pdf document type |
DE102011056502A1 (en) | 2011-12-15 | 2013-06-20 | Avira Holding GmbH | Method and apparatus for automatically generating virus descriptions |
US10701097B2 (en) | 2011-12-20 | 2020-06-30 | Micro Focus Llc | Application security testing |
US20130160130A1 (en) | 2011-12-20 | 2013-06-20 | Kirill Mendelev | Application security testing |
US8214905B1 (en) | 2011-12-21 | 2012-07-03 | Kaspersky Lab Zao | System and method for dynamically allocating computing resources for processing security information |
RU2472215C1 (en) | 2011-12-28 | 2013-01-10 | Закрытое акционерное общество "Лаборатория Касперского" | Method of detecting unknown programs by load process emulation |
US20130174214A1 (en) | 2011-12-29 | 2013-07-04 | Imation Corp. | Management Tracking Agent for Removable Media |
US20130185795A1 (en) | 2012-01-12 | 2013-07-18 | Arxceo Corporation | Methods and systems for providing network protection by progressive degradation of service |
US8533836B2 (en) | 2012-01-13 | 2013-09-10 | Accessdata Group, Llc | Identifying software execution behavior |
JP5711160B2 (en) | 2012-01-15 | 2015-04-30 | レノボ・シンガポール・プライベート・リミテッド | Method and computer for protecting passwords |
US9922190B2 (en) | 2012-01-25 | 2018-03-20 | Damballa, Inc. | Method and system for detecting DGA-based malware |
US8774761B2 (en) | 2012-01-27 | 2014-07-08 | Qualcomm Incorporated | Mobile device to detect unexpected behaviour |
US9519782B2 (en) | 2012-02-24 | 2016-12-13 | Fireeye, Inc. | Detecting malicious network content |
US9275229B2 (en) | 2012-03-15 | 2016-03-01 | Mandiant, Llc | System to bypass a compromised mass storage device driver stack and method thereof |
US9832211B2 (en) | 2012-03-19 | 2017-11-28 | Qualcomm, Incorporated | Computing device to detect malware |
US8726392B1 (en) | 2012-03-29 | 2014-05-13 | Symantec Corporation | Systems and methods for combining static and dynamic code analysis |
US8990948B2 (en) | 2012-05-01 | 2015-03-24 | Taasera, Inc. | Systems and methods for orchestrating runtime operational integrity |
US9503463B2 (en) | 2012-05-14 | 2016-11-22 | Zimperium, Inc. | Detection of threats to networks, based on geographic location |
GB2490431B (en) | 2012-05-15 | 2014-03-26 | F Secure Corp | Foiling a document exploit attack |
US9064097B2 (en) | 2012-06-06 | 2015-06-23 | Oracle International Corporation | System and method of automatically detecting outliers in usage patterns |
US8879558B1 (en) | 2012-06-27 | 2014-11-04 | Juniper Networks, Inc. | Dynamic remote packet capture |
US9223962B1 (en) * | 2012-07-03 | 2015-12-29 | Bromium, Inc. | Micro-virtual machine forensics and detection |
US9152449B2 (en) | 2012-07-13 | 2015-10-06 | International Business Machines Corporation | Co-location of virtual machines with nested virtualization |
US9245118B2 (en) | 2012-07-18 | 2016-01-26 | Infosys Limited | Methods for identifying key logging activities with a portable device and devices thereof |
US9268936B2 (en) | 2012-07-27 | 2016-02-23 | Mandiant, Llc | Physical memory forensics system and method |
US9495537B2 (en) | 2012-08-15 | 2016-11-15 | Qualcomm Incorporated | Adaptive observation of behavioral features on a mobile device |
US9747440B2 (en) | 2012-08-15 | 2017-08-29 | Qualcomm Incorporated | On-line behavioral analysis engine in mobile device with multiple analyzer model providers |
US8775925B2 (en) | 2012-08-28 | 2014-07-08 | Sweetlabs, Inc. | Systems and methods for hosted applications |
RU2514140C1 (en) | 2012-09-28 | 2014-04-27 | Закрытое акционерное общество "Лаборатория Касперского" | System and method for improving quality of detecting malicious objects using rules and priorities |
US20140181975A1 (en) | 2012-11-06 | 2014-06-26 | William Spernow | Method to scan a forensic image of a computer system with multiple malicious code detection engines simultaneously from a master control point |
US8850581B2 (en) | 2012-11-07 | 2014-09-30 | Microsoft Corporation | Identification of malware detection signature candidate code |
US8910238B2 (en) | 2012-11-13 | 2014-12-09 | Bitdefender IPR Management Ltd. | Hypervisor-based enterprise endpoint protection |
US9277378B2 (en) | 2012-12-21 | 2016-03-01 | Verizon Patent And Licensing Inc. | Short message service validation engine |
RU2522019C1 (en) | 2012-12-25 | 2014-07-10 | Закрытое акционерное общество "Лаборатория Касперского" | System and method of detecting threat in code executed by virtual machine |
US9633134B2 (en) | 2012-12-26 | 2017-04-25 | Fireeye, Inc. | Timeline wrinkling system and method |
US10572665B2 (en) | 2012-12-28 | 2020-02-25 | Fireeye, Inc. | System and method to create a number of breakpoints in a virtual machine via virtual machine trapping events |
US9690935B2 (en) | 2012-12-31 | 2017-06-27 | Fireeye, Inc. | Identification of obfuscated computer items using visual algorithms |
KR20170143006A (en) | 2013-01-16 | 2017-12-28 | 맥아피 인코퍼레이티드 | Detection of malicious scripting language code in a network environment |
US9165142B1 (en) | 2013-01-30 | 2015-10-20 | Palo Alto Networks, Inc. | Malware family identification using profile signatures |
US9176843B1 (en) | 2013-02-23 | 2015-11-03 | Fireeye, Inc. | Framework for efficient security coverage of mobile software applications |
US9195829B1 (en) | 2013-02-23 | 2015-11-24 | Fireeye, Inc. | User interface with real-time visual playback along with synchronous textual analysis log display and event/time index for anomalous behavior detection in applications |
US9009823B1 (en) | 2013-02-23 | 2015-04-14 | Fireeye, Inc. | Framework for efficient security coverage of mobile software applications installed on mobile devices |
US9159035B1 (en) | 2013-02-23 | 2015-10-13 | Fireeye, Inc. | Framework for computer application analysis of sensitive information tracking |
US9367681B1 (en) | 2013-02-23 | 2016-06-14 | Fireeye, Inc. | Framework for efficient security coverage of mobile software applications using symbolic execution to reach regions of interest within an application |
US9009822B1 (en) | 2013-02-23 | 2015-04-14 | Fireeye, Inc. | Framework for multi-phase analysis of mobile applications |
US8990944B1 (en) | 2013-02-23 | 2015-03-24 | Fireeye, Inc. | Systems and methods for automatically detecting backdoors |
US9824209B1 (en) | 2013-02-23 | 2017-11-21 | Fireeye, Inc. | Framework for efficient security coverage of mobile software applications that is usable to harden in the field code |
US9740390B2 (en) | 2013-03-11 | 2017-08-22 | Spikes, Inc. | Dynamic clip analysis |
US9355247B1 (en) | 2013-03-13 | 2016-05-31 | Fireeye, Inc. | File extraction from memory dump for malicious content analysis |
US9565202B1 (en) | 2013-03-13 | 2017-02-07 | Fireeye, Inc. | System and method for detecting exfiltration content |
US9104867B1 (en) | 2013-03-13 | 2015-08-11 | Fireeye, Inc. | Malicious content analysis using simulated user interaction without user involvement |
US9626509B1 (en) | 2013-03-13 | 2017-04-18 | Fireeye, Inc. | Malicious content analysis with multi-version application support within single operating environment |
US9311479B1 (en) | 2013-03-14 | 2016-04-12 | Fireeye, Inc. | Correlation and consolidation of analytic data for holistic view of a malware attack |
US9430646B1 (en) | 2013-03-14 | 2016-08-30 | Fireeye, Inc. | Distributed systems and methods for automatically detecting unknown bots and botnets |
US9824211B2 (en) | 2013-03-15 | 2017-11-21 | Fireeye, Inc. | System and method to visualize user sessions |
US10713358B2 (en) | 2013-03-15 | 2020-07-14 | Fireeye, Inc. | System and method to extract and utilize disassembly features to classify software intent |
US9497213B2 (en) | 2013-03-15 | 2016-11-15 | Fireeye, Inc. | System and method to manage sinkholes |
US9251343B1 (en) | 2013-03-15 | 2016-02-02 | Fireeye, Inc. | Detecting bootkits resident on compromised computers |
US9413781B2 (en) | 2013-03-15 | 2016-08-09 | Fireeye, Inc. | System and method employing structured intelligence to verify and contain threats at endpoints |
US8910285B2 (en) | 2013-04-19 | 2014-12-09 | Lastline, Inc. | Methods and systems for reciprocal generation of watch-lists and malware signatures |
US9104814B1 (en) * | 2013-05-03 | 2015-08-11 | Kabam, Inc. | System and method for integrated testing of a virtual space |
US9495180B2 (en) | 2013-05-10 | 2016-11-15 | Fireeye, Inc. | Optimized resource allocation for virtual machines within a malware content detection system |
US9635039B1 (en) | 2013-05-13 | 2017-04-25 | Fireeye, Inc. | Classifying sets of malicious indicators for detecting command and control communications associated with malware |
US10133863B2 (en) | 2013-06-24 | 2018-11-20 | Fireeye, Inc. | Zero-day discovery system |
US9536091B2 (en) | 2013-06-24 | 2017-01-03 | Fireeye, Inc. | System and method for detecting time-bomb malware |
US9888016B1 (en) | 2013-06-28 | 2018-02-06 | Fireeye, Inc. | System and method for detecting phishing using password prediction |
US9300686B2 (en) | 2013-06-28 | 2016-03-29 | Fireeye, Inc. | System and method for detecting malicious links in electronic messages |
US9426071B1 (en) | 2013-08-22 | 2016-08-23 | Fireeye, Inc. | Storing network bidirectional flow data and metadata with efficient processing technique |
US9292684B2 (en) | 2013-09-06 | 2016-03-22 | Michael Guidry | Systems and methods for security in computer systems |
US9773240B1 (en) | 2013-09-13 | 2017-09-26 | Square, Inc. | Fake sensor input for passcode entry security |
US9736179B2 (en) | 2013-09-30 | 2017-08-15 | Fireeye, Inc. | System, apparatus and method for using malware analysis results to drive adaptive instrumentation of virtual machines to improve exploit detection |
US9628507B2 (en) | 2013-09-30 | 2017-04-18 | Fireeye, Inc. | Advanced persistent threat (APT) detection center |
US9294501B2 (en) | 2013-09-30 | 2016-03-22 | Fireeye, Inc. | Fuzzy hash of behavioral results |
US10089461B1 (en) | 2013-09-30 | 2018-10-02 | Fireeye, Inc. | Page replacement code injection |
US9690936B1 (en) | 2013-09-30 | 2017-06-27 | Fireeye, Inc. | Multistage system and method for analyzing obfuscated content for malware |
US10192052B1 (en) | 2013-09-30 | 2019-01-29 | Fireeye, Inc. | System, apparatus and method for classifying a file as malicious using static scanning |
US9171160B2 (en) | 2013-09-30 | 2015-10-27 | Fireeye, Inc. | Dynamically adaptive framework and method for classifying malware using intelligent static, emulation, and dynamic analyses |
US9350747B2 (en) | 2013-10-31 | 2016-05-24 | Cyberpoint International Llc | Methods and systems for malware analysis |
US9921978B1 (en) | 2013-11-08 | 2018-03-20 | Fireeye, Inc. | System and method for enhanced security of storage devices |
US9189627B1 (en) | 2013-11-21 | 2015-11-17 | Fireeye, Inc. | System, apparatus and method for conducting on-the-fly decryption of encrypted objects for malware detection |
US9355246B1 (en) | 2013-12-05 | 2016-05-31 | Trend Micro Inc. | Tuning sandbox behavior based on static characteristics of malware |
US9747446B1 (en) | 2013-12-26 | 2017-08-29 | Fireeye, Inc. | System and method for run-time object classification |
US9756074B2 (en) | 2013-12-26 | 2017-09-05 | Fireeye, Inc. | System and method for IPS and VM-based detection of suspicious objects |
US9507935B2 (en) | 2014-01-16 | 2016-11-29 | Fireeye, Inc. | Exploit detection system with threat-aware microvisor |
US9262635B2 (en) | 2014-02-05 | 2016-02-16 | Fireeye, Inc. | Detection efficacy of virtual machine-based analysis with application specific events |
US9537972B1 (en) | 2014-02-20 | 2017-01-03 | Fireeye, Inc. | Efficient access to sparse packets in large repositories of stored network traffic |
KR101498614B1 (en) | 2014-02-27 | 2015-03-04 | 한국전자통신연구원 | Apparatus and method of deactivating malicious codes |
US9241010B1 (en) | 2014-03-20 | 2016-01-19 | Fireeye, Inc. | System and method for network behavior detection |
US10242185B1 (en) | 2014-03-21 | 2019-03-26 | Fireeye, Inc. | Dynamic guest image creation and rollback |
US9591015B1 (en) | 2014-03-28 | 2017-03-07 | Fireeye, Inc. | System and method for offloading packet processing and static analysis operations |
US9432389B1 (en) | 2014-03-31 | 2016-08-30 | Fireeye, Inc. | System, apparatus and method for detecting a malicious attack based on static analysis of a multi-flow object |
US9223972B1 (en) | 2014-03-31 | 2015-12-29 | Fireeye, Inc. | Dynamically remote tuning of a malware content detection system |
US9973531B1 (en) | 2014-06-06 | 2018-05-15 | Fireeye, Inc. | Shellcode detection |
US9438623B1 (en) | 2014-06-06 | 2016-09-06 | Fireeye, Inc. | Computer exploit detection using heap spray pattern matching |
US9594912B1 (en) | 2014-06-06 | 2017-03-14 | Fireeye, Inc. | Return-oriented programming detection |
US9760738B1 (en) | 2014-06-10 | 2017-09-12 | Lockheed Martin Corporation | Storing and transmitting sensitive data |
US9015814B1 (en) * | 2014-06-10 | 2015-04-21 | Kaspersky Lab Zao | System and methods for detecting harmful files of different formats |
US10084813B2 (en) | 2014-06-24 | 2018-09-25 | Fireeye, Inc. | Intrusion prevention and remedy system |
US9398028B1 (en) | 2014-06-26 | 2016-07-19 | Fireeye, Inc. | System, device and method for detecting a malicious attack based on communcations between remotely hosted virtual machines and malicious web servers |
US9680862B2 (en) | 2014-07-01 | 2017-06-13 | Fireeye, Inc. | Trusted threat-aware microvisor |
US10002252B2 (en) | 2014-07-01 | 2018-06-19 | Fireeye, Inc. | Verification of trusted threat-aware microvisor |
US9912644B2 (en) | 2014-08-05 | 2018-03-06 | Fireeye, Inc. | System and method to communicate sensitive information via one or more untrusted intermediate nodes with resilience to disconnected network topology |
US9363280B1 (en) | 2014-08-22 | 2016-06-07 | Fireeye, Inc. | System and method of detecting delivery of malware using cross-customer data |
EP3189638B1 (en) | 2014-09-05 | 2018-11-28 | Telefonaktiebolaget LM Ericsson (publ) | Explicit control of aggregation links via is-is |
US9773112B1 (en) | 2014-09-29 | 2017-09-26 | Fireeye, Inc. | Exploit detection of malware and malware families |
US10027689B1 (en) | 2014-09-29 | 2018-07-17 | Fireeye, Inc. | Interactive infection visualization for improved exploit detection and signature generation for malware and malware families |
US9781144B1 (en) | 2014-09-30 | 2017-10-03 | Fireeye, Inc. | Determining duplicate objects for malware analysis using environmental/context information |
US9210185B1 (en) | 2014-12-05 | 2015-12-08 | Lookingglass Cyber Solutions, Inc. | Cyber threat monitor and control apparatuses, methods and systems |
US9690933B1 (en) | 2014-12-22 | 2017-06-27 | Fireeye, Inc. | Framework for classifying an object as malicious with machine learning for deploying updated predictive models |
US9467460B1 (en) | 2014-12-23 | 2016-10-11 | Fireeye, Inc. | Modularized database architecture using vertical partitioning for a state machine |
US10075455B2 (en) | 2014-12-26 | 2018-09-11 | Fireeye, Inc. | Zero-day rotating guest image profile |
US20160191550A1 (en) | 2014-12-29 | 2016-06-30 | Fireeye, Inc. | Microvisor-based malware detection endpoint architecture |
US9934376B1 (en) | 2014-12-29 | 2018-04-03 | Fireeye, Inc. | Malware detection appliance architecture |
US9838417B1 (en) | 2014-12-30 | 2017-12-05 | Fireeye, Inc. | Intelligent context aware user interaction for malware detection |
US9690606B1 (en) | 2015-03-25 | 2017-06-27 | Fireeye, Inc. | Selective system call monitoring |
US10148693B2 (en) | 2015-03-25 | 2018-12-04 | Fireeye, Inc. | Exploit detection system |
US9438613B1 (en) | 2015-03-30 | 2016-09-06 | Fireeye, Inc. | Dynamic content activation for automated analysis of embedded objects |
US10417031B2 (en) | 2015-03-31 | 2019-09-17 | Fireeye, Inc. | Selective virtualization for security threat detection |
US9912681B1 (en) | 2015-03-31 | 2018-03-06 | Fireeye, Inc. | Injection of content processing delay in an endpoint |
US9483644B1 (en) | 2015-03-31 | 2016-11-01 | Fireeye, Inc. | Methods for detecting file altering malware in VM based analysis |
US9654485B1 (en) | 2015-04-13 | 2017-05-16 | Fireeye, Inc. | Analytics-based security monitoring system and method |
US9594904B1 (en) | 2015-04-23 | 2017-03-14 | Fireeye, Inc. | Detecting malware based on reflection |
US20160357965A1 (en) | 2015-06-04 | 2016-12-08 | Ut Battelle, Llc | Automatic clustering of malware variants based on structured control flow |
US10536357B2 (en) | 2015-06-05 | 2020-01-14 | Cisco Technology, Inc. | Late data detection in data center |
US10216927B1 (en) | 2015-06-30 | 2019-02-26 | Fireeye, Inc. | System and method for protecting memory pages associated with a process using a virtualization layer |
US10176321B2 (en) | 2015-09-22 | 2019-01-08 | Fireeye, Inc. | Leveraging behavior-based rules for malware family classification |
US10033759B1 (en) | 2015-09-28 | 2018-07-24 | Fireeye, Inc. | System and method of threat detection under hypervisor control |
US10033747B1 (en) | 2015-09-29 | 2018-07-24 | Fireeye, Inc. | System and method for detecting interpreter-based exploit attacks |
US9825989B1 (en) | 2015-09-30 | 2017-11-21 | Fireeye, Inc. | Cyber attack early warning system |
US9825976B1 (en) | 2015-09-30 | 2017-11-21 | Fireeye, Inc. | Detection and classification of exploit kits |
US10210329B1 (en) | 2015-09-30 | 2019-02-19 | Fireeye, Inc. | Method to detect application execution hijacking using memory protection |
US10284575B2 (en) | 2015-11-10 | 2019-05-07 | Fireeye, Inc. | Launcher for setting analysis environment variations for malware detection |
US10108446B1 (en) | 2015-12-11 | 2018-10-23 | Fireeye, Inc. | Late load technique for deploying a virtualization layer underneath a running operating system |
US10133866B1 (en) | 2015-12-30 | 2018-11-20 | Fireeye, Inc. | System and method for triggering analysis of an object for malware in response to modification of that object |
US10050998B1 (en) | 2015-12-30 | 2018-08-14 | Fireeye, Inc. | Malicious message analysis system |
US9824216B1 (en) | 2015-12-31 | 2017-11-21 | Fireeye, Inc. | Susceptible environment detection system |
US10169585B1 (en) | 2016-06-22 | 2019-01-01 | Fireeye, Inc. | System and methods for advanced malware detection through placement of transition events |
US10121000B1 (en) | 2016-06-28 | 2018-11-06 | Fireeye, Inc. | System and method to detect premium attacks on electronic networks and electronic devices |
US10191861B1 (en) | 2016-09-06 | 2019-01-29 | Fireeye, Inc. | Technique for implementing memory views using a layered virtualization architecture |
US10025691B1 (en) | 2016-09-09 | 2018-07-17 | Fireeye, Inc. | Verification of complex software code using a modularized architecture |
US10798112B2 (en) | 2017-03-30 | 2020-10-06 | Fireeye, Inc. | Attribute-controlled malware detection |
US10650567B2 (en) * | 2017-06-09 | 2020-05-12 | FlyInside, Inc. | Optimizing processing time of a simulation engine |
CN111511448A (en) * | 2017-06-22 | 2020-08-07 | 百夫长Vr公司 | Virtual reality simulation |
US20190066377A1 (en) * | 2017-08-22 | 2019-02-28 | Software Ag | Systems and/or methods for virtual reality based process optimization |
-
2014
- 2014-12-30 US US14/586,233 patent/US9838417B1/en active Active
-
2015
- 2015-12-21 WO PCT/US2015/067082 patent/WO2016109283A1/en active Application Filing
- 2015-12-21 EP EP15823116.7A patent/EP3245609A1/en not_active Withdrawn
- 2015-12-21 JP JP2017535823A patent/JP6702983B2/en active Active
-
2017
- 2017-12-04 US US15/831,311 patent/US10798121B1/en active Active
Patent Citations (1)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US20110167494A1 (en) * | 2009-12-31 | 2011-07-07 | Bowen Brian M | Methods, systems, and media for detecting covert malware |
Non-Patent Citations (1)
Title |
---|
BRIAN M BOWEN ET AL: "BotSwindler: Tamper Resistant Injection of Believable Decoys in VM-Based Hosts for Crimeware Detection", 15 September 2010, RECENT ADVANCES IN INTRUSION DETECTION, SPRINGER BERLIN HEIDELBERG, BERLIN, HEIDELBERG, PAGE(S) 118 - 137, ISBN: 978-3-642-15511-6, XP019150482 * |
Cited By (15)
Publication number | Priority date | Publication date | Assignee | Title |
---|---|---|---|---|
US10169585B1 (en) | 2016-06-22 | 2019-01-01 | Fireeye, Inc. | System and methods for advanced malware detection through placement of transition events |
US11062021B2 (en) | 2017-08-29 | 2021-07-13 | NortonLifeLock Inc. | Systems and methods for preventing malicious applications from exploiting application services |
WO2019046166A1 (en) * | 2017-08-29 | 2019-03-07 | Symantec Corporation | Systems and methods for preventing malicious applications from exploiting application services |
KR20190064264A (en) * | 2017-11-30 | 2019-06-10 | 건국대학교 산학협력단 | Ransomware dectecting method and apparatus based on machine learning through hybrid analysis |
KR101988747B1 (en) * | 2017-11-30 | 2019-06-12 | 건국대학교 산학협력단 | Ransomware dectecting method and apparatus based on machine learning through hybrid analysis |
WO2019142398A1 (en) * | 2018-01-17 | 2019-07-25 | 日本電信電話株式会社 | Interpretation device, interpretation method and interpretation program |
US11361073B2 (en) | 2018-01-17 | 2022-06-14 | Nippon Telegraph And Telephone Corporation | Analysis apparatus, analysis method, and analysis program |
JPWO2019142398A1 (en) * | 2018-01-17 | 2020-04-23 | 日本電信電話株式会社 | Analysis device, analysis method, and analysis program |
CN110826058A (en) * | 2018-08-13 | 2020-02-21 | 瞻博网络公司 | Malware detection based on user interaction |
US11138313B2 (en) | 2018-08-13 | 2021-10-05 | Juniper Networks, Inc. | Malware detection based on user interactions |
EP3611643A1 (en) * | 2018-08-13 | 2020-02-19 | Juniper Networks, Inc. | Malware detection based on user interactions |
EP4184357A1 (en) * | 2018-08-13 | 2023-05-24 | Juniper Networks, Inc. | Malware detection based on user interactions |
US11880458B2 (en) | 2018-08-13 | 2024-01-23 | Juniper Networks, Inc. | Malware detection based on user interactions |
CN110826058B (en) * | 2018-08-13 | 2024-03-29 | 瞻博网络公司 | Device, method and medium for malware detection based on user interaction |
US20220292191A1 (en) * | 2019-08-29 | 2022-09-15 | Nec Corporation | Backdoor inspection apparatus, backdoor inspection method, and non-transitory computer readable medium |
Also Published As
Publication number | Publication date |
---|---|
US10798121B1 (en) | 2020-10-06 |
EP3245609A1 (en) | 2017-11-22 |
JP6702983B2 (en) | 2020-06-03 |
JP2018501583A (en) | 2018-01-18 |
US9838417B1 (en) | 2017-12-05 |
Similar Documents
Publication | Publication Date | Title |
---|---|---|
US10798121B1 (en) | Intelligent context aware user interaction for malware detection | |
US10666686B1 (en) | Virtualized exploit detection system | |
US10169585B1 (en) | System and methods for advanced malware detection through placement of transition events | |
US10075455B2 (en) | Zero-day rotating guest image profile | |
US11868795B1 (en) | Selective virtualization for security threat detection | |
US9438613B1 (en) | Dynamic content activation for automated analysis of embedded objects | |
US10469512B1 (en) | Optimized resource allocation for virtual machines within a malware content detection system | |
US11075945B2 (en) | System, apparatus and method for reconfiguring virtual machines | |
US9846776B1 (en) | System and method for detecting file altering behaviors pertaining to a malicious attack | |
US10817606B1 (en) | Detecting delayed activation malware using a run-time monitoring agent and time-dilation logic | |
US10671726B1 (en) | System and method for malware analysis using thread-level event monitoring | |
US9690606B1 (en) | Selective system call monitoring | |
US20180191779A1 (en) | Flexible Deception Architecture | |
US11394739B2 (en) | Configurable event-based compute instance security assessments | |
EP3049985B1 (en) | A separate, disposable execution environment for accessing unverified content | |
US10706149B1 (en) | Detecting delayed activation malware using a primary controller and plural time controllers | |
EP3610403A1 (en) | Isolated container event monitoring | |
US11706237B2 (en) | Threat detection and security for edge devices | |
US11706251B2 (en) | Simulating user interactions for malware analysis | |
Heiser | Secure embedded systems need microkernels | |
Arunanshu et al. | Evaluating the Efficacy of Antivirus Software Against Malware and Rats Using Metasploit and Asyncrat | |
Ysterud | Keylogging of user interaction in physical and virtual environments and its implications for honeypot analysis |
Legal Events
Date | Code | Title | Description |
---|---|---|---|
121 | Ep: the epo has been informed by wipo that ep was designated in this application |
Ref document number: 15823116 Country of ref document: EP Kind code of ref document: A1 |
|
ENP | Entry into the national phase |
Ref document number: 2017535823 Country of ref document: JP Kind code of ref document: A |
|
NENP | Non-entry into the national phase |
Ref country code: DE |
|
REEP | Request for entry into the european phase |
Ref document number: 2015823116 Country of ref document: EP |