• 专利标题: System and method for detecting malicious activity and classifying a network communication based on different indicator types
  • 申请号: US15495629
    申请日: 2017-04-24
  • 公开(公告)号: US10033753B1
    公开(公告)日: 2018-07-24
  • 发明人: Ali IslamZheng Bu
  • 申请人: FireEye, Inc.
  • 申请人地址: US CA Milpitas
  • 专利权人: FireEye, Inc.
  • 当前专利权人: FireEye, Inc.
  • 当前专利权人地址: US CA Milpitas
  • 代理机构: Rutan & Tucker, LLP
  • 主分类号: H04L29/06
  • IPC分类号: H04L29/06
System and method for detecting malicious activity and classifying a network communication based on different indicator types
摘要:
One embodiment of a method for detecting a cyber-attack features first and second analyzes. The first analysis is conducted on content of a communication to determine at least a first high quality indicator. The first high quality indicator represents a first probative value for classification. The second analysis is conducted on metadata related to the content to determine supplemental indicator(s). Each of the supplemental indicator(s) is represented by a probative value for classification. The communication is classified as being part of the cyber-attack when the first probative value exceeds a predetermined threshold without consideration of the corresponding probative values for the supplemental indicator(s). In response to the first high quality indicator failing to classify the network communication, using the corresponding probative values associated with the one or more supplemental indicators with at least the first probative value to classify the network communication as being part of the cyber-attack.
信息查询
0/0