- 专利标题: System and method for detecting exfiltration content
-
申请号: US15943406申请日: 2018-04-02
-
公开(公告)号: US10467414B1公开(公告)日: 2019-11-05
- 发明人: Darien Kindlund , Julia Wolf , James Bennett
- 申请人: FireEye, Inc.
- 申请人地址: US CA Milpitas
- 专利权人: FireEye, Inc.
- 当前专利权人: FireEye, Inc.
- 当前专利权人地址: US CA Milpitas
- 代理机构: Rutan & Tucker, LLP
- 主分类号: G06F12/14
- IPC分类号: G06F12/14 ; G06F9/455 ; G06F11/30 ; H04L29/06 ; G06F21/56 ; G06F21/53
摘要:
Techniques for detecting exfiltration content are described herein. According to one embodiment, a malicious content suspect is executed and a packet inspection of outbound network traffic is performed by a packet inspector running within the virtual machine. Occurring before the outbound network traffic leaving the virtual machine, the packet inspector determines whether a portion of outbound network traffic matches one or more portions of predetermined network traffic patterns or signatures. If so, a determination is made whether the outbound network traffic includes at least one environmental property of the virtual machine that is unique or almost unique to the virtual machine. If so, migration of the outbound network traffic outside of the virtual machine is precluded and an alert is transmitted. The alert includes the malicious content suspect that is attempting to perform an exfiltration of data.
信息查询