SYSTEM AND METHOD FOR DETECTING AND CLASSIFYING MALWARE

    公开(公告)号:EP3352110A1

    公开(公告)日:2018-07-25

    申请号:EP18153061.9

    申请日:2018-01-23

    申请人: Cyphort Inc.

    IPC分类号: G06F21/56 G06F21/53 H04L29/06

    摘要: A network device may include a memory and one or more processors configured to analyze execution of suspicious data; detect one or more states of execution of the suspicious data; determine that the one or more states of execution are to be assigned a priority level; and extract at least a portion of the suspicious data from one or more locations based on determining that the one or more states of execution are to be assigned a priority level.

    SYSTEMS AND METHODS FOR VIRTUALIZATION AND EMULATION ASSISTED MALWARE DETECTION
    24.
    发明公开
    SYSTEMS AND METHODS FOR VIRTUALIZATION AND EMULATION ASSISTED MALWARE DETECTION 有权
    系统和虚拟化方法,并协助有害程序识别仿真

    公开(公告)号:EP2774038A4

    公开(公告)日:2015-08-19

    申请号:EP12844780

    申请日:2012-11-05

    申请人: CYPHORT INC

    摘要: Systems and methods for virtualization and emulation malware enabled detection are described. In some embodiments, a method comprises intercepting an object, instantiating and processing the object in a virtualization environment, tracing operations of the object while processing within the virtualization environment, detecting suspicious behavior associated with the object, instantiating an emulation environment in response to the detected suspicious behavior, processing, recording responses to, and tracing operations of the object within the emulation environment, detecting a divergence between the traced operations of the object within the virtualization environment to the traced operations of the object within the emulation environment, re-instantiating the virtualization environment, providing the recorded response from the emulation environment to the object in the virtualization environment, monitoring the operations of the object within the re-instantiation of the virtualization environment, identifying untrusted actions from the monitored operations, and generating a report regarding the identified untrusted actions of the object.

    SYSTEMS AND METHODS FOR VIRTUALIZED MALWARE DETECTION
    25.
    发明公开
    SYSTEMS AND METHODS FOR VIRTUALIZED MALWARE DETECTION 审中-公开
    系统和虚拟化的恶意软件检测方法

    公开(公告)号:EP2774039A1

    公开(公告)日:2014-09-10

    申请号:EP12845692.8

    申请日:2012-11-05

    申请人: Cyphort Inc.

    IPC分类号: G06F11/00

    摘要: Systems and methods for virtualization and emulation malware enabled detection are described. In some embodiments, a method comprises intercepting an object, instantiating and processing the object in a virtualization environment, tracing operations of the object while processing within the virtualization environment, detecting suspicious behavior associated with the object, instantiating an emulation environment in response to the detected suspicious behavior, processing, recording responses to, and tracing operations of the object within the emulation environment, detecting a divergence between the traced operations of the object within the virtualization environment to the traced operations of the object within the emulation environment, re-instantiating the virtualization environment, providing the recorded response from the emulation environment to the object in the virtualization environment, monitoring the operations of the object within the re-instantiation of the virtualization environment, identifying untrusted actions from the monitored operations, and generating a report regarding the identified untrusted actions of the object.