SYSTEM AND METHOD FOR DETECTION OF MALICIOUS HYPERTEXT TRANSFER PROTOCOL CHAINS
    3.
    发明公开
    SYSTEM AND METHOD FOR DETECTION OF MALICIOUS HYPERTEXT TRANSFER PROTOCOL CHAINS 有权
    SYSTEM UND VERFAHREN ZUR ERKENNUNGBÖSARTIGERHYPERTEXTÜBERTRAGUNGSPROTOKOLLKETTEN

    公开(公告)号:EP3108401A4

    公开(公告)日:2017-08-09

    申请号:EP15752745

    申请日:2015-02-23

    申请人: CYPHORT INC

    IPC分类号: G06F21/56

    摘要: A system configured to detect malware is described. The system configured to detect malware including a data collector configured to detect at least a first hypertext transfer object in a chain of a plurality of hypertext transfer objects. The data collector further configured to analyze at least the first hypertext transfer object for one or more events. And, the data collector configured to generate a list of events based on the analysis of at least the first hypertext transfer object.

    摘要翻译: 描述了配置为检测恶意软件的系统。 所述系统被配置为检测恶意软件,所述恶意软件包括被配置为检测多个超文本传输​​对象的链中的至少第一超文本传输​​对象的数据收集器。 数据收集器还被配置为至少分析第一超文本传输​​对象以查找一个或多个事件。 并且,数据收集器被配置为基于对至少第一超文本传输​​对象的分析来生成事件列表。

    SYSTEMS AND METHODS FOR VIRTUALIZATION AND EMULATION ASSISTED MALWARE DETECTION
    7.
    发明授权
    SYSTEMS AND METHODS FOR VIRTUALIZATION AND EMULATION ASSISTED MALWARE DETECTION 有权
    系统和虚拟化方法,并协助有害程序识别仿真

    公开(公告)号:EP2774038B1

    公开(公告)日:2016-06-22

    申请号:EP12844780.2

    申请日:2012-11-05

    申请人: Cyphort, Inc.

    摘要: Systems and methods for virtualization and emulation malware enabled detection are described. In some embodiments, a method comprises intercepting an object, instantiating and processing the object in a virtualization environment, tracing operations of the object while processing within the virtualization environment, detecting suspicious behavior associated with the object, instantiating an emulation environment in response to the detected suspicious behavior, processing, recording responses to, and tracing operations of the object within the emulation environment, detecting a divergence between the traced operations of the object within the virtualization environment to the traced operations of the object within the emulation environment, re-instantiating the virtualization environment, providing the recorded response from the emulation environment to the object in the virtualization environment, monitoring the operations of the object within the re-instantiation of the virtualization environment, identifying untrusted actions from the monitored operations, and generating a report regarding the identified untrusted actions of the object.

    SYSTEMS AND METHODS FOR VIRTUALIZED MALWARE DETECTION
    8.
    发明公开
    SYSTEMS AND METHODS FOR VIRTUALIZED MALWARE DETECTION 审中-公开
    系统和虚拟化的恶意软件检测方法

    公开(公告)号:EP2774039A4

    公开(公告)日:2015-11-11

    申请号:EP12845692

    申请日:2012-11-05

    申请人: CYPHORT INC

    摘要: Systems and methods for virtualization and emulation malware enabled detection are described. In some embodiments, a method comprises intercepting an object, instantiating and processing the object in a virtualization environment, tracing operations of the object while processing within the virtualization environment, detecting suspicious behavior associated with the object, instantiating an emulation environment in response to the detected suspicious behavior, processing, recording responses to, and tracing operations of the object within the emulation environment, detecting a divergence between the traced operations of the object within the virtualization environment to the traced operations of the object within the emulation environment, re-instantiating the virtualization environment, providing the recorded response from the emulation environment to the object in the virtualization environment, monitoring the operations of the object within the re-instantiation of the virtualization environment, identifying untrusted actions from the monitored operations, and generating a report regarding the identified untrusted actions of the object.

    SYSTEM FOR QUERY INJECTION DETECTION USING ABSTRACT SYNTAX TREES

    公开(公告)号:EP3506141A1

    公开(公告)日:2019-07-03

    申请号:EP18197668.9

    申请日:2018-09-28

    申请人: Cyphort Inc.

    IPC分类号: G06F21/56

    摘要: A device may include one or more memories; and one or more processors, communicatively coupled to the one or more memories, to receive a query for data stored by a database; generate an abstract syntax tree based on the query; determine whether the abstract syntax tree matches a list, where the list identifies one or more abstract syntax trees corresponding to queries or types of queries; and selectively perform an action based on whether the abstract syntax tree matches the entry of the list.