Malware identification using multiple artificial neural networks

    公开(公告)号:US11574051B2

    公开(公告)日:2023-02-07

    申请号:US16053479

    申请日:2018-08-02

    申请人: Fortinet, Inc.

    发明人: Xu Yang

    摘要: Systems and methods for malware detection using multiple neural networks are provided. According to one embodiment, for each training sample, a supervised learning process is performed, including: (i) generating multiple code blocks of assembly language instructions by disassembling machine language instructions contained within the training sample; (ii) extracting dynamic features corresponding to each of the code blocks by executing each of the code blocks within a virtual environment; (iii) feeding each code block into a first neural network and the corresponding dynamic features into a second neural network; (iv) updating weights and biases of the neural networks based on whether the training sample was malware or benign; and (v) after processing a predetermined or configurable number of the training samples, the neural networks criticize each other and unify their respective weights and biases by exchanging their respective weights and biases and adjusting their respective weights and biases accordingly.

    Separating broadcast and multicast wireless traffic in WLANs (wireless local access networks) for quarantine stations

    公开(公告)号:US11184741B1

    公开(公告)日:2021-11-23

    申请号:US17013612

    申请日:2020-09-06

    申请人: Fortinet, Inc.

    发明人: Venkatesh Kannan

    摘要: Quarantine stations are steered to a hidden virtual access point for quarantining multicast and broadcast traffic from other traffic on an access point, or other device. The hidden virtual access point can be spawned, with the same configurations as a non-quarantine virtual access point, for on demand traffic containment. The data stream transmitted over Wi-Fi to the quarantine client using a different GTK key generated under virtual access point of hidden SSID for encryption of the multicast or broadcast transmission, and the data packet stream transmitted over wi-fi to the non-quarantine station using different GTK key generated under virtual access point SSID of regular SSID for encryption of the multicast or broadcast transmission.

    DHCP agent assisted routing and access control

    公开(公告)号:US11044138B2

    公开(公告)日:2021-06-22

    申请号:US15702594

    申请日:2017-09-12

    申请人: Fortinet, Inc.

    发明人: Mathieu Nantel

    IPC分类号: H04L29/12 H04L12/28 H04L29/06

    摘要: Systems and methods for increasing layer 2 visibility of layer 3 network devices so as to facilitate implementation of device-oriented policy actions by layer 3 network devices are provided. According to one embodiment, unique physical addresses of one or more host devices are retrieved by a dynamic host configuration protocol (DHCP) agent that is operatively coupled with a DHCP server. The physical addresses are mapped to corresponding Internet Protocol (IP) addresses assigned by the DHCP server to the one or more host devices. The mapping is relayed directly or indirectly to a network security device. Network traffic management/security policies are defined within the network security device corresponding to at least one of the unique physical addresses.