CLOUD BASED JUST IN TIME MEMORY ANALYSIS FOR MALWARE DETECTION

    公开(公告)号:US20240012907A1

    公开(公告)日:2024-01-11

    申请号:US18369926

    申请日:2023-09-19

    申请人: SONICWALL INC.

    IPC分类号: G06F21/56 G06F21/53

    摘要: Methods and apparatus consistent with the present disclosure may be performed by a Cloud computing device may use instrumentation code that remains transparent to an application program that the instrumentation code has been injected into, may perform deep packet inspection (DPI) on computer data, or identify a content rating associated with computer data. In certain instances, data sets that include executable code may be received via packetized communications or be received via other means, such as, receiving a file from a data store. The present technique allows one or more processors executing instrumentation code to monitor actions performed by the program code included in a received data set. Malware can be detected using exception handling to track memory allocations of the program code included in the received data set. Furthermore, access to content associated with malware, potential malware, or with inappropriate content ratings may be blocked.

    Detection of exploitative program code

    公开(公告)号:US11550912B2

    公开(公告)日:2023-01-10

    申请号:US16903060

    申请日:2020-06-16

    申请人: SONICWALL INC.

    IPC分类号: G06F21/56

    摘要: The present disclosure is directed to monitoring internal process memory of a computer at a time with program code executes. Methods and apparatus consistent with the present disclosure monitor the operation of program code with the intent of detecting whether received program inputs may exploit vulnerabilities that may exist in the program code at runtime. By detecting suspicious activity or malicious code that may affect internal process memory at run-time, methods and apparatus described herein identify suspected malware based on suspicious actions performed as program code executes. Runtime exploit detection may detect certain anomalous activities or chain of events in a potentially vulnerable application during execution. These events may be detected using instrumentation code when a regular code execution path of an application is deviated from.

    Just in time memory analysis for malware detection

    公开(公告)号:US10902122B2

    公开(公告)日:2021-01-26

    申请号:US15890192

    申请日:2018-02-06

    申请人: SonicWALL Inc.

    IPC分类号: G06F21/55 G06F21/56

    摘要: Methods and apparatus consistent with the present disclosure may use instrumentation code that remains transparent to an application program that the instrumentation code has been injected into. In certain instances, data sets that include executable code may be received via packetized communications or be received via other means, such as, receiving a file from a data store. The present technique allows one or more processors executing instrumentation code to monitor actions performed by the program code included in a received data set. Malware can be detected using exception handling to track memory allocations of the program code included in the received data set.

    Dynamic Bypass
    4.
    发明申请
    Dynamic Bypass 审中-公开

    公开(公告)号:US20190182235A1

    公开(公告)日:2019-06-13

    申请号:US15834914

    申请日:2017-12-07

    申请人: SonicWALL Inc.

    IPC分类号: H04L29/06 H04L29/08

    摘要: Methods and apparatus consistent with the present disclosure may prevent a computer process from failing when a firewall located between a client device and a server identifies that a process at the firewall should be bypassed using fingerprint information associated with a connection attempt. When fingerprint information stored at a firewall matches previously received fingerprint information, the firewall may allow processes typically performed at the firewall to be bypassed, thereby, allowing communications to pass between the client device and the server without inspection. When that fingerprint information does not match previously received fingerprint information, the firewall may perform a process that causes the client device to fail the first connection attempt. Because of this, methods consistent with the present disclosure may allow communications from an application program to be passed through a firewall without relying on an ever growing list of trusted application programs.

    PROXY-LESS SECURE SOCKETS LAYER (SSL) DATA INSPECTION

    公开(公告)号:US20170374062A1

    公开(公告)日:2017-12-28

    申请号:US15685768

    申请日:2017-08-24

    申请人: SonicWall Inc.

    IPC分类号: H04L29/06 H04L9/32

    摘要: Some embodiments of proxy-less Secure Sockets Layer (SSL) data inspection have been presented. In one embodiment, a secured connection according to a secured network protocol between a client and a responder is setup via a gateway device, which is coupled between the client and the responder. The gateway device transparently intercepts data transmitted according to the secured network protocol between the client and the responder. Furthermore, the gateway device provides flow-control and retransmission of one or more data packets of the data without self-scheduling the packet retransmissions using timeouts and based on the packet retransmission logic of either the client-side or the responder side of the connection. The gateway device is further operable to perform security screening on the data.

    NOTIFICATION FOR REASSEMBLY-FREE FILE SCANNING
    6.
    发明申请
    NOTIFICATION FOR REASSEMBLY-FREE FILE SCANNING 有权
    无资格文件扫描的通知

    公开(公告)号:US20140373156A1

    公开(公告)日:2014-12-18

    申请号:US14475441

    申请日:2014-09-02

    申请人: SonicWALL, Inc.

    IPC分类号: H04L29/06 G06F21/56

    摘要: Techniques for notification of reassembly-free file scanning are described herein. According to one embodiment, a first request for accessing a document provided by a remote node is received from a client. In response to the first request, it is determined whether a second request previously for accessing the document of the remote node indicates that the requested document from the remote node contains offensive data. If the requested document contains offensive data, a message is returned to the client, without accessing the requested document of the remote node, indicating that the requested document is not delivered to the client.

    摘要翻译: 本文描述了用于通知无组装文件扫描的技术。 根据一个实施例,从客户端接收到访问由远程节点提供的文档的第一请求。 响应于第一请求,确定先前用于访问远程节点的文档的第二请求是否指示来自远程节点的所请求的文档包含令人反感的数据。 如果请求的文档包含令人反感的数据,则将消息返回给客户端,而不访问远程节点的请求文档,指示所请求的文档未传递给客户端。

    Cloud-based gateway security scanning
    7.
    发明授权
    Cloud-based gateway security scanning 有权
    基于云的网关安全扫描

    公开(公告)号:US08769678B2

    公开(公告)日:2014-07-01

    申请号:US13626777

    申请日:2012-09-25

    申请人: SonicWALL, Inc.

    IPC分类号: H04L29/06 G06F21/00

    摘要: Some embodiments of cloud-based gateway security scanning have been presented. In one embodiment, some data packets are received sequentially at a gateway device. The data packets constitute at least a part of a file being addressed to a client machine coupled to the gateway device. The gateway device forwards an identification of the file to a remote datacenter in parallel with forwarding the data packets to the client machine. The datacenter performs signature matching on the identification and returns a result of the signature matching to the gateway device. The gateway device determining whether to block the file from the client machine based on the result of the signature matching from the datacenter.

    摘要翻译: 已经提出了基于云的网关安全扫描的一些实施例。 在一个实施例中,在网关设备处​​顺序地接收一些数据分组。 数据分组构成正在寻址到耦合到网关设备的客户机的文件的至少一部分。 网关设备将数据分组转发到客户机并行地将文件的标识转发到远程数据中心。 数据中心对标识执行签名匹配,并将签名匹配的结果返回给网关设备。 网关设备基于来自数据中心的签名匹配的结果来确定是否从客户端机器阻止该文件。

    Cloud based just in time memory analysis for malware detection

    公开(公告)号:US11797677B2

    公开(公告)日:2023-10-24

    申请号:US17584152

    申请日:2022-01-25

    申请人: SonicWALL Inc.

    IPC分类号: G06F21/56 G06F21/53

    摘要: Methods and apparatus consistent with the present disclosure may be performed by a Cloud computing device may use instrumentation code that remains transparent to an application program that the instrumentation code has been injected into, may perform deep packet inspection (DPI) on computer data, or identify a content rating associated with computer data. In certain instances, data sets that include executable code may be received via packetized communications or be received via other means, such as, receiving a file from a data store. The present technique allows one or more processors executing instrumentation code to monitor actions performed by the program code included in a received data set. Malware can be detected using exception handling to track memory allocations of the program code included in the received data set. Furthermore, access to content associated with malware, potential malware, or with inappropriate content ratings may be blocked.

    CLOUD BASED JUST IN TIME MEMORY ANALYSIS FOR MALWARE DETECTION

    公开(公告)号:US20220222343A1

    公开(公告)日:2022-07-14

    申请号:US17584152

    申请日:2022-01-25

    申请人: SonicWALL Inc.

    IPC分类号: G06F21/56 G06F21/53

    摘要: Methods and apparatus consistent with the present disclosure may be performed by a Cloud computing device may use instrumentation code that remains transparent to an application program that the instrumentation code has been injected into, may perform deep packet inspection (DPI) on computer data, or identify a content rating associated with computer data. In certain instances, data sets that include executable code may be received via packetized communications or be received via other means, such as, receiving a file from a data store. The present technique allows one or more processors executing instrumentation code to monitor actions performed by the program code included in a received data set. Malware can be detected using exception handling to track memory allocations of the program code included in the received data set. Furthermore, access to content associated with malware, potential malware, or with inappropriate content ratings may be blocked.

    Cloud based just in time memory analysis for malware detection

    公开(公告)号:US11232201B2

    公开(公告)日:2022-01-25

    申请号:US16055958

    申请日:2018-08-06

    申请人: SonicWALL Inc.

    IPC分类号: G06F21/56 G06F21/53

    摘要: Methods and apparatus consistent with the present disclosure may be performed by a Cloud computing device may use instrumentation code that remains transparent to an application program that the instrumentation code has been injected into, may perform deep packet inspection (DPI) on computer data, or identify a content rating associated with computer data. In certain instances, data sets that include executable code may be received via packetized communications or be received via other means, such as, receiving a file from a data store. The present technique allows one or more processors executing instrumentation code to monitor actions performed by the program code included in a received data set. Malware can be detected using exception handling to track memory allocations of the program code included in the received data set. Furthermore, access to content associated with malware, potential malware, or with inappropriate content ratings may be blocked.