发明名称 Systems and methods for analyzing malicious PDF network content
摘要 Systems and methods for analyzing malicious PDF network content are provided herein. According to some embodiments, a PDF parser examines a body portion of a PDF document received over a network and intended for a digital device and determines if one or more suspicious characteristics indicative of malicious network content are included in the examined body portion of the PDF document. The examined body portion of the PDF document is lesser in size than an entirety of the body portion of the PDF document. When the portion of the body section of the PDF document is determined to include one or more suspicious characteristics indicative of malicious network content, the PDF document is provided to one or more virtual machines associated with the digital device to verify the inclusion of malicious network content in the portion of the body section of the PDF document. Such verification comprises execution of a PDF reader application by the one or more virtual machines to process the portion of the body section of the PDF document and monitor behavior of the PDF document so as to determine if the portion of the body section of the PDF document includes malicious network content.
申请公布号 US9438622(B1) 申请公布日期 2016.09.06
申请号 US201514673292 申请日期 2015.03.30
申请人 FireEye, Inc. 发明人 Staniford Stuart Gresley;Aziz Ashar
分类号 H04L29/06;G06F21/56 主分类号 H04L29/06
代理机构 Rutan & Tucker, LLP 代理人 Rutan & Tucker, LLP
主权项 1. A system comprising: a processor; and a memory device coupled to the processor, the memory device comprises a portable document format (PDF) parser that, when executed by the processor, examines one or more portions of a PDF document to determine if one or more suspicious characteristics indicative of malicious network content are included in the one or more examined portions of the PDF document, wherein the one or more examined portions of the PDF document comprise less than an entirety of the PDF document, and one or more virtual machines to receive the PDF document in response to the one or more examined portions of the PDF document being determined to include one or more suspicious characteristics indicative of malicious network content, the one or more virtual machines to process at least the one or more examined portions of the PDF document so as to determine whether the PDF document includes malicious network content.
地址 Milpitas CA US