发明名称 MICROVISOR-BASED MALWARE DETECTION ENDPOINT ARCHITECTURE
摘要 A threat-aware microvisor may be deployed in a malware detection endpoint architecture and execute on an endpoint to provide exploit and malware detection within a network environment. Exploit and malware detection on the endpoint may be performed in accordance with one or more processes embodied as software modules or engines configured to detect suspicious and/or malicious behaviors of an operating system process (object), and to correlate and classify the detected behaviors as indicative of malware. Detection of suspicious and/or malicious behaviors may be performed by static and dynamic analysis of the object. Static analysis may perform examination of the object to determine whether it is suspicious, while dynamic analysis may instrument the behavior of the object as the operating system process runs via capability violations of, e.g. operating system events. A behavioral analysis logic engine and a classifier may thereafter cooperate to perform correlation and classification of the detected behaviors.
申请公布号 WO2016109042(A1) 申请公布日期 2016.07.07
申请号 WO2015US61238 申请日期 2015.11.18
申请人 FIREEYE, INC. 发明人 ISMAEL, OSMAN ABDOUL;AZIZ, ASHAR
分类号 G06F21/56;G06F9/455 主分类号 G06F21/56
代理机构 代理人
主权项
地址