发明名称 DETECTING TIMING ANOMALIES
摘要 Disclosed herein are system, method, and computer program product embodiments for adapting to malware activity on a compromised computer system. An embodiment operates by detecting an active adversary operating malware on a compromised system. A stream of data traffic associated with active adversary is intercepted. The stream of data traffic includes a command and control channel of the active adversary. The stream of data traffic is accessed. An emulation of the command and control channel is provided. An analysis of the accessed stream of traffic is executed. A plurality of response mechanisms is provided. The plurality of response mechanisms is based in part on the analysis of the stream of data traffic and a custom policy language tailored for the malware.
申请公布号 EP2992445(A1) 申请公布日期 2016.03.09
申请号 EP20140791368 申请日期 2014.04.02
申请人 THE MITRE CORPORATION 发明人 LEIBNER, DARROW, PAINE;CERRUTI, ALESSANDRO, PAOLO
分类号 G01S19/21;H04K3/00 主分类号 G01S19/21
代理机构 代理人
主权项
地址