发明名称 EMULATING SHELLCODE ATTACKS
摘要 A system includes one or more "BotMagnet" modules that are exposed to infection by malicious code. The BotMagnets may include one or more virtual machines hosing operating systems in which malicious code may be installed and executed without exposing sensitive data or other parts of a network. In particular, outbound traffic may be transmitted to a Sinkhole module that implements a service requested by the outbound traffic and transmits responses to the malicious code executing within the BotMagnet. In the case of shellcode attacks, unsuccessful attacks may be emulated by selecting a corresponding emulator that will receive and execute instructions, as would a successful shellcode attack. Events occurring on the BotMagnet and Sinkhole are correlated and used to characterize the malicious code. The characterization may be transmitted to other computer systems in order to detect instances of the malicious code.
申请公布号 WO2015171789(A1) 申请公布日期 2015.11.12
申请号 WO2015US29501 申请日期 2015.05.06
申请人 ATTIVO NETWORKS INC. 发明人 VISSAMSETTY, VENU;SINGH, NAVTEJ;KAJEKAR, SACHIN
分类号 G06F11/00;G06F12/14 主分类号 G06F11/00
代理机构 代理人
主权项
地址