发明名称 INTERCEPTION AND POLICY APPLICATION FOR MALICIOUS COMMUNICATIONS
摘要 Disclosed herein are system, method, and computer program product embodiments for adapting to malware activity on a compromised computer system. An embodiment operates by detecting an adversary operating malware on a compromised system. A stream of network communications associated with adversary is intercepted. The stream of network communications includes a command and control channel of the adversary. The stream of network communications is accessed. An emulation of the command and control channel is provided. An analysis of the accessed stream of traffic is executed. A plurality of response mechanisms is provided. The plurality of response mechanisms is based in part on the analysis of the stream of network communications and a custom policy language tailored for the malware.
申请公布号 WO2014209459(A1) 申请公布日期 2014.12.31
申请号 WO2014US32676 申请日期 2014.04.02
申请人 THE MITRE CORPORATION 发明人 DICATO, STEPHEN, RALPH. JR.;FAYETTE, DANIEL, KENNETH;O'BOYLE, TODD, AARON
分类号 G06F21/56 主分类号 G06F21/56
代理机构 代理人
主权项
地址