发明名称 TRAFFIC SIMULATION TO IDENTIFY MALICIOUS ACTIVITY
摘要 Systems and methods may simulate traffic to identify malicious activity. A dynamic analysis system comprising a processor in communication with a network may receive a copy of a malware program and load the copy of the malware program into a simulated endpoint. The system may monitor simulated endpoint network traffic to or from the simulated endpoint, assess the simulated endpoint network traffic to determine a source and/or destination for the simulated endpoint network traffic and/or content of the simulated endpoint network traffic, and capture and store metadata associated with, the simulated endpoint network traffic. A comparison system may compare simulated network traffic metadata to observed network traffic metadata to determine whether the metadata are statistically similar. When the metadata are not statistically similar, the system may generate a low infection confidence score. When the metadata are statistically similar, the system may generate a high infection confidence score.
申请公布号 US2014090058(A1) 申请公布日期 2014.03.27
申请号 US201314015663 申请日期 2013.08.30
申请人 DAMBALLA, INC. 发明人 WARD JOSEPH;HOBSON ANDREW
分类号 H04L29/06 主分类号 H04L29/06
代理机构 代理人
主权项
地址
您可能感兴趣的专利