The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jul. 17, 2018

Filed:

Apr. 17, 2017
Applicant:

Fireeye, Inc., Milpitas, CA (US);

Inventors:

Yasir Khalid, Fremont, CA (US);

Muhammad Amin, San Francisco, CA (US);

Emily Jing, Fremont, CA (US);

Muhammad Rizwan, Singapore, SG;

Assignee:

FireEye, Inc., Milpitas, CA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 21/56 (2013.01); G06F 21/53 (2013.01); G06F 9/455 (2018.01);
U.S. Cl.
CPC ...
G06F 21/56 (2013.01); G06F 21/53 (2013.01); G06F 21/564 (2013.01); G06F 21/566 (2013.01); G06F 2009/45575 (2013.01); G06F 2009/45587 (2013.01);
Abstract

Techniques for efficient malicious content detection in plural versions of a software application are described. According to one embodiment, the computerized method includes installing a plurality of different versions of a software application concurrently within a virtual machine and selecting a subset of the plurality of versions of the software application that are concurrently installed within the virtual machine. Next, one or more software application versions of the subset of the plurality of versions of the software application are processed to access a potentially malicious content suspect within the virtual machine, without switching to another virtual machine. The behaviors of the potentially malicious content suspect during processing by the one or more software application versions are monitored to detect behaviors associated with a malicious attack. Thereafter, information associated with the detected behaviors pertaining to a malicious attack is stored, and an alert with respect to the malicious attack is issued.


Find Patent Forward Citations

Loading…