The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Oct. 01, 2019

Filed:

Jan. 15, 2016
Applicant:

Fireeye, Inc., Milpitas, CA (US);

Inventors:

James Bennett, Santa Clara, CA (US);

Zheng Bu, Fremont, CA (US);

Assignee:

FireEye, Inc., Milpitas, CA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
H04L 29/06 (2006.01); G06F 9/455 (2018.01); G06F 17/27 (2006.01); G06F 16/28 (2019.01);
U.S. Cl.
CPC ...
H04L 63/1425 (2013.01); G06F 9/45558 (2013.01); G06F 16/285 (2019.01); G06F 17/2705 (2013.01); H04L 63/145 (2013.01); H04L 63/1416 (2013.01); G06F 2009/45587 (2013.01);
Abstract

Techniques for detecting malicious behavior of content (object) are described herein. An object is processed within a virtual machine. Responsive to receiving the result of the processing (response object), a parser parses the response object into a plurality of sub-objects. The plurality of sub-objects include a first sub-object and a second sub-object. A first behavior match result is determined based, at least in part, on whether information within the first sub-object corresponds to a identifiers associated with malicious activity. Also, a second behavior match result is determined based, at least in part, on whether information within the second sub-object corresponds to identifiers associated with malicious activity. Thereafter, the first and second behavior match results are aggregated to produce an aggregated result, wherein a malicious behavior score is calculated based, at least in part, on the aggregated result. The object is classified according to the malicious behavior score.


Find Patent Forward Citations

Loading…