The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jun. 02, 2020

Filed:

Dec. 27, 2016
Applicant:

Fireeye, Inc., Milpitas, CA (US);

Inventors:

Alexander Otvagin, Milpitas, CA (US);

Mumtaz Siddiqui, Milpitas, CA (US);

Assignee:

FireEye, Inc., Milpitas, CA (US);

Attorney:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
G06F 21/56 (2013.01); G06F 21/57 (2013.01); G06F 21/53 (2013.01); H04L 29/06 (2006.01); H04W 12/12 (2009.01);
U.S. Cl.
CPC ...
G06F 21/53 (2013.01); G06F 21/56 (2013.01); G06F 21/577 (2013.01); H04L 63/145 (2013.01); H04W 12/1208 (2019.01); G06F 2221/033 (2013.01); G06F 2221/2151 (2013.01);
Abstract

A scalable, threat detection system features computing nodes including a first computing node and a second computing node operating as a cluster. Each computing node features an analysis coordinator and an object analyzer. The analysis coordinator is configured to conduct an analysis of metadata associated with a suspicious object that is to be analyzed for malware, where the metadata being received from a remotely located network device and to store a portion of the metadata within a data store. The object analyzer is configured to retrieve the portion of the metadata from the data store, monitor a duration of retention of the metadata in the data store, and determine whether a timeout event has occurred for the object associated with the metadata based on retention of the metadata within the data store that exceeds a timeout value included as part of the metadata associated with the suspicious object for malware.


Find Patent Forward Citations

Loading…