The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Aug. 03, 2021

Filed:

May. 06, 2019
Applicant:

Fireeye, Inc., Milpitas, CA (US);

Inventors:

Ashar Aziz, Coral Gables, FL (US);

Wei-Lung Lai, Cupertino, CA (US);

Jayaraman Manni, San Jose, CA (US);

Assignee:

FireEye, Inc., Milpitas, CA (US);

Attorney:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
G06F 13/30 (2006.01); H04L 29/06 (2006.01); G06F 21/56 (2013.01); G06F 9/00 (2006.01); G06F 21/00 (2013.01); G06F 21/55 (2013.01); G06F 9/455 (2018.01);
U.S. Cl.
CPC ...
H04L 63/1416 (2013.01); G06F 9/00 (2013.01); G06F 21/00 (2013.01); G06F 21/554 (2013.01); G06F 21/56 (2013.01); G06F 21/561 (2013.01); H04L 63/145 (2013.01); H04L 63/1491 (2013.01); G06F 9/455 (2013.01); G06F 2221/034 (2013.01);
Abstract

Exemplary systems and methods for malware attack detection and identification are provided. A malware detection and identification system a controller that features an analysis environment including a virtual machine. The analysis environment to (1) receive data by the virtual machine of the analysis environment and identify a portion of the data that have been received from one or more untrusted, (2) monitor state information associated with the identified portion of the data during execution by the virtual machine, (3) identify an outcome of the state information by tracking the state information during execution of the identified portion of the data by the virtual machine, and (4) determine whether the identified outcome comprises a redirection in control flow during execution by the virtual machine of the portion of the data, the redirection in the control flow constituting an unauthorized activity.


Find Patent Forward Citations

Loading…