- Patent Title: Sample-specific sandbox configuration based on endpoint telemetry
-
Application No.: US15468636Application Date: 2017-03-24
-
Publication No.: US10586040B2Publication Date: 2020-03-10
- Inventor: Lars Haukli , Felix Leder , Kevin Roundy
- Applicant: CA, Inc.
- Applicant Address: US CA San Jose
- Assignee: CA, Inc.
- Current Assignee: CA, Inc.
- Current Assignee Address: US CA San Jose
- Agency: Maschoff Brennan
- Main IPC: G06F21/53
- IPC: G06F21/53 ; G06F21/56 ; H04L29/06

Abstract:
A method for determining sandbox configurations for malware analysis is described. In one embodiment, the method may include receiving a plurality of files, extracting at least one element from at least one file from the plurality of files, identifying one or more properties associated with an endpoint, determining a correlation between the at least one extracted element and the one or more properties of the endpoint, and determining one or more sandbox configurations based at least in part on the determined correlation. In some cases, the endpoint is related to at least one of the plurality of files.
Public/Granted literature
- US20180276371A1 SAMPLE-SPECIFIC SANDBOX CONFIGURATION BASED ON ENDPOINT TELEMETRY Public/Granted day:2018-09-27
Information query