Invention Grant
- Patent Title: Method and server for determining malicious files in network traffic
-
Application No.: US16249004Application Date: 2019-01-16
-
Publication No.: US11122061B2Publication Date: 2021-09-14
- Inventor: Nikita Igorevich Kislitsin , Nikolay Nikolaevich Andreev
- Applicant: Group IB TDS, Ltd
- Applicant Address: RU Moscow
- Assignee: Group IB TDS, Ltd
- Current Assignee: Group IB TDS, Ltd
- Current Assignee Address: RU Moscow
- Agency: BCF LLP
- Priority: RURU2018101763 20180117
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F9/455 ; G06F21/56

Abstract:
There is disclosed a method for determining malicious files in a network traffic, the method executable by a server. The method comprises: receiving the network traffic from a data communication network, retrieving a plurality of files from the network traffic, analyzing the plurality of files in order to detect at least one suspicious file, running the at least one suspicious file in at least one virtual machine, the at least one virtual machine associated with a set of the status parameters, determining changes in the set of the status parameters of the at least of one virtual machine, analyzing the changes in the set of status parameters using a set of the analysis rules such that to classify the at least one suspicious file as a malicious file based on the changes in the set of status parameters being indicative of the at least one file being the malicious file.
Public/Granted literature
- US20190222591A1 METHOD AND SERVER FOR DETERMINING MALICIOUS FILES IN NETWORK TRAFFIC Public/Granted day:2019-07-18
Information query