Invention Grant
- Patent Title: Technique for verifying exploit/malware at malware detection appliance through correlation with endpoints
-
Application No.: US17087550Application Date: 2020-11-02
-
Publication No.: US11979428B1Publication Date: 2024-05-07
- Inventor: Osman Abdoul Ismael , Ashar Aziz
- Applicant: FireEye, Inc.
- Applicant Address: US CA Milpitas
- Assignee: Musarubra US LLC
- Current Assignee: Musarubra US LLC
- Current Assignee Address: US TX Plano
- Agency: Rutan & Tucker, LLP
- Main IPC: H04L9/40
- IPC: H04L9/40 ; G06F21/53

Abstract:
A technique verifies a determination of an exploit or malware in an object at a malware detection system (MDS) appliance through correlation of behavior activity of the object running on endpoints of a network. The appliance may analyze the object to render a determination that the object is suspicious and may contain the exploit or malware. In response, the MDS appliance may poll the endpoints (or receive messages pushed from the endpoints) to determine as to whether any of the endpoints may have analyzed the suspect object and observed its behaviors. If the object was analyzed, the endpoints may provide the observed behavior information to the appliance, which may then correlate that information, e.g., against correlation rules, to verify its determination of the exploit or malware. In addition, the appliance may task the endpoints to analyze the object, e.g., during run time, to determine whether it contains the exploit and provide the results to the appliance for correlation.
Public/Granted literature
- US2760111A Magnetron amplifier Public/Granted day:1956-08-21
Information query