Invention Grant
- Patent Title: System and method of detecting malicious traffic while reducing false positives
- Patent Title (中): 检测恶意流量同时减少误报的系统和方法
-
Application No.: US14012945Application Date: 2013-08-28
-
Publication No.: US08776229B1Publication Date: 2014-07-08
- Inventor: Ashar Aziz
- Applicant: FireEye, Inc.
- Applicant Address: US CA Milpitas
- Assignee: FireEye, Inc.
- Current Assignee: FireEye, Inc.
- Current Assignee Address: US CA Milpitas
- Agency: Blakely, Sokoloff, Taylor & Zafman LLP
- Main IPC: G06F21/00
- IPC: G06F21/00 ; H04L29/06 ; G06F21/56

Abstract:
A system comprises a traffic analysis device and a network device. The traffic analysis device is configured to analyze network traffic received over a communication network and duplicate at least select network communications within the network traffic having characteristics associated with malicious traffic when determined through heuristic analysis to satisfy a heuristic threshold. The network device comprises a controller in communication with one or more virtual machines that are configured to (i) receive the duplicated network communications from the traffic analysis device, (ii) monitor a behavior of a first virtual machine of the one or more virtual machines in response to processing of the duplicated network communications within the first virtual machine, (iii) identify an anomalous behavior as an unexpected occurrence in the monitored behavior, and (iv) determine, based on the identified anomalous behavior, the presence of the malicious traffic in the duplicated network communications.
Information query