Invention Grant
US09591015B1 System and method for offloading packet processing and static analysis operations
有权
用于卸载数据包处理和静态分析操作的系统和方法
- Patent Title: System and method for offloading packet processing and static analysis operations
- Patent Title (中): 用于卸载数据包处理和静态分析操作的系统和方法
-
Application No.: US14229541Application Date: 2014-03-28
-
Publication No.: US09591015B1Publication Date: 2017-03-07
- Inventor: Muhammad Amin , Masood Mehmood , Ramaswamy Ramaswamy , Madhusudan Challa , Shrikrishna Karandikar
- Applicant: FireEye, Inc.
- Applicant Address: US CA Milpitas
- Assignee: FireEye, Inc.
- Current Assignee: FireEye, Inc.
- Current Assignee Address: US CA Milpitas
- Agency: Rutan & Tucker, LLP
- Main IPC: H04L29/06
- IPC: H04L29/06

Abstract:
According to one embodiment, a network security device configured to detect malicious content within received network traffic comprises a traffic analysis controller (TAC) is provided. The traffic analysis controller comprises a network processing unit (NPU) and is configured to perform at least packet processing on the NPU with a set of pre-filters. In addition, the network security device further comprises a central processing unit (CPU) and is configured to perform at least virtual machine (VM)-based processing. The set of pre-filters is configured to distribute objects of received network traffic such that either static analysis or dynamic analysis may be performed on an object to determine whether the object contains malicious content. The static analysis may be performed on either the NPU or the CPU while the dynamic analysis is performed on the CPU.
Information query