Enriching malware information for use with network security analysis and malware detection
Abstract:
One or more malware data pipelines is configured to provide malware data that includes original data fields identifying information for detected malware instances and corresponding files that are associated with the detected malware instances. Malware enrichment circuitry is configured to identify additional information to include in enriched data fields for the detected malware instances, the additional information being identified from one or more of: the original data fields, the corresponding files, and one or more third party services. A datastore is configured to store the malware data with the original data fields and the enriched data fields, wherein the datastore includes indices for both the original data fields and the enriched data fields to permit for searching and analysis across the original data fields and the enriched data fields.
Public/Granted literature
Information query
Patent Agency Ranking
0/0