Invention Grant
- Patent Title: System and method for IPS and VM-based detection of suspicious objects
-
Application No.: US14228073Application Date: 2014-03-27
-
Publication No.: US09756074B2Publication Date: 2017-09-05
- Inventor: Ashar Aziz , Muhammad Amin , Osman Abdoul Ismael , Zheng Bu
- Applicant: FireEye, Inc.
- Applicant Address: US CA Milpitas
- Assignee: FireEye, Inc.
- Current Assignee: FireEye, Inc.
- Current Assignee Address: US CA Milpitas
- Agency: Rutan & Tucker, LLP
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/56 ; G06F9/455

Abstract:
A threat detection system is integrated with intrusion protection system (IPS) logic and virtual execution logic is shown. The IPS logic is configured to receive a first plurality of objects and filter the first plurality of objects by identifying a second plurality of objects as suspicious objects. The second plurality of objects is a subset of the first plurality of objects and is lesser or equal in number to the first plurality of objects. The virtual execution logic is configured to automatically verify whether any of the suspicious objects is an exploit. The virtual execution logic comprises at least one virtual machine configured to virtually process content within the suspicious objects and monitor for anomalous behaviors during the virtual processing that are indicative of exploits.
Public/Granted literature
Information query