Patent · US Active

System, apparatus and method for automatically verifying exploits within suspect objects and highlighting the display information associated with the verified exploits

US10476909B1 · kind B1 · utility

23Cited by
362References
32Claims
0Family size

Assignee

Inventors

Key dates

Filing dateOct 19, 2016
Grant dateNov 12, 2019
Priority date
Expiry dateAug 4, 2037

Classification

  • Technology area (CPC H)Electricity
  • CPC primaryH04L63/145
  • WIPO fieldComputer technology
  • WIPO sectorElectrical engineering

Abstract

According to one embodiment, a threat detection system comprising an intrusion protection system (IPS) logic, a virtual execution logic and a reporting logic is shown. The IPS logic is configured to receive a first plurality of objects and analyze the first plurality of objects to identify a second plurality of objects as potential exploits, the second plurality of objects being a subset of the first plurality of objects and being lesser or equal in number to the first plurality of objects. The virtual execution logic including at least one virtual machine configured to process content within each of the second plurality of objects and monitor for anomalous behaviors during the processing that are indicative of exploits to classify that a first subset of the second plurality of objects includes one or more verified exploits. The reporting logic configured to provide a display of exploit information associated with the one or more verified exploits.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.