SYSTEM AND METHOD FOR DETECTING MALICIOUS TRAFFIC USING A VIRTUAL MACHINE CONFIGURED WITH A SELECT SOFTWARE ENVIRONMENT
Patent №
US 9,356,944
Granted
2016-05-31
Filed 2013
Owner
FIREEYE, INC.
Lab
—
AI components
2
kr · hardware
Assignment
Recorded
Dataset
AIPD
2023_r1 edition
Application
13931633
The system comprises a traffic analysis device in communication with a network device. The traffic analysis device can analyze network traffic received over a communication network and duplicate at least select network communications within the network traffic having characteristics associated with malicious traffic when the network communications are determined through heuristic analysis to satisfy a heuristic threshold. The network device comprises a controller in communication with one or more virtual machines that are configured to (i) receive the duplicated network communications from the traffic analysis device, (ii) monitor a behavior of a first virtual machine of the one or more virtual machines in response to processing of the duplicated network communications within the first virtual machine, (iii) identify an anomalous behavior as an unexpected occurrence in the monitored behavior, and (iv) determine, based on the identified anomalous behavior, the presence of the malicious traffic in the duplicated network communications.
AI classification
Ownership
FIREEYE, INC.
assignment · 384570953
Assignors
AZIZ, ASHAR
On an employer assignment, the assignors are typically the inventors.