Nova Patents
IL229531A

Malware analysis system

Abstract

This record has no abstract on file.

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

24 claims: 5 independent, 19 dependent

  1. 1
    V2 - amended 01.08.2017 - 19 - CLAIMS:1. A system, comprising: a processor configured to: receive a potential malware sample from a firewall;5 analyze the potential malware sample using a virtual machine to determine if the potential malware sample is malware, comprises to: use the virtual machine to emulate the potential malware sample;and use the virtual machine to monitor one or more behaviors of the emulated potential malware sample;and 10 automatically generate a signature if the potential malware sample is determined to be malware;and a memory coupled to the processor and configured to provide the processor with instructions.
  2. 19
    A method, comprising:25 receiving a potential malware sample from a firewall;analyzing the potential malware sample using a virtual machine to determine if the potential malware sample is malware, comprising: using the virtual machine to emulate the potential malware sample;and 02258266\68-01 V2 - amended 01.08.2017 - 22 - using the virtual machine to monitor one or more behaviors of the emulated potential malware sample;and automatically generating a signature if the potential malware sample is determined to be malware.
  3. 21
    A computer program product, the computer program product being embodied in a computer readable storage medium and comprising computer instructions for:receiving a potential malware sample from a firewall;analyzing the potential malware sample using a virtual machine to determine if the potential malware sample is malware, comprising: using the virtual machine to emulate the potential malware sample;and using the virtual machine to monitor one or more behaviors of the emulated potential malware sample;and automatically generating a signature if the potential malware sample is determined to be malware.
  4. 23
    A system, comprising:a processor configured to: receive a potential malware sample from a firewall;analyze the potential malware sample using a virtual machine to determine if the potential malware sample is malware, comprises to: use the virtual machine to emulate the potential malware sample;and use the virtual machine to monitor one or more behaviors of the emulated potential malware sample;02258266\68-01 V2 - amended 01.08.2017 - 23 - automatically generate a signature if the potential malware sample is determined to be malware;and distribute the signature to a plurality of security devices;and a memory coupled to the processor and configured to provide the processor 5 with instructions.
  5. 24
    A system, comprising:a processor configured to: monitor a plurality of network traffic flows;decrypt an encrypted network traffic flow to generate a potential malware 10 sample, wherein a preexisting signature does not match the potential malware sample;send the potential malware sample to a malware analysis device, wherein the malware analysis device executes a virtual machine to analyze the potential malware sample using the virtual machine to determine if the potential malware sample is malware, wherein the virtual machine is configured to: 15 emulate the potential malware sample;and monitor one or more behaviors of the emulated potential malware sample;receive results of the analysis by the virtual machine of the potential malware sample from the malware analysis device;20 automatically generate a signature if the potential malware sample is determined to be malware;and enforce a security policy for network access based on the signature;and a memory coupled to the processor and configured to provide the processor with instructions. 25 25. A system, comprising: a processor configured to: analyze a potential malware sample using a virtual machine to determine if the potential malware sample is malware, wherein a signature does not exist for the potential malware sample, comprises to: 30 use the virtual machine to emulate the potential malware sample;and 02258266\68-01 V2 - amended 01.08.2017 - 24 - use the virtual machine to monitor one or more behaviors of the emulated potential malware sample;automatically generate a signature if the potential malware sample is determined to be malware;5 add a firewall rule based on the signature;and enforce the firewall rule using the signature;and a memory coupled to the processor and configured to provide the processor with instructions. 02258266\68-01