×

System and method for detecting exfiltration content

  • US 10,467,414 B1
  • Filed: 04/02/2018
  • Issued: 11/05/2019
  • Est. Priority Date: 03/13/2013
  • Status: Active Grant
First Claim
Patent Images

1. A computer-implemented method for detecting exfiltration of data, comprising:

  • executing a malicious content suspect within a virtual machine that is configured to simulate a target operating environment, wherein the malicious content suspect comprises content that is potentially malicious;

    performing a packet inspection on attempted outbound network traffic by a packet inspector running within the virtual machine, the packet inspection to determine whether a portion of the attempted outbound network traffic matches one or more portions of predetermined network traffic patterns or signatures;

    determining whether the attempted outbound network traffic includes at least one environmental property, which is unique or distinctive of the target operating environment including at least the virtual machine, by at least determining the portion of the attempted outbound network traffic matches the one or more portions of predetermined network traffic patterns or signatures, the match indicates that the malicious content suspect is attempting to perform an exfiltration of data; and

    transmitting an alert indicating that the malicious content suspect is attempting to perform an exfiltration of data from the virtual machine based on determining that the attempted outbound network traffic includes the at least one environmental property of the target operating environment and precluding migration of the attempted outbound network traffic outside of the virtual machine when the attempted outbound network traffic includes the at least one environmental property that is unique or distinctive to the target operating environment.

View all claims
  • 5 Assignments
Timeline View
Assignment View
    ×
    ×