×

Methods and apparatus for control and detection of malicious content using a sandbox environment

  • US 9,081,959 B2
  • Filed: 11/30/2012
  • Issued: 07/14/2015
  • Est. Priority Date: 12/02/2011
  • Status: Active Grant
First Claim
Patent Images

1. A non-transitory processor-readable medium storing code representing instructions to be executed by a processor, the code comprising code to cause the processor to:

  • receive a set of indications of predetermined allowed behavior specific to an application;

    initiate an instance of the application within a sandbox environment;

    receive, from a monitor module associated with the sandbox environment, a set of indications of actual behavior of the instance of the application in response to initiating the instance of the application within the sandbox environment;

    define an indication associated with an anomalous behavior in response to at least one indication from the set of indications of actual behavior not corresponding to an indication from the set of indications of predetermined allowed behavior, the indication associated with the anomalous behavior includes a trace associated with a source of the anomalous behavior;

    define, based on the set of indications of actual behavior and the indication associated with the anomalous behavior, an evaluation tree to include (1) a node associated with the instance of the application and (2) a node associated with the source of the anomalous behavior as a child of the node associated with the instance of the application; and

    send a report based on the evaluation tree.

View all claims
  • 8 Assignments
Timeline View
Assignment View
    ×
    ×