Fortinet, Inc.
EARLY MALWARE DETECTION IN ON-THE-FLY SECURITY SANDBOXES USING RECURSIVE NEURAL NETWORKS (RNNS)TO CAPTURE RELATIONSHIPS IN BEHAVIOR SEQUENCES ON DATA COMMUNICATION NETWORKS
Last updated:
Abstract:
A file copy is executed in a virtual runtime environment that tracks behavior using RNN taking runtime behavior of at least a first time into account with current runtime behavior at a second time. This is responsive to not finding a known signature for suspicious activity during virus scanning. A behavior sequence is identified on-the-fly during file copy execution that is indicative of malware, prior to completing the execution, the behavior sequence involving at least two actions taken at different times during file copy execution. Responsive to the identification, the execution is terminated and the virtual runtime environment is returned to the pool of available virtual runtime environments.
Status:
Application
Type:
Utility
Filling date:
9 Dec 2020
Issue date:
9 Jun 2022