Fortinet, Inc.
PERFORMING THREAT DETECTION BY SYNERGISTICALLY COMBINING RESULTS OF STATIC FILE ANALYSIS AND BEHAVIOR ANALYSIS

Last updated:

Abstract:

Systems and methods are described for synergistically combining static file based detection and behavioral analysis to improve both threat detection time and accuracy. An endpoint security solution running on an endpoint device generates a static analysis score by performing a static file analysis on files associated with a process initiated on the endpoint device. When the static analysis score meets or exceeds a static analysis threshold, then a network security platform treats the process as malicious and blocks execution of the process. When the static analysis score is less than the static analysis threshold, then the endpoint security solution obtains a dynamic analysis score for the process. The network security platform treats the process as malicious and causes execution of the process to be blocked based on a function of the static analysis score and the dynamic analysis score.

Status:
Application
Type:

Utility

Filling date:

31 Dec 2019

Issue date:

1 Jul 2021