Zscaler, Inc.
Dynamic rules engine in a cloud-based sandbox
Last updated:
Abstract:
Computer-implemented systems and methods include receiving unknown content in a cloud-based sandbox; performing an analysis of the unknown content in the cloud-based sandbox, to obtain a score to determine whether or not the unknown content is malware; obtaining events based on the analysis; running one or more rules on the events; and adjusting the score based on a result of the one or more. The systems and methods can include classifying the unknown content as malware or clean based on the adjusted score. The analysis can include a static analysis and a dynamic analysis, with the events generated based thereon.
Status:
Application
Type:
Utility
Filling date:
30 Jan 2020
Issue date:
24 Jun 2021