×

Micro-virtual machine forensics and detection

  • US 10,607,007 B2
  • Filed: 11/21/2016
  • Issued: 03/31/2020
  • Est. Priority Date: 07/03/2012
  • Status: Active Grant
First Claim
Patent Images

1. One or more non-transitory computer-readable storage mediums storing one or more sequences of instructions for monitoring process behavior, which when executed by one or more processors, cause:

  • identifying one or more events occurring within an isolated environment in which a process executes, wherein the isolated environment is instantiated in response to receiving a request to execute the process;

    determining whether an actual behavior of the process executing within the isolated environment deviates from an expected behavior of the execution of the process based upon a set of events associated with the process that pertain to the process accessing or attempting to access an encryption API or an API associated with sleeping;

    only upon determining that the process deviates from the expected behavior, storing behavior data that describes the actual behavior of the process during execution, the storing behavior data includes creating a snapshot of the isolated environment; and

    determining whether the process is compromised by analyzing the behavior data that describes the actual behavior of the process.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×