×

Micro-virtual machine forensics and detection

  • US 9,092,625 B1
  • Filed: 12/07/2012
  • Issued: 07/28/2015
  • Est. Priority Date: 07/03/2012
  • Status: Active Grant
First Claim
Patent Images

1. One or more non-transitory computer-readable storage mediums storing one or more sequences of instructions for monitoring task behavior in a virtual machine, which when executed by one or more processors, causes:

  • executing a plurality of tasks in a plurality of virtual machines executing in a computing environment, wherein each task executes in a separate virtual machine instantiated for the particular task;

    identifying an action performed by a first task of the plurality of tasks, wherein the first task is executing in a first virtual machine;

    analyzing the action in relation to a set of heuristics;

    based on the analysis, initiating a data collection process, wherein the data comprises information about events occurring in the first virtual machine,wherein the set of heuristics comprises execution of the one or more sequences of instructions to further cause;

    identifying a suspected file;

    determining all files modified after the introduction of the suspected file;

    determining what portion of the modified files comprise files of a first file type; and

    if the portion of the modified files exceeds a predetermined threshold, then classifying the suspected file as malware.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×