×

Micro-virtual machine forensics and detection

  • US 9,501,310 B2
  • Filed: 12/28/2015
  • Issued: 11/22/2016
  • Est. Priority Date: 07/03/2012
  • Status: Active Grant
First Claim
Patent Images

1. One or more non-transitory computer-readable storage mediums storing one or more sequences of instructions for monitoring process behavior, which when executed by one or more processors, cause:

  • identifying an action performed by a process executing within an isolated environment, wherein identifying comprises;

    monitoring a list of processes to determine when a new process is initiated within the isolated environment,monitoring events associated with a guest operating system executing within said isolated environment, andmonitoring events associated with said isolated environment, wherein said events includes attempts to modify page tables and attempts to access CPU registers;

    determining whether an actual behavior of said process executing within said isolated environment deviates from an expected behavior of the execution of the process;

    upon determining that that the process deviates from the expected behavior, initiating monitoring activity of the process by storing behavior data that describes the actual behavior of the process during execution; and

    determining whether the process is compromised by analyzing the behavior data that describes the actual behavior of the process.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×