×

System and method for detecting anomalous behaviors using a virtual machine environment

  • US 9,661,018 B1
  • Filed: 05/27/2016
  • Issued: 05/23/2017
  • Est. Priority Date: 04/01/2004
  • Status: Active Grant
First Claim
Patent Images

1. A network device comprising:

  • a memory storage device; and

    a hardware controller operating in cooperation with one or more virtual machines that are based on software modules stored within the memory storage device, the hardware controller to (i) select an orchestration pattern based on a type of data received over a network for analysis, the orchestration pattern identifies at least one or more ports accessible by at least a first virtual machine of the one or more virtual machines during processing of the data and coordinates network activities by the one or more virtual machines based on the selected orchestration pattern, (ii) monitor behaviors of at least the first virtual machine of the one or more virtual machines processing data received over the network, (iii) identify at least one anomalous behavior that includes either a communication anomaly or an execution anomaly, and (iv) detect, based on the identified at least one anomalous behavior, a presence of malware in the first virtual machine in response to identifying the at least one anomalous behavior that includes one or more accesses of a port other than the one or more ports identified by the orchestration pattern.

View all claims
  • 5 Assignments
Timeline View
Assignment View
    ×
    ×