×

MICRO-VIRTUAL MACHINE FORENSICS AND DETECTION

  • US 20170076092A1
  • Filed: 11/21/2016
  • Published: 03/16/2017
  • Est. Priority Date: 07/03/2012
  • Status: Active Grant
First Claim
Patent Images

1. One or more non-transitory computer-readable storage mediums storing one or more sequences of instructions for monitoring process behavior, which when executed by one or more processors, cause:

  • identifying one or more events occurring within an isolated environment in which a process executes, wherein said isolated environment is instantiated in response to receiving a request to execute said process;

    determining whether an actual behavior of said process executing within said isolated environment deviates from an expected behavior of the execution of the process;

    only upon determining that the process deviates from the expected behavior, storing behavior data that describes the actual behavior of the process during execution; and

    determining whether the process is compromised by analyzing the behavior data that describes the actual behavior of the process.

View all claims
  • 2 Assignments
Timeline View
Assignment View
    ×
    ×