Patent · US Active

Micro-virtual machine forensics and detection

US9223962B1 · kind B1 · utility

51Cited by
6References
30Claims
0Family size

Assignee

Inventors

Key dates

Filing dateDec 7, 2012
Grant dateDec 29, 2015
Priority date
Expiry dateFeb 25, 2033

Classification

  • Technology area (CPC G)Physics
  • CPC primaryG06F2221/034
  • WIPO fieldComputer technology
  • WIPO sectorElectrical engineering

Abstract

The execution of a process within a VM may be monitored, and when a trigger event occurs, additional monitoring is initiated, including storing behavior data describing the real-time events taking place inside the VM. This behavior data may then be compared to information about the expected behavior of that type of process in order to determine whether malware has compromised the VM.

Source: USPTO / EPO open patent data. Objective bibliographic and citation counts.