会员体验
专利管家(专利管理)
工作空间(专利管理)
风险监控(情报监控)
数据分析(专利分析)
侵权分析(诉讼无效)
联系我们
交流群
官方交流:
QQ群: 891211   
微信请扫码    >>>
现在联系顾问~
热词
    • 2. 发明授权
    • Malware detection using risk analysis based on file system and network activity
    • 基于文件系统和网络活动的风险分析的恶意软件检测
    • US08479276B1
    • 2013-07-02
    • US12981072
    • 2010-12-29
    • Alex VaystikhRobert PolanskySamir Dilipkumar SaklikarLiron Liptz
    • Alex VaystikhRobert PolanskySamir Dilipkumar SaklikarLiron Liptz
    • G06F7/04
    • G06F21/577
    • A virtual machine computing platform uses a security virtual machine (SVM) in operational communications with a risk engine which has access to a database including stored patterns corresponding to patterns of filtered operational data that are expected to be generated during operation of the monitored virtual machine when malware is executing. The stored patterns may have been generated during preceding design and training phases. The SVM is operated to (1) receive raw operational data from a virtual machine monitor, the raw operational data obtained from file system operations and network operations of the monitored virtual machine; (2) apply rule-based filtering to the raw operational data to generate filtered operational data; and (3) in conjunction with the risk engine, perform a mathematical (e.g., Bayesian) analysis based on the filtered operational data and the stored patterns in the database to calculate a likelihood that the malware is executing in the monitored virtual machine. A control action is taken if the likelihood is sufficiently high.
    • 虚拟机计算平台使用安全虚拟机(SVM)与风险引擎进行操作通信,所述风险引擎可以访问数据库,所述数据库包括对应于预期在所监视的虚拟机的操作期间生成的经过过滤的操作数据的模式的存储模式, 恶意软件正在执行。 存储的模式可能在以前的设计和训练阶段已经生成。 运行SVM以(1)从虚拟机监视器接收原始操作数据,从文件系统操作获得的原始操作数据和被监视虚拟机的网络操作; (2)对原始操作数据应用基于规则的过滤以生成经过滤的操作数据; 和(3)结合风险引擎,基于过滤的操作数据和数据库中存储的模式执行数学(例如,贝叶斯)分析,以计算恶意软件在被监视的虚拟机中执行的可能性。 如果可能性足够高,则采取控制措施。