Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

5 results about "Virtual machine introspection" patented technology

In computing, virtual machine introspection (VMI) is a technique "for monitoring the runtime state of a system-level virtual machine (VM)", which is helpful for debugging or forensic analysis. The term introspection in application to the virtual machines was introduced by Garfinkel and Rosenblum. They invented an approach for "protecting a security application from attack by malicious software" and called it VMI. Now VMI is a common term for different virtual machine forensics and analysis methods. VMI-based approaches are widely used for security applications, software debugging, and systems management.

Multi-view malicious software detection method and system based on high-speed introspection of virtual machine

The invention discloses a multi-view fusion cloud native malicious software detection method and system based on high-speed introspection of a virtual machine, and the method comprises the steps: 1), deploying a high-speed introspection module in a monitoring layer of the virtual machine, capturing an API call sequence of an internal process of a target virtual machine from the outside in a safe and low-invasion manner, and structuring the API call sequence into a runtime log; (2) the API calling sequence is regarded as a sentence, and a Word2Vec model is used for training to generate a structure embedding vector of the API; then, constructing a directed heterogeneous graph containing a file, a thread and API calling for each sample, taking the structure embedded vector as an initial feature of an API node, encoding the graph by using a graph attention network, and extracting a structure context feature vector; 3) extracting an API official function description text by utilizing the pre-training language model to generate a semantic embedding vector; constructing a directed heterogeneous graph for each sample, replacing the initial features of the API nodes in the graph with the semantic embedding vector, coding the graph by using the graph attention network again, and extracting a functional semantic feature vector; 4) firstly performing function classification on the APIs, and performing dimensionality reduction on the complete API calling sequence to obtain a limited function state sequence; constructing a Markov transition probability matrix for the state sequence of each sample, and selectively stacking a multi-order transition matrix to form a multi-channel feature tensor; inputting the feature tensor into a convolutional neural network for coding, and extracting a macroscopic behavior evolution feature vector; 5) splicing the structure context feature vector, the function semantic feature vector and the behavior evolution feature vector to form a final comprehensive feature vector; and inputting the comprehensive feature vector into a multi-layer perceptron classifier, and training the classifier in an end-to-end manner to enable an output sample of the classifier to be a classification result of malicious software or benign software.
Owner:ZHEJIANG UNIV OF TECH

A method for detecting malicious code in a customer virtual machine in a cloud platform

The application discloses a method for detecting malicious code of a client virtual machine in a cloud platform, comprising the following steps: S1, obtaining a memory dump file; S2, extracting information by virtual machine introspection; S3, model training; and S4, malicious code detection. The method can avoid attacks of malicious code on agents in the client machine, make the agents invalid or even bypass detection software, improve detection efficiency and detection accuracy, and does not need to be re-adapted for different types of operating systems.
Owner:KYLIN CORP

Register caching for efficient virtual machine introspection

A virtual machine malware detection service caches contents that correspond to operating system registries. By caching the content of important registers, the malware detector is able to efficiently traverse virtual machine memory contents to identify important operating system properties. Examples of such operating system properties include a list of running processes. The malware detector replaces agent-based threat detection for compute endpoints. The malware detector detects cryptocurrency miners and malware by scanning guest virtual machine (VM) memories. The guest VM memory may be scanned according to the guest physical address. According to some examples, the memories of guest user processes may be scanned one by one, using the page table address for each guest process to efficiently locate its memory.
Owner:GOOGLE LLC

A cloud host security baseline checking method and system based on virtual machine introspection

The present application belongs to the technical field of computer information security, and particularly relates to a cloud host security baseline checking method and system based on virtual machine introspection, which comprises the following steps: accessing a target virtual machine through a host virtualization management program layer and dividing physical memory pages, obtaining physical memory dirty page states and system I / O load; according to the dirty page states of the physical memory pages in a historical observation window and a physical neighborhood set, obtaining an activity accumulation index and a spatial neighborhood linkage index at the current time, respectively; obtaining a checking trigger score according to the activity accumulation index, the spatial neighborhood linkage index and the system I / O load, and realizing security baseline checking based on the threshold relationship of the checking trigger score. The present application can identify normal business hotspots and abnormal tampering behaviors, and reduce the checking frequency when the system is under high load, thereby realizing low-overhead agentless security baseline checking.
Owner:WUHAN MINGJIAXIN TECHNOLOGY CO LTD

Cloud host security baseline checking method and system based on virtual machine introspection

The invention belongs to the technical field of computer information security, and particularly relates to a cloud host security baseline checking method and system based on virtual machine introspection, and the method comprises the steps: accessing a target virtual machine through a host machine virtualization management program layer, dividing a physical memory page, and obtaining a physical memory dirty page state and a system I / O load; according to dirty page states of the physical memory page in the historical observation window and the physical neighborhood set, respectively obtaining an activeness accumulation index and a spatial neighborhood linkage index at the current moment; and according to the activeness accumulation index, the spatial neighborhood linkage index and the system I / O load, obtaining a check trigger score, and based on a relationship between the check trigger score and a threshold value, realizing security baseline check. According to the invention, normal service hotspots and abnormal tampering behaviors can be identified, the checking frequency is reduced when the system is in high load, and low-overhead agency-free security baseline checking is realized.
Owner:WUHAN MINGJIAXIN TECHNOLOGY CO LTD