FIELD: data processing.
SUBSTANCE: invention relates to the protection of computer systems from malicious programs. System contains a hardware processor for controlling: hypervisor, to provide a virtual machine containing a virtualized processor and virtualized memory to use a virtualized processor to perform the target process; and a memory introspection engine that runs outside the virtual machine and is configured to: determine, in accordance with the table of pages of the virtual machine, whether the target page of the virtual memory space of the target process is downloaded from the virtualized memory; and in response to, when the target page is unloaded from virtualized memory, direct insertion of specified page error into the virtual machine, and the page error results in the virtual machine operating system displaying the target page in a page of virtualized memory, and a direct error of the page is provided by the engine of introspection of the memory of a certain value in the field for inputting the event.
EFFECT: increased protection of the virtual machine against malicious programs.
23 cl, 10 dwg
Title | Year | Author | Number |
---|---|---|---|
EVALUATION OF PROCESS OF MALWARE DETECTION IN VIRTUAL MACHINES | 2014 |
|
RU2634205C2 |
MEMORY INTROSPECTION ENGINE FOR PROTECTING INTEGRITY OF VIRTUAL MACHINES | 2014 |
|
RU2640300C2 |
SYSTEMS AND METHODS FOR PRESENTING A RESULT OF A CURRENT PROCESSOR INSTRUCTION WHEN EXITING FROM A VIRTUAL MACHINE | 2015 |
|
RU2686552C2 |
COMPLEX CLASSIFICATION FOR DETECTING MALWARE | 2014 |
|
RU2645268C2 |
EVENT FILTERING FOR SECURITY APPLICATIONS OF VIRTUAL MACHINES | 2017 |
|
RU2723668C1 |
SYSTEM AND METHODS FOR DECRYPTING NETWORK TRAFFIC IN A VIRTUALIZED ENVIRONMENT | 2017 |
|
RU2738021C2 |
COMPUTER SECURITY SYSTEMS AND METHODS USING ASYNCHRONOUS INTROSPECTION EXCEPTIONS | 2016 |
|
RU2703156C2 |
DOUBLE SELF-TEST OF MEMORY FOR PROTECTION OF MULTIPLE NETWORK ENDPOINTS | 2016 |
|
RU2714607C2 |
SYSTEM AND METHODS FOR AUDITING A VIRTUAL MACHINE | 2017 |
|
RU2691187C1 |
TECHNIQUES FOR DOWNLOADING TARGET OBJECT OF VIRTUAL STORAGE | 2010 |
|
RU2562436C2 |
Authors
Dates
2018-07-02—Published
2014-07-02—Filed