FIELD: information technologies.
SUBSTANCE: invention relates to the field of computer security. Method employs a hybrid event notification and analysis system in which a first component running in a secure virtual machine (VM) is registered as a processor exception handler caused by memory access violations, and a second component which is executed outside the corresponding VM is registered as a handler for VM output events. First component filters violations violation events in accordance with a set of rules and only notifies the second component about events considered to be relevant for security. Second component analyses the notified events to determine whether the software is malicious.
EFFECT: technical result is providing protection of a virtual machine from malicious software.
21 cl, 10 dwg
Title | Year | Author | Number |
---|---|---|---|
SYSTEM AND METHODS FOR DECRYPTING NETWORK TRAFFIC IN A VIRTUALIZED ENVIRONMENT | 2017 |
|
RU2738021C2 |
SYSTEM AND METHODS FOR AUDITING A VIRTUAL MACHINE | 2017 |
|
RU2691187C1 |
DOUBLE SELF-TEST OF MEMORY FOR PROTECTION OF MULTIPLE NETWORK ENDPOINTS | 2016 |
|
RU2714607C2 |
ROBUST AND SECURE HARDWARE-COMPUTER SYSTEM IN CLOUD COMPUTING ENVIRONMENT | 2013 |
|
RU2557476C2 |
COMPUTER SECURITY SYSTEMS AND METHODS USING ASYNCHRONOUS INTROSPECTION EXCEPTIONS | 2016 |
|
RU2703156C2 |
MEMORY INTROSPECTION ENGINE FOR PROTECTING INTEGRITY OF VIRTUAL MACHINES | 2014 |
|
RU2640300C2 |
PROTECTED STORAGE DEVICE | 2018 |
|
RU2768196C2 |
SYSTEMS AND METHODS FOR PRESENTING A RESULT OF A CURRENT PROCESSOR INSTRUCTION WHEN EXITING FROM A VIRTUAL MACHINE | 2015 |
|
RU2686552C2 |
ATTESTATION OF HOST CONTAINING TRUSTED EXECUTION ENVIRONMENT | 2015 |
|
RU2679721C2 |
EVALUATION OF PROCESS OF MALWARE DETECTION IN VIRTUAL MACHINES | 2014 |
|
RU2634205C2 |
Authors
Dates
2020-06-17—Published
2017-12-19—Filed