EVENT FILTERING FOR SECURITY APPLICATIONS OF VIRTUAL MACHINES Russian patent published in 2020 - IPC G06F21/53 G06F21/56 

Abstract RU 2723668 C1

FIELD: information technologies.

SUBSTANCE: invention relates to the field of computer security. Method employs a hybrid event notification and analysis system in which a first component running in a secure virtual machine (VM) is registered as a processor exception handler caused by memory access violations, and a second component which is executed outside the corresponding VM is registered as a handler for VM output events. First component filters violations violation events in accordance with a set of rules and only notifies the second component about events considered to be relevant for security. Second component analyses the notified events to determine whether the software is malicious.

EFFECT: technical result is providing protection of a virtual machine from malicious software.

21 cl, 10 dwg

Similar patents RU2723668C1

Title Year Author Number
SYSTEM AND METHODS FOR DECRYPTING NETWORK TRAFFIC IN A VIRTUALIZED ENVIRONMENT 2017
  • Caragea Radu
RU2738021C2
SYSTEM AND METHODS FOR AUDITING A VIRTUAL MACHINE 2017
  • Lukacs Sandor
  • Lutas Andrei-Vlad
  • Anichitei Ionel C.
RU2691187C1
DOUBLE SELF-TEST OF MEMORY FOR PROTECTION OF MULTIPLE NETWORK ENDPOINTS 2016
  • Lutas Dan-Horea
  • Lukacs Sandor
  • Ticle Daniel-Ioan
  • Ciocas Radu-Ioan
  • Anichitei Ionel-Cristinel
RU2714607C2
ROBUST AND SECURE HARDWARE-COMPUTER SYSTEM IN CLOUD COMPUTING ENVIRONMENT 2013
  • Gavrilov Dmitrij Aleksandrovich
  • Shchelkunov Nikolaj Nikolaevich
RU2557476C2
COMPUTER SECURITY SYSTEMS AND METHODS USING ASYNCHRONOUS INTROSPECTION EXCEPTIONS 2016
  • Lukaks Sandor
  • Sirb Kristyan-Bogdan
  • Lutas Andrej-Vlad
RU2703156C2
MEMORY INTROSPECTION ENGINE FOR PROTECTING INTEGRITY OF VIRTUAL MACHINES 2014
  • Lutsas Andrej-Vlad
  • Lukaks Sandor
  • Lutsas Dan-Khorya
RU2640300C2
PROTECTED STORAGE DEVICE 2018
  • Lukaks Sandor
  • Turiku Dan-Kristyan
RU2768196C2
SYSTEMS AND METHODS FOR PRESENTING A RESULT OF A CURRENT PROCESSOR INSTRUCTION WHEN EXITING FROM A VIRTUAL MACHINE 2015
  • Lukaks Sandor
  • Lutas Andrej-Vlad
RU2686552C2
ATTESTATION OF HOST CONTAINING TRUSTED EXECUTION ENVIRONMENT 2015
  • Fergyuson Nils T.
  • Samsonov Evgenij Anatolevich
  • Kinskhumann
  • Chandrashekar Samartkha
  • Messek Dzhon Entoni
  • Novak Mark Fishel
  • Makkarron Kristofer
  • Temkhejn Amitabkh Prakash
  • Van Tsyan
  • Krus Devid Mettyu
  • Ben-Zvi Nir
  • Vinberg Anders Bertil
RU2679721C2
EVALUATION OF PROCESS OF MALWARE DETECTION IN VIRTUAL MACHINES 2014
  • Lukaks Sandor
  • Tosha Raul-Vasile
  • Boka Paul-Daniel
  • Khazhmashan George-Florin
  • Lutsas Andrej-Vlad
RU2634205C2

RU 2 723 668 C1

Authors

Lutas Andrei-Vlad

Dates

2020-06-17Published

2017-12-19Filed