首页> 外国专利> SYSTÈME ET PROCÉDÉS DE DÉCRYPTAGE DE TRAFIC DE RÉSEAU DANS UN ENVIRONNEMENT VIRTUALISÉ

SYSTÈME ET PROCÉDÉS DE DÉCRYPTAGE DE TRAFIC DE RÉSEAU DANS UN ENVIRONNEMENT VIRTUALISÉ

摘要

Described systems and methods enable a decryption of encrypted communication between a client system and a remote party, for applications such as detection and analysis of malicious software, intrusion detection, and surveillance, among others. The client system executes a virtual machine and an introspection engine outside the virtual machine. The introspection engine is configured to identify memory pages whose contents have changed between a first session event (e.g., a ServerHello message) and a second session event (e.g., a ClientFinished message). The respective memory pages are likely to contain encryption key material for the respective communication session. A decryption engine may then attempt to decrypt an encrypted payload of the respective communication session using information derived from the content of the identified memory pages.

著录项

  • 公开/公告号EP3440584B1

    专利类型

  • 公开/公告日2020.07.29

    原文格式PDF

  • 申请/专利权人

    申请/专利号EP17715652.8

  • 发明设计人

    申请日2017.03.29

  • 分类号

  • 国家 EP

  • 入库时间 2022-08-21 10:57:10

相似文献

  • 专利
  • 外文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号