首页>
外国专利>
SYSTÈME ET PROCÉDÉS DE DÉCRYPTAGE DE TRAFIC DE RÉSEAU DANS UN ENVIRONNEMENT VIRTUALISÉ
SYSTÈME ET PROCÉDÉS DE DÉCRYPTAGE DE TRAFIC DE RÉSEAU DANS UN ENVIRONNEMENT VIRTUALISÉ
展开▼
展开▼
页面导航
摘要
著录项
相似文献
摘要
Described systems and methods enable a decryption of encrypted communication between a client system and a remote party, for applications such as detection and analysis of malicious software, intrusion detection, and surveillance, among others. The client system executes a virtual machine and an introspection engine outside the virtual machine. The introspection engine is configured to identify memory pages whose contents have changed between a first session event (e.g., a ServerHello message) and a second session event (e.g., a ClientFinished message). The respective memory pages are likely to contain encryption key material for the respective communication session. A decryption engine may then attempt to decrypt an encrypted payload of the respective communication session using information derived from the content of the identified memory pages.
展开▼