首页> 外国专利> Threat defense techniques

Threat defense techniques

机译:威胁防御技术

摘要

In an approach, an intermediary guest manager operates within a virtual machine hosted by a host machine and managed by a hypervisor. The intermediary guest manager manages one or more guest operating systems operating within the virtual machine and implements one or more security services for the guest operating systems. The security services provided to the guest operating systems may include system call filtering, memory protections, secure memory dumps, and others. In some cases, the intermediary guest manager consults a threat defense policy which contains a number of records, where each record has one or more triggers representing suspicious activity and one or more actions to take in response to being triggered. When the intermediary guest manager identifies a request, such as a system call or memory access, that meets the trigger of a particular record, the intermediary guest manager executes the associated actions to remediate the suspicious activity.
机译:在一种方法中,中间访客管理器在由主机托管且由管理程序管理的虚拟机内操作。中间访客管理器管理在虚拟机内运行的一个或多个访客操作系统,并为访客操作系统实施一个或多个安全服务。提供给客户操作系统的安全服务可以包括系统调用筛选,内存保护,安全内存转储等。在某些情况下,中间来宾管理器会参考包含许多记录的威胁防御策略,其中每条记录都有一个或多个代表可疑活动的触发器以及为响应被触发而采取的一个或多个动作。当中间访客管理器识别出满足特定记录触发要求的请求(例如系统调用或内存访问)时,中间访客管理器将执行关联的操作来补救可疑活动。

著录项

  • 公开/公告号US10552606B2

    专利类型

  • 公开/公告日2020-02-04

    原文格式PDF

  • 申请/专利权人 VMWARE INC.;

    申请/专利号US201815863574

  • 申请日2018-01-05

  • 分类号G06F12/14;G06F21/55;G06F9/455;G06F21/56;G06F21/62;

  • 国家 US

  • 入库时间 2022-08-21 11:24:54

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号