首页> 外国专利> Security event detection method, apparatus, and tangible computer readable storage medium through virtual machine introspection

Security event detection method, apparatus, and tangible computer readable storage medium through virtual machine introspection

机译:通过虚拟机内省的安全事件检测方法,装置和有形计算机可读存储介质

摘要

Methods and apparatus are disclosed for security event detection through virtual machine introspection. Example methods involve monitoring usage of a plurality of resources by a first virtual machine executing on a computing device by a monitoring agent, the monitoring agent executing on the computing device separate from the first virtual machine. Example methods further involve detecting a potential security event by comparing the usage of the plurality of resources to resource usage patterns. Example methods further involve assigning a severity level to the detected potential security event, and initiating a security action defined for the assigned severity level.
机译:公开了用于通过虚拟机内省进行安全事件检测的方法和装置。示例方法包括由监视代理程序在计算设备上执行的第一虚拟机监视多个资源的使用,在计算设备上执行的监视代理程序与第一虚拟机分开。示例方法还包括通过将多个资源的使用与资源使用模式进行比较来检测潜在的安全事件。示例方法还包括将严重性级别分配给检测到的潜在安全事件,并启动针对所分配的严重性级别定义的安全性动作。

著录项

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号