首页> 外国专利> System and method for virtual partition monitoring

System and method for virtual partition monitoring

机译:虚拟分区监视的系统和方法

摘要

A method is provided in one example embodiment that includes receiving in an external handler an event notification associated with an event in a virtual partition. A thread in the process in the virtual partition that caused the event can be parked. Other threads and processes may be allowed to resume while a security handler evaluates the event for potential threats. A helper agent within the virtual partition may be instructed to execute a task, such as collecting and assembling event context within the virtual partition, and results based on the task can be returned to the external handler. A policy action can be taken based on the results returned by the helper agent, which may include, for example, instructing the helper agent to terminate the process that caused the event.
机译:在一个示例实施例中提供了一种方法,该方法包括在外部处理程序中接收与虚拟分区中的事件相关联的事件通知。可以停滞虚拟分区中导致事件的进程中的线程。在安全处理程序评估事件的潜在威胁时,可以允许其他线程和进程继续进行。可以指示虚拟分区内的助手代理执行任务,例如在虚拟分区内收集和组装事件上下文,并且可以将基于该任务的结果返回给外部处理程序。可以基于帮助者代理返回的结果来采取策略动作,该结果可以包括,例如,指示帮助者代理终止导致事件的过程。

著录项

  • 公开/公告号US10032024B2

    专利类型

  • 公开/公告日2018-07-24

    原文格式PDF

  • 申请/专利权人 MCAFEE LLC;

    申请/专利号US201615082060

  • 发明设计人 GREGORY W. DALCHER;JONATHAN L. EDWARDS;

    申请日2016-03-28

  • 分类号G06F21/56;G06F21/55;G06F21/53;G06F9/455;G06F21/57;G06F21/62;

  • 国家 US

  • 入库时间 2022-08-21 13:05:03

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号