首页> 外国专利> Exploit detection system with threat-aware microvisor

Exploit detection system with threat-aware microvisor

机译:带有威胁感知微型监控程序的漏洞利用检测系统

摘要

An exploit detection system deploys a threat-aware microvisor to facilitate real-time security analysis, including exploit detection and threat intelligence, of an operating system process executing on a node of a network environment. The microvisor may be organized as a main protection domain representative of the operating system process. In response to the process attempting to access a kernel resource for which it does not have permission, a capability violation may be generated at the main protection domain of the microvisor and a micro-virtual machine (VM) may be spawned as a container configured to encapsulate the process. The main protection domain may then be cloned to create a cloned protection domain that is representative of the process and that is bound to the spawned micro-VM. Capabilities of the cloned protection domain may be configured to be more restricted than the capabilities of the main protection domain with respect to access to the kernel resource. The restricted capabilities may be configured to generate more capability violations than those generated by the capabilities of the main protection domain and, in turn, enable further monitoring of the process as it attempts to access the kernel resource.
机译:漏洞利用检测系统部署威胁感知微管理器,以促进对在网络环境的节点上执行的操作系统进程进行实时安全分析,包括漏洞利用检测和威胁情报。可以将微管理器组织为代表操作系统进程的主要保护域。响应于尝试访问其没有权限的内核资源的过程,可能会在微管理器的主保护域上生成功能冲突,并且可能会生成微虚拟机(VM)作为配置为的容器封装过程。然后,可以克隆主保护域以创建一个克隆保护域,该域代表该过程并绑定到生成的微型VM。就访问内核资源而言,克隆保护域的功能可以配置为比主保护域的功能受到更多限制。可以将受限功能配置为生成比由主保护域的功能生成的功能违规更多的功能违规,进而在进程尝试访问内核资源时启用对进程的进一步监视。

著录项

  • 公开/公告号US9507935B2

    专利类型

  • 公开/公告日2016-11-29

    原文格式PDF

  • 申请/专利权人 FIREEYE INC.;

    申请/专利号US201414229580

  • 发明设计人 OSMAN ABDOUL ISMAEL;ASHAR AZIZ;

    申请日2014-03-28

  • 分类号G06F21/55;G06F9/455;G06F21/62;G06F21/53;

  • 国家 US

  • 入库时间 2022-08-21 13:41:14

相似文献

  • 专利
  • 外文文献
  • 中文文献
获取专利

客服邮箱:kefu@zhangqiaokeyan.com

京公网安备:11010802029741号 ICP备案号:京ICP备15016152号-6 六维联合信息科技 (北京) 有限公司©版权所有
  • 客服微信

  • 服务号