发明名称 SYSTEM AND METHOD FOR VIRTUAL PARTITION MONITORING
摘要 A method is provided in one example embodiment that includes receiving in an external handler an event notification associated with an event in a virtual partition. A thread in the process in the virtual partition that caused the event can be parked. Other threads and processes may be allowed to resume while a security handler evaluates the event for potential threats. A helper agent within the virtual partition may be instructed to execute a task, such as collecting and assembling event context within the virtual partition, and results based on the task can be returned to the external handler. A policy action can be taken based on the results returned by the helper agent, which may include, for example, instructing the helper agent to terminate the process that caused the event.
申请公布号 US2016224792(A1) 申请公布日期 2016.08.04
申请号 US201615082060 申请日期 2016.03.28
申请人 McAfee, Inc. 发明人 Dalcher Gregory W.;Edwards Jonathan L.
分类号 G06F21/56;G06F21/62;G06F9/455;G06F21/57 主分类号 G06F21/56
代理机构 代理人
主权项
地址 Santa Clara CA US