发明名称 EXPLOIT DETECTION SYSTEM WITH THREAT-AWARE MICROVISOR
摘要 A micro-virtualization architecture deploys a threat-aware microvisor as a module of a virtualization system configured to facilitate real-time security analysis, including exploit detection and threat intelligence, of operating system processes executing in a memory of a node in a network environment. The micro-virtualization architecture organizes the memory as a user space and kernel space, wherein the microvisor executes in the kernel space of the architecture, while the operating system processes, an operating system kernel, a virtual machine monitor (VMM) and its spawned virtual machines (VMs) execute in the user space. Notably, the microvisor executes at the highest privilege level of a central processing unit of the node to virtualize access to kernel resources. The operating system kernel executes under control of the microvisor at a privilege level lower than a highest privilege level of the microvisor. The VMM and its spawned VMs execute at the highest privilege level of the microvisor.
申请公布号 EP3095058(A1) 申请公布日期 2016.11.23
申请号 EP20140879075 申请日期 2014.12.22
申请人 FIREEYE INC. 发明人 ISMAEL, OSMAN ABDOUL;AZIZ, ASHAR
分类号 G06F21/10 主分类号 G06F21/10
代理机构 代理人
主权项
地址