发明名称 SYSTEM AND METHOD FOR PASSIVE THREAT DETECTION USING VIRTUAL MEMORY INSPECTION
摘要 A method in one example implementation includes synchronizing a first memory page set with a second memory page set of a virtual guest machine, inspecting the first memory page set off-line, and detecting a threat in the first memory page set. The method further includes taking an action based on the threat. In more specific embodiments, the method includes updating the first memory page set with a subset of the second memory page set at an expiration of a synchronization interval, where the subset of the second memory page set was modified during the synchronization interval. In other more specific embodiments, the second memory page set of the virtual guest machine represents non-persistent memory of the virtual guest machine. In yet other specific embodiments, the action includes at least one of shutting down the virtual guest machine and alerting an administrator.
申请公布号 US2013246685(A1) 申请公布日期 2013.09.19
申请号 US201113229502 申请日期 2011.09.09
申请人 BHARGAVA RISHI;REESE, JR. DAVID P.;MCAFEE, INC. 发明人 BHARGAVA RISHI;REESE, JR. DAVID P.
分类号 G06F12/10;G06F12/00 主分类号 G06F12/10
代理机构 代理人
主权项
地址