发明名称 SYSTEM AND METHOD FOR VIRTUAL PARTITION MONITORING
摘要 A method is provided in one example embodiment that includes receiving in an external handler an event notification associated with an event in a virtual partition. A thread in the process in the virtual partition that caused the event can be parked. Other threads and processes may be allowed to resume while a security handler evaluates the event for potential threats. A helper agent within the virtual partition may be instructed to execute a task, such as collecting and assembling event context within the virtual partition, and results based on the task can be returned to the external handler. A policy action can be taken based on the results returned by the helper agent, which may include, for example, instructing the helper agent to terminate the process that caused the event.
申请公布号 US2012317570(A1) 申请公布日期 2012.12.13
申请号 US201113155572 申请日期 2011.06.08
申请人 DALCHER GREGORY W.;EDWARDS JONATHAN L. 发明人 DALCHER GREGORY W.;EDWARDS JONATHAN L.
分类号 G06F9/455 主分类号 G06F9/455
代理机构 代理人
主权项
地址