Invention Grant
- Patent Title: Systems and methods for decrypting network traffic in a virtualized environment
-
Application No.: US16173490Application Date: 2018-10-29
-
Publication No.: US10257170B2Publication Date: 2019-04-09
- Inventor: Radu Caragea
- Applicant: Bitdefender IPR Management Ltd.
- Applicant Address: CY Nicosia
- Assignee: Bitdefender IPR Management Ltd.
- Current Assignee: Bitdefender IPR Management Ltd.
- Current Assignee Address: CY Nicosia
- Agency: Law Office of Andrei D Popovici, PC
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F21/56 ; H04L9/32 ; G06F12/1009 ; H04L9/14 ; H04L9/30 ; G06F9/455

Abstract:
Described systems and methods enable a decryption of encrypted communication between a client system and a remote party, for applications such as detection and analysis of malicious software, intrusion detection, and surveillance, among others. The client system executes a virtual machine and an introspection engine outside the virtual machine. The introspection engine is configured to identify memory pages whose contents have changed between a first session event (e.g., a ServerHello message) and a second session event (e.g., a ClientFinished message). The respective memory pages are likely to contain encryption key material for the respective communication session. A decryption engine may then attempt to decrypt an encrypted payload of the respective communication session using information derived from the content of the identified memory pages.
Public/Granted literature
- US20190068561A1 Systems and Methods for Decrypting Network Traffic in a Virtualized Environment Public/Granted day:2019-02-28
Information query