Invention Grant
US08479276B1 Malware detection using risk analysis based on file system and network activity
有权
基于文件系统和网络活动的风险分析的恶意软件检测
- Patent Title: Malware detection using risk analysis based on file system and network activity
- Patent Title (中): 基于文件系统和网络活动的风险分析的恶意软件检测
-
Application No.: US12981072Application Date: 2010-12-29
-
Publication No.: US08479276B1Publication Date: 2013-07-02
- Inventor: Alex Vaystikh , Robert Polansky , Samir Dilipkumar Saklikar , Liron Liptz
- Applicant: Alex Vaystikh , Robert Polansky , Samir Dilipkumar Saklikar , Liron Liptz
- Applicant Address: US MA Hopkinton
- Assignee: EMC Corporation
- Current Assignee: EMC Corporation
- Current Assignee Address: US MA Hopkinton
- Agency: BainwoodHaung
- Main IPC: G06F7/04
- IPC: G06F7/04

Abstract:
A virtual machine computing platform uses a security virtual machine (SVM) in operational communications with a risk engine which has access to a database including stored patterns corresponding to patterns of filtered operational data that are expected to be generated during operation of the monitored virtual machine when malware is executing. The stored patterns may have been generated during preceding design and training phases. The SVM is operated to (1) receive raw operational data from a virtual machine monitor, the raw operational data obtained from file system operations and network operations of the monitored virtual machine; (2) apply rule-based filtering to the raw operational data to generate filtered operational data; and (3) in conjunction with the risk engine, perform a mathematical (e.g., Bayesian) analysis based on the filtered operational data and the stored patterns in the database to calculate a likelihood that the malware is executing in the monitored virtual machine. A control action is taken if the likelihood is sufficiently high.
Information query