Invention Grant
- Patent Title: Detecting malicious instructions on a virtual machine
-
Application No.: US15169282Application Date: 2016-05-31
-
Publication No.: US10210324B2Publication Date: 2019-02-19
- Inventor: Jeffery Ray Schilling , Chase Cooper Cunningham , Tawfiq Mohan Shah , Srujan Das Kotikela
- Applicant: Armor Defense Inc.
- Applicant Address: US TX Richardson
- Assignee: Armor Defense Inc.
- Current Assignee: Armor Defense Inc.
- Current Assignee Address: US TX Richardson
- Agency: Baker Botts L.L.P.
- Main IPC: G06F21/53
- IPC: G06F21/53 ; G06F21/56 ; G06F9/455 ; G06F17/30 ; G06F12/1009 ; H04L29/06 ; G06F21/54

Abstract:
A system that includes a hypervisor configured to communicate packets comprising virtual machine operating characteristics metadata for guest virtual machines. The system further includes a virtual vault machine comprising a hypervisor device driver, a hypervisor device driver interface, and an analysis tool. The hypervisor device driver is configured to receive a packet comprising virtual machine operating characteristics metadata for a guest virtual machine and to communicate the virtual machine operating characteristics metadata to an analysis tool using the hypervisor device driver interface. The analysis tool is configured to correlate the virtual machine operating characteristics metadata to one of a cluster of known healthy guest virtual machines or a cluster of known compromised guest virtual machines using a machine learning algorithm and to classify the guest virtual machine.
Public/Granted literature
- US20170149807A1 Detecting Malicious Instructions on a Virtual Machine Public/Granted day:2017-05-25
Information query