Invention Grant
- Patent Title: Detecting arbitrary code execution using a hypervisor
-
Application No.: US15898236Application Date: 2018-02-16
-
Publication No.: US10678922B2Publication Date: 2020-06-09
- Inventor: Prasad Dabak
- Applicant: NICIRA, INC.
- Applicant Address: US CA Palo Alto
- Assignee: NICIRA, INC.
- Current Assignee: NICIRA, INC.
- Current Assignee Address: US CA Palo Alto
- Priority: com.zzzhc.datahub.patent.etl.us.BibliographicData$PriorityClaim@301b68
- Main IPC: G06F21/56
- IPC: G06F21/56 ; G06F12/1009 ; H04L29/06 ; G06F21/53 ; G06F9/455

Abstract:
The subject matter described herein provides protection against zero-day attacks by detecting, via a hypervisor maintaining an extended page table, an attempt to execute arbitrary code associated with malware in a guest operation system (OS) running within a virtual machine (VM). Further, the subject matter provides detection of lateral movement of the malware. The hypervisor uses hidden breakpoints to detect a request for thread creation, and then determines whether the request is to download and execute arbitrary code.
Public/Granted literature
- US20190156036A1 DETECTING ARBITRARY CODE EXECUTION USING A HYPERVISOR Public/Granted day:2019-05-23
Information query