Invention Grant
- Patent Title: Protecting computer systems used in virtualization environments against fileless malware
-
Application No.: US15708328Application Date: 2017-09-19
-
Publication No.: US10860718B2Publication Date: 2020-12-08
- Inventor: Sriranga Seetharamaiah , Carl D. Woodward
- Applicant: McAfee, LLC
- Applicant Address: US CA San Jose
- Assignee: McAfee, LLC
- Current Assignee: McAfee, LLC
- Current Assignee Address: US CA San Jose
- Agency: Hanley, Flight & Zimmerman, LLC
- Priority: IN201741026875 20170728
- Main IPC: G06F12/14
- IPC: G06F12/14 ; G06F21/56 ; G06F21/60 ; G06F21/53 ; G06F9/455

Abstract:
Techniques for protecting a computer system against fileless malware are described. One technique includes a virtual machine (VM) locker logic/module implemented by one or more processors receiving information about input/output (I/O) requests associated with injection of data into a process. The logic/module can generate or update an information log to reflect that the process includes data from an external source. The data from the external source can include fileless malware. The technique also includes the logic/module intercepting an execution request by a process (e.g., the process that includes data from an external source, another process, etc.), where an execute privilege located in an operating system mediated access control mechanism approves the request. Next, the logic/module determines that the process requesting execution is included in the log and removes an execute privilege located in a hypervisor mediated access control mechanism to deny the request. Other advantages and embodiments are described.
Public/Granted literature
- US20190034633A1 PROTECTING COMPUTER SYSTEMS USED IN VIRTUALIZATION ENVIRONMENTS AGAINST FILELESS MALWARE Public/Granted day:2019-01-31
Information query