Invention Grant
- Patent Title: Using a threat model to monitor host execution in a virtualized environment
-
Application No.: US16575227Application Date: 2019-09-18
-
Publication No.: US11295021B2Publication Date: 2022-04-05
- Inventor: Ian Pratt , Rahul Kashyap , Adrian Taylor , James McKenzie
- Applicant: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
- Applicant Address: US TX Spring
- Assignee: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
- Current Assignee: HEWLETT-PACKARD DEVELOPMENT COMPANY, L.P.
- Current Assignee Address: US TX Spring
- Agency: HPI Patent Department
- Main IPC: G06F21/57
- IPC: G06F21/57 ; G06F21/55 ; H04L29/06 ; G06F9/455 ; G06F21/56

Abstract:
Approaches for monitoring a host operating system. A threat model is stored and maintained in an isolated execution environment. The threat model identifies for any process executing on a host operating system how trustworthy the process should be deemed based on a pattern of observed behavior. The execution of the process and those processes in a monitoring circle relationship thereto are monitored. The monitoring circle relationship includes a parent process, any process in communication with a member of monitoring circle relationship, and any process instantiated by a present member of monitoring circle relationship. Observed process behavior is correlated with the threat model. Upon determining that a particular process has behaved in a manner inconsistent with a pattern of allowable behavior identified by the threat model for that process, a responsive action is taken.
Public/Granted literature
- US20200327236A1 Using a Threat Model to Monitor Host Execution in a Virtualized Environment Public/Granted day:2020-10-15
Information query