Invention Grant
US08719936B2 VMM-based intrusion detection system 失效
基于VMM的入侵检测系统

VMM-based intrusion detection system
Abstract:
An intrusion detection system collects architectural level events from a Virtual Machine Monitor where the collected events represent operation of a corresponding Virtual Machine. The events are consolidated into features that are compared with features from a known normal operating system. If an amount of any differences between the collected features and the normal features exceeds a threshold value, a compromised Virtual Machine may be indicated. The comparison thresholds are determined by training on normal and abnormal systems and analyzing the collected events with machine learning algorithms to arrive at a model of normal operation.
Public/Granted literature
Information query
Patent Agency Ranking
0/0