AU2011338482B2 - Antimalware protection of virtual machines - Google Patents
Antimalware protection of virtual machines Download PDFInfo
- Publication number
- AU2011338482B2 AU2011338482B2 AU2011338482A AU2011338482A AU2011338482B2 AU 2011338482 B2 AU2011338482 B2 AU 2011338482B2 AU 2011338482 A AU2011338482 A AU 2011338482A AU 2011338482 A AU2011338482 A AU 2011338482A AU 2011338482 B2 AU2011338482 B2 AU 2011338482B2
- Authority
- AU
- Australia
- Prior art keywords
- guest
- antimalware
- scanning
- partition
- scanning mechanism
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Ceased
Links
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/56—Computer malware detection or handling, e.g. anti-virus arrangements
- G06F21/566—Dynamic detection, i.e. detection performed at run-time, e.g. emulation, suspicious activities
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
- G06F21/55—Detecting local intrusion or implementing counter-measures
- G06F21/56—Computer malware detection or handling, e.g. anti-virus arrangements
- G06F21/568—Computer malware detection or handling, e.g. anti-virus arrangements eliminating virus, restoring damaged files
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F9/00—Arrangements for program control, e.g. control units
- G06F9/06—Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
- G06F9/44—Arrangements for executing specific programs
- G06F9/455—Emulation; Interpretation; Software simulation, e.g. virtualisation or emulation of application or operating system execution engines
- G06F9/45533—Hypervisors; Virtual machine monitors
- G06F9/45558—Hypervisor-specific management and integration aspects
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F9/00—Arrangements for program control, e.g. control units
- G06F9/06—Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
- G06F9/44—Arrangements for executing specific programs
- G06F9/455—Emulation; Interpretation; Software simulation, e.g. virtualisation or emulation of application or operating system execution engines
- G06F9/45533—Hypervisors; Virtual machine monitors
- G06F9/45558—Hypervisor-specific management and integration aspects
- G06F2009/45587—Isolation or security of virtual machine instances
Landscapes
- Engineering & Computer Science (AREA)
- Software Systems (AREA)
- Theoretical Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- General Engineering & Computer Science (AREA)
- Computer Hardware Design (AREA)
- General Physics & Mathematics (AREA)
- Health & Medical Sciences (AREA)
- Virology (AREA)
- Physics & Mathematics (AREA)
- General Health & Medical Sciences (AREA)
- Debugging And Monitoring (AREA)
- Multi Processors (AREA)
- Stored Programmes (AREA)
Applications Claiming Priority (3)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US12/961,854 | 2010-12-07 | ||
| US12/961,854 US20120144489A1 (en) | 2010-12-07 | 2010-12-07 | Antimalware Protection of Virtual Machines |
| PCT/US2011/063615 WO2012078690A1 (en) | 2010-12-07 | 2011-12-06 | Antimalware protection of virtual machines |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| AU2011338482A1 AU2011338482A1 (en) | 2013-05-30 |
| AU2011338482B2 true AU2011338482B2 (en) | 2016-11-03 |
Family
ID=46163556
Family Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| AU2011338482A Ceased AU2011338482B2 (en) | 2010-12-07 | 2011-12-06 | Antimalware protection of virtual machines |
Country Status (7)
| Country | Link |
|---|---|
| US (1) | US20120144489A1 (enExample) |
| EP (1) | EP2649548B1 (enExample) |
| JP (1) | JP2013545208A (enExample) |
| CN (1) | CN102542207A (enExample) |
| AU (1) | AU2011338482B2 (enExample) |
| CA (1) | CA2817245A1 (enExample) |
| WO (1) | WO2012078690A1 (enExample) |
Families Citing this family (52)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US9460270B2 (en) * | 2011-04-27 | 2016-10-04 | Panasonic Intellectual Property Corporation Of America | Generating child virtual machine to execute authorized application with reduced risk of malware attack |
| US10546118B1 (en) | 2011-05-25 | 2020-01-28 | Hewlett-Packard Development Company, L.P. | Using a profile to provide selective access to resources in performing file operations |
| US8819062B2 (en) * | 2012-01-03 | 2014-08-26 | Yext, Inc. | Providing enhanced business listings with structured lists to multiple search providers from a source system |
| US9203862B1 (en) * | 2012-07-03 | 2015-12-01 | Bromium, Inc. | Centralized storage and management of malware manifests |
| CN103634366A (zh) * | 2012-08-27 | 2014-03-12 | 北京千橡网景科技发展有限公司 | 用于识别网络机器人的方法和设备 |
| US8984641B2 (en) * | 2012-10-10 | 2015-03-17 | Honeywell International Inc. | Field device having tamper attempt reporting |
| US9571507B2 (en) | 2012-10-21 | 2017-02-14 | Mcafee, Inc. | Providing a virtual security appliance architecture to a virtual cloud infrastructure |
| US8925085B2 (en) * | 2012-11-15 | 2014-12-30 | Microsoft Corporation | Dynamic selection and loading of anti-malware signatures |
| CN105074651A (zh) * | 2013-01-23 | 2015-11-18 | 惠普发展公司,有限责任合伙企业 | 共享资源争用 |
| US9104455B2 (en) | 2013-02-19 | 2015-08-11 | International Business Machines Corporation | Virtual machine-to-image affinity on a physical server |
| US9565202B1 (en) | 2013-03-13 | 2017-02-07 | Fireeye, Inc. | System and method for detecting exfiltration content |
| US9430647B2 (en) * | 2013-03-15 | 2016-08-30 | Mcafee, Inc. | Peer-aware self-regulation for virtualized environments |
| KR101901911B1 (ko) | 2013-05-21 | 2018-09-27 | 삼성전자주식회사 | 악성 프로그램을 탐지하는 방법 및 장치 |
| US9736179B2 (en) * | 2013-09-30 | 2017-08-15 | Fireeye, Inc. | System, apparatus and method for using malware analysis results to drive adaptive instrumentation of virtual machines to improve exploit detection |
| US9065854B2 (en) * | 2013-10-28 | 2015-06-23 | Citrix Systems, Inc. | Systems and methods for managing a guest virtual machine executing within a virtualized environment |
| US9258324B2 (en) | 2013-11-26 | 2016-02-09 | At&T Intellectual Property I, L.P. | Methods, systems, and computer program products for protecting a communication network against internet enabled cyber attacks through use of screen replication from controlled internet access points |
| US20150304343A1 (en) | 2014-04-18 | 2015-10-22 | Intuit Inc. | Method and system for providing self-monitoring, self-reporting, and self-repairing virtual assets in a cloud computing environment |
| US9866581B2 (en) | 2014-06-30 | 2018-01-09 | Intuit Inc. | Method and system for secure delivery of information to computing environments |
| US10757133B2 (en) | 2014-02-21 | 2020-08-25 | Intuit Inc. | Method and system for creating and deploying virtual assets |
| US11294700B2 (en) | 2014-04-18 | 2022-04-05 | Intuit Inc. | Method and system for enabling self-monitoring virtual assets to correlate external events with characteristic patterns associated with the virtual assets |
| RU2568282C2 (ru) * | 2014-04-18 | 2015-11-20 | Закрытое акционерное общество "Лаборатория Касперского" | Система и способ обеспечения отказоустойчивости антивирусной защиты, реализуемой в виртуальной среде |
| RU2573789C2 (ru) | 2014-04-18 | 2016-01-27 | Закрытое акционерное общество "Лаборатория Касперского" | Система и способ запуска виртуальной машины |
| RU2580030C2 (ru) | 2014-04-18 | 2016-04-10 | Закрытое акционерное общество "Лаборатория Касперского" | Система и способ распределения задач антивирусной проверки между виртуальными машинами в виртуальной сети |
| US9009836B1 (en) * | 2014-07-17 | 2015-04-14 | Kaspersky Lab Zao | Security architecture for virtual machines |
| US10102082B2 (en) | 2014-07-31 | 2018-10-16 | Intuit Inc. | Method and system for providing automated self-healing virtual assets |
| EP3259665A4 (en) * | 2015-02-20 | 2018-10-10 | Pristine Machine, LLC | Method to split data operational function among system layers |
| US10389747B2 (en) * | 2015-02-27 | 2019-08-20 | Hewlett-Packard Development Company, L.P. | Facilitating scanning of protected resources |
| US9652612B2 (en) * | 2015-03-25 | 2017-05-16 | International Business Machines Corporation | Security within a software-defined infrastructure |
| US10417031B2 (en) * | 2015-03-31 | 2019-09-17 | Fireeye, Inc. | Selective virtualization for security threat detection |
| US10726127B1 (en) | 2015-06-30 | 2020-07-28 | Fireeye, Inc. | System and method for protecting a software component running in a virtual machine through virtual interrupts by the virtualization layer |
| US11113086B1 (en) | 2015-06-30 | 2021-09-07 | Fireeye, Inc. | Virtual system and method for securing external network connectivity |
| US10216927B1 (en) | 2015-06-30 | 2019-02-26 | Fireeye, Inc. | System and method for protecting memory pages associated with a process using a virtualization layer |
| US10395029B1 (en) | 2015-06-30 | 2019-08-27 | Fireeye, Inc. | Virtual system and method with threat protection |
| US10642753B1 (en) | 2015-06-30 | 2020-05-05 | Fireeye, Inc. | System and method for protecting a software component running in virtual machine using a virtualization layer |
| US10033759B1 (en) | 2015-09-28 | 2018-07-24 | Fireeye, Inc. | System and method of threat detection under hypervisor control |
| US9977894B2 (en) | 2015-11-18 | 2018-05-22 | Red Hat, Inc. | Virtual machine malware scanning |
| CN105631320B (zh) * | 2015-12-18 | 2019-04-19 | 北京奇虎科技有限公司 | 虚拟机逃逸的检测方法及装置 |
| CN108369625B (zh) * | 2015-12-19 | 2022-03-04 | 比特梵德知识产权管理有限公司 | 用于保护多个网络端点的双重存储器内省 |
| US12339979B2 (en) | 2016-03-07 | 2025-06-24 | Crowdstrike, Inc. | Hypervisor-based interception of memory and register accesses |
| US12248560B2 (en) * | 2016-03-07 | 2025-03-11 | Crowdstrike, Inc. | Hypervisor-based redirection of system calls and interrupt-based task offloading |
| CN105844162B (zh) * | 2016-04-08 | 2019-03-29 | 北京北信源软件股份有限公司 | 一种虚拟化平台下windows虚拟机漏洞扫描的方法 |
| US9665714B1 (en) * | 2016-05-31 | 2017-05-30 | AO Kaspersky Lab | System and method of detecting malicious files on virtual machines in a distributed network |
| US20180173526A1 (en) | 2016-12-20 | 2018-06-21 | Invensys Systems, Inc. | Application lifecycle management system |
| EP3361406A1 (en) * | 2017-02-08 | 2018-08-15 | AO Kaspersky Lab | System and method of analysis of files for maliciousness in a virtual machine |
| RU2665911C2 (ru) * | 2017-02-08 | 2018-09-04 | Акционерное общество "Лаборатория Касперского" | Система и способ анализа файла на вредоносность в виртуальной машине |
| WO2020026228A1 (en) * | 2018-08-01 | 2020-02-06 | Vdoo Connected Trust Ltd. | Firmware verification |
| US11385766B2 (en) | 2019-01-07 | 2022-07-12 | AppEsteem Corporation | Technologies for indicating deceptive and trustworthy resources |
| IL275098A (en) * | 2020-06-03 | 2022-01-01 | Kazuar Advanced Tech Ltd | A multi-computing environment with the fewest loopholes |
| US11930019B2 (en) * | 2021-04-21 | 2024-03-12 | Saudi Arabian Oil Company | Methods and systems for fast-paced dynamic malware analysis |
| US11954333B2 (en) * | 2021-06-23 | 2024-04-09 | Western Digital Technologies, Inc. | Secured firmware with anti-malware |
| US12079339B2 (en) * | 2022-05-12 | 2024-09-03 | Vmware, Inc. | In-memory scanning for fileless malware on a host device |
| CN116150797B (zh) * | 2023-04-21 | 2023-08-01 | 深圳市科力锐科技有限公司 | 数据保护方法、系统、设备及存储介质 |
Citations (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20090158432A1 (en) * | 2007-12-12 | 2009-06-18 | Yufeng Zheng | On-Access Anti-Virus Mechanism for Virtual Machine Architecture |
Family Cites Families (20)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US7409719B2 (en) * | 2004-12-21 | 2008-08-05 | Microsoft Corporation | Computer security management, such as in a virtual machine or hardened operating system |
| US7475135B2 (en) * | 2005-03-31 | 2009-01-06 | International Business Machines Corporation | Systems and methods for event detection |
| US8619971B2 (en) * | 2005-04-01 | 2013-12-31 | Microsoft Corporation | Local secure service partitions for operating system security |
| US20060224623A1 (en) * | 2005-04-02 | 2006-10-05 | Microsoft Corporation | Computer status monitoring and support |
| US20110047618A1 (en) * | 2006-10-18 | 2011-02-24 | University Of Virginia Patent Foundation | Method, System, and Computer Program Product for Malware Detection, Analysis, and Response |
| US9189265B2 (en) * | 2006-12-21 | 2015-11-17 | Vmware, Inc. | Storage architecture for virtual machines |
| US9354927B2 (en) * | 2006-12-21 | 2016-05-31 | Vmware, Inc. | Securing virtual machine data |
| US9098347B2 (en) * | 2006-12-21 | 2015-08-04 | Vmware | Implementation of virtual machine operations using storage system functionality |
| US7765374B2 (en) * | 2007-01-25 | 2010-07-27 | Microsoft Corporation | Protecting operating-system resources |
| US8380987B2 (en) * | 2007-01-25 | 2013-02-19 | Microsoft Corporation | Protection agents and privilege modes |
| US20080320594A1 (en) * | 2007-03-19 | 2008-12-25 | Xuxian Jiang | Malware Detector |
| US8011010B2 (en) * | 2007-04-17 | 2011-08-30 | Microsoft Corporation | Using antimalware technologies to perform offline scanning of virtual machine images |
| CN101039177A (zh) * | 2007-04-27 | 2007-09-19 | 珠海金山软件股份有限公司 | 一种在线查毒的装置和方法 |
| US8601124B2 (en) * | 2007-06-25 | 2013-12-03 | Microsoft Corporation | Secure publishing of data to DMZ using virtual hard drives |
| US20090007100A1 (en) * | 2007-06-28 | 2009-01-01 | Microsoft Corporation | Suspending a Running Operating System to Enable Security Scanning |
| US8839237B2 (en) | 2007-12-31 | 2014-09-16 | Intel Corporation | Method and apparatus for tamper resistant communication in a virtualization enabled platform |
| JP2008152796A (ja) * | 2008-01-11 | 2008-07-03 | Nec Corp | データ複製システム、およびストレージ内のデータを複製するためのプログラム |
| JP5446167B2 (ja) * | 2008-08-13 | 2014-03-19 | 富士通株式会社 | ウイルス対策方法、コンピュータ、及びプログラム |
| US8954897B2 (en) * | 2008-08-28 | 2015-02-10 | Microsoft Corporation | Protecting a virtual guest machine from attacks by an infected host |
| US20100169972A1 (en) * | 2008-12-31 | 2010-07-01 | Microsoft Corporation | Shared repository of malware data |
-
2010
- 2010-12-07 US US12/961,854 patent/US20120144489A1/en not_active Abandoned
-
2011
- 2011-12-06 WO PCT/US2011/063615 patent/WO2012078690A1/en not_active Ceased
- 2011-12-06 EP EP11847224.0A patent/EP2649548B1/en not_active Not-in-force
- 2011-12-06 JP JP2013543292A patent/JP2013545208A/ja active Pending
- 2011-12-06 AU AU2011338482A patent/AU2011338482B2/en not_active Ceased
- 2011-12-06 CA CA2817245A patent/CA2817245A1/en not_active Abandoned
- 2011-12-07 CN CN2011104304337A patent/CN102542207A/zh active Pending
Patent Citations (1)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20090158432A1 (en) * | 2007-12-12 | 2009-06-18 | Yufeng Zheng | On-Access Anti-Virus Mechanism for Virtual Machine Architecture |
Also Published As
| Publication number | Publication date |
|---|---|
| AU2011338482A1 (en) | 2013-05-30 |
| EP2649548A1 (en) | 2013-10-16 |
| EP2649548B1 (en) | 2018-08-08 |
| CA2817245A1 (en) | 2012-06-14 |
| WO2012078690A1 (en) | 2012-06-14 |
| CN102542207A (zh) | 2012-07-04 |
| JP2013545208A (ja) | 2013-12-19 |
| US20120144489A1 (en) | 2012-06-07 |
| EP2649548A4 (en) | 2014-07-30 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| AU2011338482B2 (en) | Antimalware protection of virtual machines | |
| US11270015B2 (en) | Secure disk access control | |
| US9769250B2 (en) | Fight-through nodes with disposable virtual machines and rollback of persistent state | |
| KR101535502B1 (ko) | 보안 내재형 가상 네트워크 제어 시스템 및 방법 | |
| US9473526B2 (en) | Fight-through nodes for survivable computer network | |
| US9858108B2 (en) | Virtual switch interceptor | |
| US9213572B2 (en) | Interdependent virtual machine management | |
| US8839426B1 (en) | Fight-through nodes with disposable virtual machines and rollback of persistent state | |
| US8127412B2 (en) | Network context triggers for activating virtualized computer applications | |
| US8640238B2 (en) | Fight-through nodes for survivable computer network | |
| US20140372717A1 (en) | Fast and Secure Virtual Machine Memory Checkpointing | |
| US9021008B1 (en) | Managing targeted scripts | |
| US20230198863A1 (en) | Telemetry targeted query injection for enhanced debugging in microservices architectures | |
| US11438245B2 (en) | System monitoring with metrics correlation for data center | |
| US9686171B1 (en) | Systems and methods for attributing input/output statistics networks to region-mapped entities | |
| US20250126035A1 (en) | Monitoring operation of edge datacenter devices | |
| JP5698280B2 (ja) | 仮想化装置、通信方法、およびプログラム | |
| US20250335406A1 (en) | Deduplication in a multi-tiered architecture | |
| GB2548147A (en) | Self-propagating cloud-aware distributed agents for benign cloud exploitation | |
| Sansiya | Capacity Building of Client-Server Disruption Network Over Cloud Server Using Network Forensics | |
| HK1176186B (en) | Virtual switch interceptor | |
| HK1176186A (en) | Virtual switch interceptor |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| PC1 | Assignment before grant (sect. 113) |
Owner name: MICROSOFT TECHNOLOGY LICENSING, LLC Free format text: FORMER APPLICANT(S): MICROSOFT CORPORATION |
|
| FGA | Letters patent sealed or granted (standard patent) | ||
| MK14 | Patent ceased section 143(a) (annual fees not paid) or expired |