The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Apr. 21, 2020

Filed:

Dec. 19, 2016
Applicant:

Bitdefender Ipr Management Ltd., Nicosia, CY;

Inventors:

Dan H. Lutas, Cluj-Napoca, RO;

Daniel I. Ticle, Turda, RO;

Radu I. Ciocas, Cluj-Napoca, RO;

Sandor Lukacs, Floresti, RO;

Ionel C. Anichitei, Cluj-Napoca, RO;

Assignee:
Attorney:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
G06F 21/00 (2013.01); H04L 29/06 (2006.01); G06F 21/56 (2013.01); G06F 9/455 (2018.01); G06F 9/54 (2006.01);
U.S. Cl.
CPC ...
H04L 63/0254 (2013.01); G06F 9/45558 (2013.01); G06F 9/542 (2013.01); G06F 21/567 (2013.01); G06F 21/568 (2013.01); H04L 63/0245 (2013.01); H04L 63/0272 (2013.01); H04L 63/14 (2013.01); G06F 2009/45587 (2013.01);
Abstract

In some embodiments, a protected client operates a live introspection engine and an on-demand introspection engine. The live introspection engine detects the occurrence of certain events within a protected virtual machine exposed on the respective client system, and communicates the occurrence to a remote security server. In turn, the server may request a forensic analysis of the event from the client system, by indicating a forensic tool to be executed by the client. Forensic tools may be stored in a central repository accessible to the client. In response to receiving the analysis request, the on-demand introspection engine may retrieve and execute the forensic tool, and communicate a result of the forensic analysis to the security server. The server may use the information to determine whether the respective client is under attack by malicious software or an intruder.


Find Patent Forward Citations

Loading…