The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Sep. 15, 2020

Filed:

Mar. 28, 2018
Applicant:

Electronics and Telecommunications Research Institute, Daejeon, KR;

Inventors:

Sung-Jin Kim, Daejeon, KR;

Hyunyi Yi, Incheon, KR;

Seong-Joong Kim, Daejeon, KR;

Woomin Hwang, Daejeon, KR;

Byung-Joon Kim, Daejeon, KR;

Chulwoo Lee, Daejeon, KR;

Hyoung-Chun Kim, Daejeon, KR;

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 21/55 (2013.01); G06F 21/57 (2013.01); G06F 9/455 (2018.01); G06F 21/53 (2013.01); G06F 21/56 (2013.01);
U.S. Cl.
CPC ...
G06F 21/575 (2013.01); G06F 9/45533 (2013.01); G06F 9/45558 (2013.01); G06F 21/53 (2013.01); G06F 21/552 (2013.01); G06F 21/554 (2013.01); G06F 21/566 (2013.01); G06F 2009/45575 (2013.01); G06F 2009/45587 (2013.01); G06F 2009/45591 (2013.01); G06F 2221/034 (2013.01); G06F 2221/2101 (2013.01);
Abstract

An apparatus and method for collecting an audit trail in a virtual machine boot process, the audit-trail-collecting apparatus including an event detection unit for detecting a software interrupt event, a register state information extraction unit for extracting state information of a CPU register corresponding to a detection time of the software interrupt event, a monitoring unit for monitoring a change in a vector value corresponding to the software interrupt event in an interrupt vector table, a threat occurrence detection unit for detecting a threat occurrence in a virtual machine boot process based on at least one of the CPU register state information and a monitored result, and an audit trail collection unit for storing an audit trail corresponding to at least one of the CPU register state information and the monitored result when the threat occurrence is detected in the virtual machine boot process.


Find Patent Forward Citations

Loading…