The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Aug. 04, 2015

Filed:

Sep. 14, 2009
Applicants:

Anup Ghosh, Centreville, VA (US);

Yih Huang, Fairfax, VA (US);

Jiang Wang, Fairfax, VA (US);

Angelos Stavrou, Springfield, VA (US);

Inventors:

Anup Ghosh, Centreville, VA (US);

Yih Huang, Fairfax, VA (US);

Jiang Wang, Fairfax, VA (US);

Angelos Stavrou, Springfield, VA (US);

Assignee:
Attorney:
Primary Examiner:
Assistant Examiner:
Int. Cl.
CPC ...
H04L 29/06 (2006.01); G06F 21/55 (2013.01);
U.S. Cl.
CPC ...
G06F 21/55 (2013.01); G06F 2221/2149 (2013.01);
Abstract

Processor(s) for detecting malicious software. A hardware virtual machine monitor (HVMM) operates under a host OS. Container(s) initialized with network application template(s) operate under a guest OS VM. A detection module operates under the guest OS VM includes a trigger detection module, a logging module and a container command module. The trigger detection module monitors activity on container(s) for a trigger event. The logging module writes activity report(s) in response to trigger event(s). The container command module issues command(s) in response to trigger event(s). The command(s) include a container start, stop and revert commands. A virtual machine control console operates under the host OS and starts/stops the HVMM. A container control module operates under the guest OSVM and controls container(s) in response to the command(s). The server communication module sends activity report(s) to a central collection network appliance that maintains a repository of activities for infected devices.


Find Patent Forward Citations

Loading…