The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Nov. 22, 2016

Filed:

Dec. 28, 2015
Applicant:

Bromium, Inc., Cupertino, CA (US);

Inventors:

Rahul C. Kashyap, Foster City, CA (US);

J. McEnroe Samuel Navaraj, Santa Clara, CA (US);

Baibhav Singh, San Jose, CA (US);

Arun Passi, Sunnyvale, CA (US);

Rafal Wojtczuk, Warsaw, PL;

Assignee:

Bromium, Inc., Cupertino, CA (US);

Attorneys:
Primary Examiner:
Int. Cl.
CPC ...
G06F 11/00 (2006.01); G06F 12/14 (2006.01); G06F 12/16 (2006.01); G08B 23/00 (2006.01); G06F 9/455 (2006.01); G06F 21/56 (2013.01); G06F 21/52 (2013.01); G06F 21/53 (2013.01); G06F 21/55 (2013.01);
U.S. Cl.
CPC ...
G06F 9/45558 (2013.01); G06F 9/45533 (2013.01); G06F 21/52 (2013.01); G06F 21/53 (2013.01); G06F 21/552 (2013.01); G06F 21/56 (2013.01); G06F 21/566 (2013.01); G06F 2009/45587 (2013.01); G06F 2009/45591 (2013.01); G06F 2221/034 (2013.01);
Abstract

The execution of a process within a VM may be monitored, and when a trigger event occurs, additional monitoring is initiated, including storing behavior data describing the real-time events taking place inside the VM. This behavior data may then be compared to information about the expected behavior of that type of process in order to determine whether malware has compromised the VM.


Find Patent Forward Citations

Loading…