发明授权
- 专利标题: Detecting stealth network communications
- 专利标题(中): 检测隐形网络通信
-
申请号: US11685534申请日: 2007-03-13
-
公开(公告)号: US08079030B1公开(公告)日: 2011-12-13
- 发明人: Sourabh Satish , Brian Hernacki
- 申请人: Sourabh Satish , Brian Hernacki
- 申请人地址: US CA Mountain View
- 专利权人: Symantec Corporation
- 当前专利权人: Symantec Corporation
- 当前专利权人地址: US CA Mountain View
- 代理机构: Fenwick & West LLP
- 主分类号: G06F9/455
- IPC分类号: G06F9/455 ; H04L29/06
摘要:
A computer has a hypervisor that supervises a virtual machine. The virtual machine includes a guest security module that enforces a security policy on network traffic entering and exiting the virtual machine. Malicious software (malware) uses stealth network communications to avoid the guest security module and attempts to communicate with its home base. A security module within the hypervisor has access to all network communications entering and exiting the computer. The security module communicates with the guest security module to identify communications of which the guest security module is aware. The security module analyzes the network communications for the computer to identify a stealth network communication of which the guest security module is unaware. The security module alters the stealth network communication, thereby prevent the malware from communicating with its home base.
信息查询