-
公开(公告)号:EP3767506A1
公开(公告)日:2021-01-20
申请号:EP20184056.8
申请日:2016-11-16
申请人: Armor Defense Inc.
摘要: A system that includes a hypervisor (102) configured to communicate packets comprising virtual machine operating characteristics metadata for guest virtual machines (104). The system further includes a virtual vault machine (106) comprising a hypervisor device driver (136), a hypervisor device driver interface (134), and an analysis tool (132). The hypervisor device driver (136) is configured to receive a packet comprising virtual machine operating characteristics metadata for a guest virtual machine (104) and to communicate the virtual machine operating characteristics metadata to an analysis tool using the hypervisor device driver interface (134). The analysis tool (132) is configured to correlate the virtual machine operating characteristics metadata to one of a cluster of known healthy guest virtual machines or a cluster of known compromised guest virtual machines using a machine learning algorithm and to classify the guest virtual machine (104).