EXTRACTING MALICIOUS INSTRUCTIONS ON A VIRTUAL MACHINE IN A NETWORK ENVIRONMENT

    公开(公告)号:EP3767506A1

    公开(公告)日:2021-01-20

    申请号:EP20184056.8

    申请日:2016-11-16

    摘要: A system that includes a hypervisor (102) configured to communicate packets comprising virtual machine operating characteristics metadata for guest virtual machines (104). The system further includes a virtual vault machine (106) comprising a hypervisor device driver (136), a hypervisor device driver interface (134), and an analysis tool (132). The hypervisor device driver (136) is configured to receive a packet comprising virtual machine operating characteristics metadata for a guest virtual machine (104) and to communicate the virtual machine operating characteristics metadata to an analysis tool using the hypervisor device driver interface (134). The analysis tool (132) is configured to correlate the virtual machine operating characteristics metadata to one of a cluster of known healthy guest virtual machines or a cluster of known compromised guest virtual machines using a machine learning algorithm and to classify the guest virtual machine (104).