SYSTEMS AND METHODS FOR VIRTUALIZATION AND EMULATION ASSISTED MALWARE DETECTION
    3.
    发明授权
    SYSTEMS AND METHODS FOR VIRTUALIZATION AND EMULATION ASSISTED MALWARE DETECTION 有权
    系统和虚拟化方法,并协助有害程序识别仿真

    公开(公告)号:EP2774038B1

    公开(公告)日:2016-06-22

    申请号:EP12844780.2

    申请日:2012-11-05

    申请人: Cyphort, Inc.

    摘要: Systems and methods for virtualization and emulation malware enabled detection are described. In some embodiments, a method comprises intercepting an object, instantiating and processing the object in a virtualization environment, tracing operations of the object while processing within the virtualization environment, detecting suspicious behavior associated with the object, instantiating an emulation environment in response to the detected suspicious behavior, processing, recording responses to, and tracing operations of the object within the emulation environment, detecting a divergence between the traced operations of the object within the virtualization environment to the traced operations of the object within the emulation environment, re-instantiating the virtualization environment, providing the recorded response from the emulation environment to the object in the virtualization environment, monitoring the operations of the object within the re-instantiation of the virtualization environment, identifying untrusted actions from the monitored operations, and generating a report regarding the identified untrusted actions of the object.

    SYSTEMS AND METHODS FOR VIRTUALIZED MALWARE DETECTION
    4.
    发明公开
    SYSTEMS AND METHODS FOR VIRTUALIZED MALWARE DETECTION 审中-公开
    系统和虚拟化的恶意软件检测方法

    公开(公告)号:EP2774039A4

    公开(公告)日:2015-11-11

    申请号:EP12845692

    申请日:2012-11-05

    申请人: CYPHORT INC

    摘要: Systems and methods for virtualization and emulation malware enabled detection are described. In some embodiments, a method comprises intercepting an object, instantiating and processing the object in a virtualization environment, tracing operations of the object while processing within the virtualization environment, detecting suspicious behavior associated with the object, instantiating an emulation environment in response to the detected suspicious behavior, processing, recording responses to, and tracing operations of the object within the emulation environment, detecting a divergence between the traced operations of the object within the virtualization environment to the traced operations of the object within the emulation environment, re-instantiating the virtualization environment, providing the recorded response from the emulation environment to the object in the virtualization environment, monitoring the operations of the object within the re-instantiation of the virtualization environment, identifying untrusted actions from the monitored operations, and generating a report regarding the identified untrusted actions of the object.

    APPLICATION ACCELERATION IN A VIRTUALIZED ENVIRONMENT
    5.
    发明公开
    APPLICATION ACCELERATION IN A VIRTUALIZED ENVIRONMENT 审中-公开
    在虚拟化环境中的应用加速

    公开(公告)号:EP2756394A1

    公开(公告)日:2014-07-23

    申请号:EP12832494.4

    申请日:2012-09-11

    IPC分类号: G06F9/44

    摘要: One embodiment illustrated herein includes a method that may be practiced in a computing environment. The method includes acts for providing direct access to hardware to virtual machines. The method includes determining that a virtual machine should have access to a piece of hardware. The method further includes a virtual machine requesting access to the hardware from the host wherein a host is a special partition that controls the physical hardware of a computing system and manages virtual machines. The method further includes the host configuring the hardware to allow access to the hardware directly by the virtual machine by the host mapping hardware resources into the virtual machine's address space. The method further includes the virtual machine directly accessing the hardware without going through the host once the hardware has been configured by the host.

    Power control method for virtual machine and virtual computer system
    7.
    发明授权
    Power control method for virtual machine and virtual computer system 有权
    对虚拟机和虚拟计算机系统的功率控制方法

    公开(公告)号:EP2071458B1

    公开(公告)日:2010-11-24

    申请号:EP08021082.6

    申请日:2008-12-04

    申请人: Hitachi Ltd.

    IPC分类号: G06F9/50 G06F1/32

    摘要: Provided is a method of controlling a virtual computer system in which a physical computer includes a plurality of physical CPUs that is switchable between a sleep state and a normal state, and a virtualization control unit divides the physical computer into a plurality of logical partitions to run a guest OS in each of the logical partitions and controls allocation of resources of the physical computer to the logical partitions, causes the virtualization control unit to: receive an operation instruction for operating the logical partitions; and if the operation instruction is for deleting a virtual CPU from one of the logical partitions, delete this virtual CPU from a table for managing virtual CPU-physical CPU allocation and put, if the deleting leaves no virtual CPUs allocated to one of the physical CPUs that has been allocated the deleted virtual CPU, this one of the physical CPUs into the sleep state.