-
公开(公告)号:US20190012465A1
公开(公告)日:2019-01-10
申请号:US15938017
申请日:2018-03-28
Inventor: Sung-Jin KIM , Hyunyi YI , Seong-Joong KIM , Woomin HWANG , Byung-Joon KIM , Chulwoo LEE , Hyoung-Chun KIM
CPC classification number: G06F21/575 , G06F9/45533 , G06F9/45558 , G06F21/53 , G06F21/552 , G06F21/554 , G06F21/566 , G06F2009/45575 , G06F2009/45587 , G06F2009/45591 , G06F2221/034 , G06F2221/2101
Abstract: An apparatus and method for collecting an audit trail in a virtual machine boot process, the audit-trail-collecting apparatus including an event detection unit for detecting a software interrupt event, a register state information extraction unit for extracting state information of a CPU register corresponding to a detection time of the software interrupt event, a monitoring unit for monitoring a change in a vector value corresponding to the software interrupt event in an interrupt vector table, a threat occurrence detection unit for detecting a threat occurrence in a virtual machine boot process based on at least one of the CPU register state information and a monitored result, and an audit trail collection unit for storing an audit trail corresponding to at least one of the CPU register state information and the monitored result when the threat occurrence is detected in the virtual machine boot process.
-
公开(公告)号:US20230016571A1
公开(公告)日:2023-01-19
申请号:US17489032
申请日:2021-09-29
Inventor: Seung-Hun HAN , Seong-Joong KIM , Gak-Soo LIM , Byung-Joon KIM
Abstract: Disclosed herein are an apparatus and method for preventing a security threat to a virtual machine. The apparatus includes one or more processors and executable memory for storing at least one program executed by the one or more processors. The at least one program is configured such that a hypervisor for virtualization in a host kernel executes a virtualization instruction corresponding to the service requested by a virtual machine of a host application and such that a hypervisor for monitoring interrupts the virtualization instruction in response to a security threat event occurring in the monitoring area of the hypervisor for virtualization and controls the process and thread of the host kernel. The hypervisor for monitoring is located in an area separate from the area in which the hypervisor for virtualization is located in the host kernel.
-
公开(公告)号:US20190044946A1
公开(公告)日:2019-02-07
申请号:US15938003
申请日:2018-03-28
Inventor: Woomin HWANG , Hyunyi YI , Sung-Jin KIM , Seong-Joong KIM , Chulwoo LEE , Byung-Joon KIM , Hyoung-Chun KIM
Abstract: An apparatus for monitoring file access in a virtual machine in a cloud-computing system based on a virtualized environment includes a hypervisor for implementing at least one virtual machine and managing the virtual machine by monitoring a task in which a the virtual machine accesses a file loaded from storage to memory, the storage storing data including environment information of the virtual machine.
-
4.
公开(公告)号:US20190012194A1
公开(公告)日:2019-01-10
申请号:US15975932
申请日:2018-05-10
Inventor: Hyunyi YI , Sung-Jin KIM , Woomin HWANG , Seong-Joong KIM , Chulwoo LEE , Byung-Joon KIM , Hyoung-Chun KIM
Abstract: An apparatus and method for storing an audit trail in response to execution of a virtual-machine process. The method for storing an audit trail, performed by the apparatus for storing an audit trail in response to execution of a virtual-machine process, includes detecting execution of a process inside a virtual machine, determining whether the executed process is a monitoring target process and determining a type of the process, activating one or more monitoring events for monitoring at least one of an upload, a download and a drop by the process based on a result of the determination, and storing information about occurrence of the activated monitoring event as an audit trail.
-
-
-