IP Library Granted Patent US 10,572,665
Granted Patent B2
US 10,572,665 · App. 13/869,511 · Granted Feb 25, 2020

System and method to create a number of breakpoints in a virtual machine via virtual machine trapping events

Inventors: Robert Jung (Albuquerque, NM); Antony Saba (Albuquerque, NM)
Assignee: FireEye, Inc.
G06F21/566G06F9/45558G06F21/14G06F21/53G06F2009/45583G06F2009/45591G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,572,665
App. No.
13/869,511
Granted
Feb 25, 2020
Kind
B2
Abstract

A system and method for dynamic software analysis operable to describe program behavior via instrumentation of virtualization events.

Claims (26)

1. A method to create a number of passive breakpoints in a virtual machine for dynamic software analysis of program behavior, the method comprising:

instrumenting, by an analysis engine, a guest virtual machine to provide a user with programmatic control configured to (i) register to receive a virtualization trapping event and (ii) modify guest virtual machine execution behavior;

responsive to instrumenting the guest virtual machine to receive the virtualization trapping event,

triggering the virtualization trapping event in a hardware-assisted virtualization platform, during an application software or operating system execution within the guest virtual machine, wherein the hardware-assisted virtualization platform comprises an event driven hooking engine that is further configured to manipulate at least one page permission in the guest virtual machine and utilize at least one virtual machine trap to provide execution at an address within a memory allocated to a process of the guest virtual machine,

intercepting the virtualization trapping event via a hardware-assisted virtualization hypervisor, and

reading the memory within the guest virtual machine by the analysis engine to enable the analysis engine to determine whether the virtualization trapping event includes any unexpected software execution; and

responsive to instrumenting the guest virtual machine to modify the guest execution behavior,

modifying one or more page permissions,

operating in a single-stepping mode by controlling instruction processing by the guest virtual machine to enable the analysis engine to determine any unexpected software execution, and

resetting the one or more page permissions.

2. The method according to claim 1 , wherein the triggering is performed by at least one of (i) the operating system, and (ii) the application software.

3. The method according to claim 1 , wherein when the guest virtual machine attempts to execute any code contained within a physical page, (i) a permission of the physical page is set to executable, and (ii) a single stepping flag is turned on.

4. The method according to claim 1 , wherein the modifying of the guest virtual machine execution behavior is conducted based on controlling instruction processing by the guest virtual machine by at least placing the guest virtual machine in a single-stepping mode.

5. The system according to claim 1 , wherein the modifying of the one or more page permissions includes setting the one or more page permissions to an executable permission.

6. The system according to claim 5 , wherein the resetting of the one or more page permissions includes setting the one or more page permissions to a non-executable permission.

7. The method according to claim 1 , wherein the virtualization trapping event is an event that is registered with the analysis engine and operates as a breakpoint.

8. A system with a processor to create a number of passive breakpoints in a virtual machine via instrumentation of common virtual machine trapping events, the system including:

a hardware-assisted virtualization hypervisor to intercept a virtualization trapping event, the virtualization trapping event triggered (i) in the guest virtual machine, and (ii) during software execution within the guest virtual machine, wherein the hardware-assisted virtualization hypervisor comprises an event driven hooking engine that is further configured to manipulate at least one page permission in the guest virtual machine and utilize at least one virtual machine trap to provide execution at an address within a memory allocated to a process of the guest virtual machine; and

an analysis engine that is separate from the guest virtual machine and the hardware-assisted virtualization hypervisor, the analysis engine to (i) instrument the guest virtual machine to provide a user with programmatic control configured to (i) register to receive a virtualization trapping event and (ii) modify guest virtual machine execution behavior, (ii) read the memory within the guest virtual machine to enable the analysis engine to determine whether the virtualization trapping event includes any unexpected arbitrary software execution, and (iii) modify the guest virtual machine execution behavior by at least modifying one or more page permissions, operating in a single-stepping mode by controlling instruction processing by the guest virtual machine to enable the analysis engine to determine any unexpected software execution, and resetting the one or more page permissions.

9. The system according to claim 8 , further comprising: an operating system that triggers the virtualization trapping event.

10. The system according to claim 8 , wherein the virtualization trapping event is triggered by application software.

11. The system according to claim 8 , wherein the analysis engine to modify the one or more page permissions to an executable permission.

12. The system according to claim 9 , wherein the resetting of the one or more page permissions includes setting the one or more page permissions back to a non-executable permission.

13. The system according to claim 8 , wherein the analysis engine to, when the virtual machine attempts to execute any code contained within a physical page, (i) set a permission of the physical page to executable, and (ii) turn a single stepping flag on.

14. The system according to claim 8 , wherein the analysis engine to modify the guest virtual machine execution behavior based on at least controlling instruction processing by the guest virtual machine by at least placing the guest virtual machine in a single-stepping mode.

15. The system according to claim 8 , wherein the virtualization trapping event is an event that is registered with the analysis engine and operates as a breakpoint.

Assignments (16)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
MERGER Recorded Aug 13, 2024
From: FIREEYE SECURITY HOLDINGS US LLC
To: MUSARUBRA US LLC
Reel/Frame 068581/0279 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
CHANGE OF NAME Recorded Mar 16, 2023
From: FIREEYE, INC.
To: MANDIANT, INC.
Reel/Frame 063113/0029 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2023
From: MANDIANT, INC.
To: FIREEYE SECURITY HOLDINGS US LLC
Reel/Frame 063272/0743 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0791 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0681 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 12, 2016
From: MANDIANT, LLC
To: FIREEYE, INC.
Reel/Frame 038568/0947 →
CHANGE OF NAME Recorded Mar 5, 2014
From: MERCURY MERGER LLC
To: MANDIANT, LLC
Reel/Frame 032351/0340 →
MERGER Recorded Mar 4, 2014
From: MANDIANT CORPORATION
To: MERCURY MERGER LLC
Reel/Frame 032342/0806 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 26, 2013
From: JUNG, ROBERT; SABA, ANTONY
To: MANDIANT CORPORATION
Reel/Frame 030693/0851 →
Continuity (3)
Provisional Application 61747114 · Dec 28, 2012
Provisional Application 61747796 · Dec 31, 2012
Related Publication 20140189687A1 · Jul 3, 2014
Cited By (5)
US 12,200,013 US 12,248,563 US 12,316,651 US 12,363,145 US 12,445,458