IP Library Granted Patent US 10,255,432
Granted Patent B2
US 10,255,432 · App. 15/169,320 · Granted Apr 9, 2019

Detecting malicious instructions on a virtual machine using profiling

Inventors: Jeffery Ray Schilling (Murphy, TX); Chase Cooper Cunningham (Frisco, TX); Tawfiq Mohan Shah (Argyle, TX); Srujan Das Kotikela (Dallas, TX)
Assignee: Armor Defense Inc.
G06F21/53G06F9/45545G06F9/45558G06F12/1009G06F17/30424G06F17/30598G06F21/54G06F21/56G06F21/561G06F21/565G06F21/566H04L63/0227H04L63/1408H04L63/1416H04L63/1425G06F21/567G06F2009/45579G06F2009/45583G06F2009/45587G06F2009/45591G06F2009/45595G06F2212/1052G06F2212/152G06F2212/154G06F2221/034G06F2221/2149
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,255,432
App. No.
15/169,320
Granted
Apr 9, 2019
Kind
B2
Abstract

A system that includes a trusted measurement machine comprising a profiling tool, a semantics virtual machine profiling engine interface, a semantics virtual machine profiling engine. The profiling tool is configured to receive virtual machine operating characteristics metadata for a guest virtual machine and to communicate the virtual machine operating characteristics metadata to the semantics virtual machine profiling engine using the semantics virtual machine profiling engine interface. The profiling tool is further configured to compare the virtual machine operating characteristics metadata to a target profile comprising known configurations for guest virtual machines, to determine a classification for the guest virtual machine, and to communicate the determined classification to the vault management console. The semantics virtual machine profiling engine is configured to generate the target profile based on the virtual machine operating characteristics metadata and to communicate the target profile to the profiling tool using the semantics virtual machine profiling interface.

Claims (14)

1. A system comprising: a processor; a vault management console configured to send a measurement request for virtual machine operating characteristic metadata for a guest virtual machine, the measurement request including a measurement duration and a preferred format; and a trusted measurement machine in communication with the virtual management console, and comprising: a profiling tool implemented by the processor, the profiling tool operating in a user space of the trusted measurement machine and configured to: receive virtual machine operating characteristics metadata for a guest virtual machine; communicate the virtual machine operating characteristics metadata to a semantics virtual machine profiling engine using a semantics virtual machine profiling engine interface; receive a target profile from the semantics virtual machine profiling engine; compare the virtual machine operating characteristics metadata to the target profile, wherein the target profile comprises known healthy configurations and known compromised configurations for guest virtual machines, wherein the said comparing comprises comparing the virtual machine operating characteristics metadata to the known healthy configurations and the known compromised configurations; determine a classification for the guest virtual machine based on the comparison, wherein the determined classification comprises at least one of the following states of the guest virtual machine: healthy state, compromised state, and unknown state, wherein determining the classification for the guest virtual machine comprises: in response to determining that virtual machine operating characteristics metadata matches the known healthy configurations, classifying the guest virtual machine as in a healthy state; in response to determining that virtual machine operating characteristics metadata matches the known compromised configurations, classifying the guest virtual machine as in a compromised state; and in response to determining that virtual machine operating characteristics metadata matches neither the known healthy configurations nor the known compromised configurations, classifying the guest virtual machine as in an unknown state; and communicate the determined classification to the vault management console; the semantics virtual machine profiling engine interface implemented by the processor, and configured to: communicate the virtual machine operating characteristics metadata from the profiling tool to the semantics virtual machine profiling engine; and communicate the target profile from the semantics virtual machine profiling engine to the profiling tool; and the semantics virtual machine profiling engine implemented by the processor, the semantics virtual machine profiling engine operating in a kernel space of the trusted measurement machine and configured to: generate the target profile based on the virtual machine operating characteristics metadata; communicate the target profile to the profiling tool using the semantics virtual machine profiling interface; and the semantics virtual machine profiling engine is configured to: communicate the virtual machine operating characteristics metadata from the profiling tool in the user space of the trusted measurement machine to the semantics virtual machine profiling engine in the kernel space of the trusted measurement machine; and communicate the target profile from the semantics virtual machine profiling engine in the kernel space of the trusted measurement machine to the profiling tool in the user space of the trusted measurement machine.

2. The system of claim 1 , wherein: the semantics virtual machine profiling engine is configured to receive known threat information; and generating the target profile is based on the virtual machine operating characteristics metadata and the known threat information.

3. The system of claim 1 , wherein: the known configurations for guest virtual machines comprises known compromised configurations for guest virtual machines; and the profiling tool classifies the guest virtual machine as compromised in response to matching the at a least of portion of the virtual machine operating characteristics metadata to the, known compromised configurations for guest virtual machines.

4. The system of claim 1 , wherein generating the target profile comprises formatting the target profile based on the virtual machine operating characteristics metadata.

5. The system of claim 1 , wherein the profiling tool is configured to store the virtual machine operating characteristics metadata and the determined classification.

6. An apparatus comprising: a processor; a profiling tool implemented by the processor, the profiling tool operating in a user space of a trusted measurement machine and configured to: in response to a measurement request for virtual machine operating characteristic metadata for a guest virtual machine, the measurement request including a measurement duration and a preferred format, receive virtual machine operating characteristics metadata for a guest virtual machine; communicate the virtual machine operating characteristics metadata to a semantics virtual machine profiling engine using a semantics virtual machine profiling engine interface; receive a target profile from the semantics virtual machine profiling engine; compare the virtual machine operating characteristics metadata to the target profile, wherein the target profile comprises known healthy configurations and known compromised configurations for guest virtual machines, wherein the said comparing comprises comparing the virtual machine operating characteristics metadata to the known healthy configurations and the known compromised configurations; determine a classification for the guest virtual machine based on the comparison, wherein the determined classification comprises at least one of the following states of the guest virtual machine: healthy state, compromised state, and unknown state, wherein determining the classification for the guest virtual machine comprises: in response to determining that virtual machine operating characteristics metadata matches the known healthy configurations, classifying the guest virtual machine as in a healthy state; in response to determining that virtual machine operating characteristics metadata matches the known compromised configurations, classifying the guest virtual machine as in a compromised state; and in response to determining that virtual machine operating characteristics metadata matches neither the known healthy configurations nor the known compromised configurations, classifying the guest virtual machine as in an unknown state; and communicate the determined classification to the vault management console; the semantics virtual machine profiling engine interface implemented by the processor, and configured to: communicate the virtual machine operating characteristics metadata from the profiling tool to the semantics virtual machine profiling engine; and communicate the target profile from the semantics virtual machine profiling engine to the profiling tool; the semantics virtual machine profiling engine implemented by the processor, the semantics virtual machine profiling engine operating in a kernel space of the trusted measurement machine and configured to: generate the target profile based on the virtual machine operating characteristics metadata; communicate the target profile to the profiling tool using the semantics virtual machine profiling interface; and the semantics virtual machine profiling engine interface is configured to: communicate the virtual machine operating characteristics metadata from the profiling tool in the user space to the semantics virtual machine profiling engine in the kernel space; and communicate the target profile from the semantics virtual machine profiling engine in the kernel space to the profiling tool in the user space.

7. The apparatus of claim 6 , wherein: the semantics virtual machine profiling engine is configured to receive known threat information; and generating the target profile is based on the virtual machine operating characteristics metadata and the known threat information.

8. The apparatus of claim 6 , wherein: the known configurations for guest virtual machines comprises known compromised configurations for guest virtual machines; and the profiling tool classifies the guest virtual machine as compromised in response to matching the at least a portion of the virtual machine operating characteristics metadata to the known compromised configurations for guest virtual machines.

9. The apparatus of claim 6 , wherein generating the target profile compromised formatting the target profile based on the virtual machine operating characteristics metadata.

10. The apparatus of claim 6 , wherein the profiling tool is configured to store the virtual machine operating characteristics metadata and the determined classification.

11. A virtual machine intrusion detection method comprising: sending a measurement request for virtual machine operating characteristic metadata for a quest virtual machine, the measurement request including a measurement duration and a preferred format; receiving, at a profiling tool implemented by a processor, virtual machine operating characteristics metadata for a guest virtual machine, wherein the profiling tool operates in a user space of a trusted measurement machine; communicating, by the profiling tool, the virtual machine operating characteristics metadata to a semantics virtual machine profiling engine using a semantics virtual machine profiling engine interface implemented by the processor, wherein the semantics virtual machine profiling engine operates in a kernel space of the trusted measurement machine; generating, by the semantics virtual machine profiling engine implemented by the processor, a target profile based on the virtual machine operating characteristics metadata, wherein the target profile comprises known healthy configurations and known compromised configurations for guest virtual machines; communicating, by the semantics virtual machine profiling engine, the target profile to the profiling tool; comparing, by the profiling tool, the virtual machine operating characteristics metadata to the target profile, wherein the said comparing comprises comparing the virtual machine operating characteristics metadata to the known healthy configurations and the known compromised configurations; determining, by the profiling tool, a classification for the guest virtual machine based on the comparison, wherein the determined classification comprises at least one of the following states of the guest virtual machine: healthy state, compromised state, and unknown state, wherein determining the classification for the guest virtual machine comprises: in response to determining that virtual machine operating characteristics metadata matches the known healthy configurations, classifying the guest virtual machine as in a healthy state; in response to determining that virtual machine operating characteristics metadata matches the known compromised configurations, classifying the guest virtual machine as in a compromised state; and in response to determining that virtual machine operating characteristics metadata matches neither the known healthy configurations nor the known compromised configurations, classifying the guest virtual machine as in an unknown state; communicating, by the profiling tool, the determined classification to a vault management console; communicating the virtual machine operating characteristics metadata comprises communicating the virtual machine operating characteristics metadata from the profiling tool operating in a user space to the semantics virtual machine profiling engine operating in a kernel space; and communicating the target profile comprises communicating the target profile from the semantics virtual machine profiling engine in the kernel space to the profiling tool in the user space.

12. The method of claim 11 , further comprising receiving, by the semantics virtual machine profiling engine, known threats information; and wherein the generating the target profile is based on the virtual machine operating characteristics metadata and the known threats information.

13. The method of claim 11 , wherein: the known configurations for guest virtual machines comprises known compromised configurations for guest virtual machines; and the profiling tool classifies the guest virtual machine as compromised in response to matching at least a portion of the virtual machine operating characteristics metadata to known compromised configurations for guest virtual machines.

14. The method of claim 11 , wherein generating the target profile comprises formatting the target profile based on the virtual machine operating characteristics metadata.

Assignments (6)
RELEASE OF SECURITY INTEREST Recorded Apr 6, 2026
From: ESCALATE CAPITAL IV, LP
To: ARMOR DEFENSE INC.; ARMOR DEFENSE LIMITED
Reel/Frame 074284/0469 →
RELEASE OF SECURITY INTEREST Recorded Apr 6, 2026
From: SILICON VALLEY BANK
To: ARMOR DEFENSE LIMITED; ARMOR DEFENSE INC.
Reel/Frame 074284/0476 →
SECURITY INTEREST Recorded Oct 1, 2024
From: ARMOR DEFENSE INC.
To: SUNFLOWER BANK , N.A.
Reel/Frame 068758/0972 →
SECURITY INTEREST Recorded Dec 23, 2020
From: ARMOR DEFENSE INC.; ARMOR DEFENSE LIMITED
To: ESCALATE CAPITAL IV, LP
Reel/Frame 054741/0749 →
SECURITY INTEREST Recorded Oct 16, 2019
From: ARMOR DEFENSE, INC.
To: SILICON VALLEY BANK
Reel/Frame 050730/0113 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 31, 2016
From: SCHILLING, JEFFERY RAY; CUNNINGHAM, CHASE COOPER; SHAH, TAWFIQ MOHAN; KOTIKELA, SRUJAN DAS
To: ARMOR DEFENSE INC.
Reel/Frame 038753/0896 →
Continuity (2)
Provisional Application 62258730 · Nov 23, 2015
Related Publication 20170147821A1 · May 25, 2017