IP Library Granted Patent US 10,469,512
Granted Patent B1
US 10,469,512 · App. 15/351,112 · Granted Nov 5, 2019

Optimized resource allocation for virtual machines within a malware content detection system

Inventor: Osman Abdoul Ismael (Palo Alto, CA)
Assignee: FireEye, Inc.
H04L63/1425G06F3/0604G06F3/067G06F3/0631G06F9/45558H04L63/145G06F2009/45583G06F2009/45587G06F2009/45591
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,469,512
App. No.
15/351,112
Granted
Nov 5, 2019
Kind
B1
Abstract

According to one embodiment, a computerized method comprises operations of receiving incoming content propagating over a network and determining software profile information of an operating environment targeted for the incoming content. Responsive to determining that the system supports a first software profile that corresponds to the software profile information and a first virtual machine instance operating with the first software profile is currently running, a second virtual machine instance operating with the first software profile is instantiated for conducting a malware analysis on the incoming content. The second virtual machine instance is provided access to resources allocated for use by the first virtual machine instance.

Claims (68)

1. A computerized method conducted by a system, comprising:

determining software profile information of an operating environment targeted for received content;

responsive to determining that the system supports a first software profile that corresponds to the software profile information and a first virtual machine instance operating with the first software profile is currently running, instantiating a second virtual machine instance operating with the first software profile to conduct malware analysis on the received content, the second virtual machine instance being provided access to resources allocated for use by the first virtual machine instance; and

instantiating a third virtual machine instance that is based on a software profile that is different than the first software profile wherein the first software profile is associated with a first version of a particular application and the software profile is associated with a second version of the particular application that is different from the first version of the particular application, the third virtual machine instance being allocated resources that are not shared by the first virtual machine instance and the second virtual machine instance.

2. The computerized method of claim 1 , wherein prior to instantiating the second virtual machine instance, the method further comprising:

determining whether instantiation of the second virtual machine instance would exceed a virtual machine threshold, the virtual machine threshold representing a predetermined number of concurrently operating virtual machine instances and is computed by analyzing an amount of memory allocated for virtual machine operations within the system and determining that the instantiating of the second virtual machine instance will not exceed the virtual machine threshold; and

refraining from instantiating the second virtual machine instance if the sum of the plurality of virtual machine instances exceeds the virtual machine threshold.

3. The computerized method of claim 2 , wherein an amount of memory allocated to support the second virtual machine instance operating with the first software profile is less than an amount of memory allocated to support a virtual machine instance operating in accordance with a second software profile different than the first software profile.

4. The computerized method of claim 3 , wherein the amount of memory allocated to support the second virtual machine instance operating with the first software profile is at least ten times less than the amount of memory allocated to support the virtual machine instance operating in accordance with the second software profile.

5. The computerized method of claim 2 , further comprising:

after instantiation of a plurality of virtual machine instances including the first virtual machine instance and the second virtual machine instance, determining whether instantiation of the third virtual machine instance would exceed the virtual machine threshold;

instantiating the third virtual machine instance if a sum of the plurality of virtual machine instances does not exceed the virtual machine threshold; and

refraining from instantiating the third virtual machine instance if the sum of the plurality of virtual machine instances exceeds the virtual machine threshold.

6. The computerized method of claim 2 , wherein the predetermined number of concurrently operating virtual machine instances varies based on a number of software profiles supported by the system.

7. The computerized method of claim 1 , wherein the determining whether the system supports the first software profile comprises determining whether any virtual machine disk files within a storage device of the system corresponds to the software profile information.

8. The computerized method of claim 1 further comprising:

allocating additional resources exclusively accessible by the second virtual machine instance in response to conducting a Copy-On Write operation.

9. The computerized method of claim 1 , wherein the second virtual machine instance operating concurrently with the first virtual machine instance.

10. The computerized method of claim 9 , wherein the first software profile comprises at least one of (i) a type of operating system corresponding to an operating system identified in the software profile information, or (ii) a type of application corresponding to a particular application identified in the software profile information.

11. The computerized method of claim 1 , wherein the resources allocated for use by the first virtual machine instance include one or more memory pages within a system memory implemented within an electronic device.

12. The computerized method of claim 1 , wherein the first software profile identifies a first type of operating system and a first version of the first type of the operating system while the second software profile identifies the first type of operating system and a second version of the first type of the operating system, wherein the first version is different from the second version.

13. An electronic device for conducting an analysis for malware, comprising:

a network port adapted to receive incoming content; and

a controller coupled to the network port, the controller to (i) determine software profile information of an operating environment targeted for the incoming content, and (ii) responsive to a determination that the electronic device supports a first software profile that corresponds to the software profile information and a first virtual machine instance operating with the first software profile is currently running, instantiate a second virtual machine instance operating with the first software profile to conduct malware analysis on the incoming content, the second virtual machine instance being provided access to resources allocated for use by the first virtual machine instance,

wherein the resources include one or more memory pages within a memory implemented within the electronic device.

14. The electronic device of claim 13 , wherein prior to instantiating the second virtual machine instance, the controller to (i) determine whether instantiation of the second virtual machine instance would exceed a virtual machine threshold, the virtual machine threshold representing a predetermined number of concurrently operating virtual machine instances and being computed by (a) analyzing an amount of memory allocated for virtual machine operations within the electronic device and (b) determining that the instantiating of the second virtual machine instance will not exceed the virtual machine threshold, and (ii) refrain from instantiating the second virtual machine instance if the sum of the plurality of virtual machine instances exceeds the virtual machine threshold.

15. The electronic device of claim 14 , wherein an amount of memory allocated to support the second virtual machine instance operating with the first software profile is less than an amount of memory allocated to support a virtual machine instance operating in accordance with a second software profile different than the first software profile.

16. The electronic device of claim 15 , wherein the amount of memory allocated to support the second virtual machine instance operating with the first software profile is at least ten times less than the amount of memory allocated to support the virtual machine instance operating in accordance with the second software profile.

17. The electronic device of claim 13 , wherein the controller to determine whether the electronic device supports the first software profile by at least determining whether any virtual machine disk files within a storage device of the electronic device corresponds to the software profile information.

18. The electronic device of claim 13 , wherein the controller to allocate additional resources exclusively accessible by the second virtual machine instance in response to conducting a Copy-On Write operation.

19. The electronic device of claim 13 , wherein the second virtual machine instance operating concurrently with the first virtual machine instance.

20. The electronic device of claim 19 , wherein the first software profile comprises at least one of (i) a type of operating system corresponding to an operating system identified in the software profile information, or (ii) a type of application corresponding to a particular application identified in the software profile information.

21. The electronic device of claim 19 , wherein the predetermined number of concurrently operating virtual machine instances varies based on a number of software profiles supported by the electronic device.

22. An electronic device for conducting an analysis for malware, comprising:

a network port adapted to receive incoming content; and

a controller coupled to the network port, the controller to (i) determine software profile information of an operating environment targeted for the incoming content, and (ii) responsive to a determination that the electronic device supports a first software profile that corresponds to the software profile information and a first virtual machine instance operating with the first software profile is currently running, instantiate a second virtual machine instance operating with the first software profile to conduct malware analysis on the incoming content,

wherein the second virtual machine instance, operating concurrently with the first virtual machine instance, being provided access to resources allocated for use by the first virtual machine instance, and

wherein a virtual machine threshold, representing a predetermined number of concurrently operating virtual machine instances, varies based on a number of software profiles supported by the electronic device.

23. The electronic device of claim 22 , wherein prior to instantiating the second virtual machine instance, the controller to (i) determine whether instantiation of the second virtual machine instance would exceed the virtual machine threshold by at least (a) analyzing an amount of memory allocated for virtual machine operations within the electronic device and (b) determining that the instantiating of the second virtual machine instance will not exceed the virtual machine threshold, and (ii) refrain from instantiating the second virtual machine instance if the sum of the plurality of virtual machine instances exceeds the threshold.

24. The electronic device of claim 23 , wherein an amount of memory allocated to support the second virtual machine instance operating with the first software profile is less than an amount of memory allocated to support a virtual machine instance operating in accordance with a second software profile different than the first software profile.

25. The electronic device of claim 24 , wherein the amount of memory allocated to support the second virtual machine instance operating with the first software profile is at least ten times less than the amount of memory allocated to support the virtual machine instance operating in accordance with the second software profile.

26. The electronic device of claim 22 , wherein the controller to determine whether the electronic device supports the first software profile by at least determining whether any virtual machine disk files within a storage device of the electronic device corresponds to the software profile information.

27. The electronic device of claim 22 , wherein the controller to allocate additional resources exclusively accessible by the second virtual machine instance in response to conducting a Copy-On Write operation.

28. The electronic device of claim 22 , wherein the virtual machine threshold varies based on the number of software profiles supported by the electronic device given that a low number of software profiles necessitates that a greater number of virtual machine instances would share a substantial portion of the same resources.

29. The electronic device of claim 22 , wherein the first software profile comprises at least one of (i) a type of operating system corresponding to an operating system identified in the software profile information, or (ii) a type of application corresponding to a particular application identified in the software profile information.

30. The electronic device of claim 22 , wherein the resources include one or more memory pages within a memory implemented within the electronic device.

31. A non-transitory storage medium including software, deployed within and processed by an electronic device including a scheduler, that performs operations comprising:

determining software profile information of an operating environment targeted for received content;

determining that the electronic device supports a first software profile based on the software profile information;

responsive to determining that the electronic device supports the first software profile and a first virtual machine instance operating with the first software profile is currently running, instantiating a second virtual machine instance operating with the first software profile to conduct malware analysis on the received content, the second virtual machine instance being provided access to resources allocated for use by the first virtual machine instance; and

instantiating a third virtual machine instance that is based on a software profile that is different than the first software profile, wherein the first software profile is associated with a first version of a particular application and the software profile is associated with a second version of the particular application that is different from the first version of the particular application, the third virtual machine instance being allocated resources that are not shared by the first virtual machine instance and the second virtual machine instance.

32. The non-transitory storage medium of claim 31 , wherein prior to instantiating the second virtual machine instance, the software, deployed within and processed by the electronic device, performs operations comprising:

determining whether instantiation of the second virtual machine instance would exceed a virtual machine threshold, the virtual machine threshold representing a predetermined number of concurrently operating virtual machine instances and is computed by analyzing an amount of memory allocated for virtual machine operations within the system and determining that the instantiating of the second virtual machine instance will not exceed the virtual machine threshold; and

refraining from instantiating the second virtual machine instance if the sum of the plurality of virtual machine instances exceeds the virtual machine threshold.

33. The non-transitory storage medium of claim 32 , wherein an amount of memory allocated to support the second virtual machine instance operating with the first software profile is less than an amount of memory allocated to support a virtual machine instance operating in accordance with a second software profile different than the first software profile.

34. The non-transitory storage medium of claim 33 , wherein the amount of memory allocated to support the second virtual machine instance operating with the first software profile is at least ten times less than the amount of memory allocated to support the virtual machine instance operating in accordance with the second software profile.

35. The non-transitory storage medium of claim 32 , wherein the software, deployed within and processed by the electronic device, further performs operations comprising:

after instantiation of a plurality of virtual machine instances including the first virtual machine instance and the second virtual machine instance, determining whether instantiation of the third virtual machine instance would exceed the virtual machine threshold;

instantiating the third virtual machine instance if a sum of the plurality of virtual machine instances does not exceed the virtual machine threshold; and

refraining from instantiating the third virtual machine instance if the sum of the plurality of virtual machine instances exceeds the virtual machine threshold.

36. The non-transitory storage medium of claim 32 , wherein the predetermined number of concurrently operating virtual machine instances varies based on a number of software profiles supported by the system.

37. The non-transitory storage medium of claim 31 , wherein the determining whether the system supports the first software profile comprises determining whether any virtual machine disk files within a storage device of the system corresponds to the software profile information.

38. The non-transitory storage medium of claim 31 further comprising:

allocating additional resources exclusively accessible by the second virtual machine instance in response to conducting a Copy-On Write operation.

39. The non-transitory storage medium of claim 31 , wherein the second virtual machine instance operating concurrently with the first virtual machine instance.

40. The non-transitory storage medium of claim 39 , wherein the first software profile comprises at least one of (i) a type of operating system corresponding to an operating system identified in the software profile information, or (ii) a type of application corresponding to a particular application identified in the software profile information.

41. The non-transitory storage medium of claim 31 , wherein the resources allocated for use by the first virtual machine instance include one or more memory pages within a system memory implemented within an electronic device.

42. The non-transitory storage medium of claim 31 , wherein the first software profile identifies a first type of operating system and a first version of the first type of the operating system while the second software profile identifies the first type of operating system and a second version of the first type of the operating system, wherein the first version is different from the second version.

Assignments (13)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
MERGER Recorded Aug 13, 2024
From: FIREEYE SECURITY HOLDINGS US LLC
To: MUSARUBRA US LLC
Reel/Frame 068581/0279 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2023
From: FIREEYE, INC.
To: FIREEYE SECURITY HOLDINGS US LLC
Reel/Frame 063287/0776 →
CHANGE OF NAME Recorded Mar 16, 2023
From: FIREEYE, INC.
To: MANDIANT, INC.
Reel/Frame 063287/0771 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0791 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0681 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 14, 2019
From: ISMAEL, OSMAN ABDOUL
To: FIREEYE, INC.
Reel/Frame 049177/0846 →
Continuity (1)
Continuation 13892193 · May 10, 2013
Cited By (5)
US 12,200,013 US 12,248,563 US 12,278,834 US 12,363,145 US 12,445,458