IP Library Granted Patent US 10,528,726
Granted Patent B1
US 10,528,726 · App. 15/943,357 · Granted Jan 7, 2020

Microvisor-based malware detection appliance architecture

Inventor: Osman Abdoul Ismael (Palo Alto, CA)
Assignee: FireEye, Inc.
G06F21/552G06F9/45558G06F2009/45587G06F2009/45591G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,528,726
App. No.
15/943,357
Granted
Jan 7, 2020
Kind
B1
Abstract

A threat-aware microvisor may be deployed in a malware detection appliance architecture and execute on a malware detection system (MDS) appliance to provide exploit and malware detection within a network environment. The microvisor may underlie an operating system kernel of the MDS appliance and execute in kernel space of the architecture to control access to kernel resources of the appliance for any operating system process. A type 0 virtual machine monitor may be disposed over the microvisor and execute in user space of the architecture as a pass-through module configured to expose the kernel resources of the appliance to the operating system kernel. One or more hypervisors, e.g., type 1 VMM, may be further disposed over the microvisor and execute in user space of the architecture under control of the microvisor to support execution of one or more guest operating systems inside one or more full virtual machines.

Claims (30)

1. A system comprising:

a microvisor configured to control access to a kernel resource of the system by generating a capability violation in response to an object running in a guest operating system attempting to access the kernel resource;

a type 0 virtual machine monitor (VMM 0) disposed over the microvisor and configured to expose the kernel resource to an operating system kernel of the system; and

a type 1 virtual machine monitor (VMM 1) further disposed over the microvisor and configured to operate under control of the microvisor to instrument the object as the object runs in the guest operating system,

wherein the VMM 1 and VMM 0 being configured to cooperate with the microvisor to capture run-time behaviors of the object as dynamic analysis results in response to the capability violation to detect whether the behaviors are indicative of malware.

2. The system of claim 1 wherein the microvisor comprises a main protection domain including one or more execution contexts and capabilities defining permissions for the object to access the kernel resource of the system.

3. The system of claim 2 wherein the VMM 1 is further configured to create a virtual machine to contain the guest operating system, the virtual machine bound to a clone of the main protection domain representative of the guest operating system.

4. The system of claim 3 wherein the clone of the main protection domain is created by copying the execution contexts and capabilities of the main protection domain, wherein the capabilities of the clone of the main protection domain are more restricted than the capabilities of the main protection domain with respect to access to the kernel resource.

5. The system of claim 1 further comprising a behavioral analysis logic engine configured to correlate the dynamic analysis results against correlation rules to generate correlation information pertaining to a level of risk used to arrive at a decision of maliciousness.

6. The system of claim 5 further comprising a classifier configured to use the correlation information to render a decision as to whether the object is malicious, the classifier further configured to classify the correlation information, including the behaviors and the capability violation, of the object relative to known malware.

7. The system of claim 1 , wherein the microvisor is configured to communicate with the operating system kernel and perform a subset of hypervisor functionality including initiating one or more hyper-calls to implement a virtual machine monitor.

8. The system of claim 1 , wherein the virtual machine monitor corresponds to VMM 1.

9. The system of claim 1 , wherein the microvisor executes in a kernel space of the system to control access to the kernel resources.

10. The system of claim 9 being a virtualization architecture including a trusted computing base (TCB) that is configured to provide a trusted malware detection environment, the TCB includes at least the microvisor.

11. The system of claim 10 , wherein the microvisor being configured to enforce a security policy for the TCB.

12. The system of claim 11 further comprising a behavioral analysis logic engine deployed as part of the TCB, the behavioral analysis logic engine to correlate the dynamic analysis results against correlation rules to generate correlation information pertaining to a level of risk used to arrive at a decision of maliciousness.

13. A system comprising:

one or more processing units;

one or more network interfaces;

one or more input/output (I/O) devices; and

a memory coupled to the one or more processing units, the memory comprises

a microvisor that, when executed by the one or more processing units, controls access to a kernel resource, being at least one of a collection of resources including any of the one or more processing units, the one or more network interfaces and the one or more I/O devices, by generating a capability violation in response to an object running in a guest operating system attempting to access the kernel resource;

a type 0 virtual machine monitor (VMM 0) that, when executed by the one or more processing units, exposes the kernel resource to an operating system kernel of the system; and

a type 1 virtual machine monitor (VMM 1) that, when executed by the one or more processing units, operates under control of the microvisor to instrument the object as the object runs in the guest operating system,

wherein the VMM 1 and VMM 0 being configured to cooperate with the microvisor to capture run-time behaviors of the object as dynamic analysis results in response to the capability violation to detect whether the behaviors are indicative of malware.

14. The system of claim 13 wherein the microvisor implemented within the memory and executed by the one or more processing units comprises a main protection domain including one or more execution contexts and capabilities defining permissions for the object to access the kernel resource of the system.

15. The system of claim 14 wherein the VMM 1 of the memory is further configured to create a virtual machine to contain the guest operating system, the virtual machine bound to a clone of the main protection domain representative of the guest operating system.

16. The system of claim 15 wherein the clone of the main protection domain is created by copying the execution contexts and capabilities of the main protection domain, wherein the capabilities of the clone of the main protection domain are more restricted than the capabilities of the main protection domain with respect to access to the kernel resource.

17. The system of claim 13 , wherein the memory further comprises a behavioral analysis logic engine that, when executed by the one or more processing units, correlates the dynamic analysis results against correlation rules to generate correlation information pertaining to a level of risk used to arrive at a decision of maliciousness.

18. The system of claim 17 , wherein the memory further comprises a classifier that, when executed by the one or more processing units, uses the correlation information to render a decision as to whether the object is malicious, the classifier further configured to classify the correlation information, including the behaviors and the capability violation, of the object relative to known malware.

Assignments (13)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
MERGER Recorded Aug 13, 2024
From: FIREEYE SECURITY HOLDINGS US LLC
To: MUSARUBRA US LLC
Reel/Frame 068581/0279 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2023
From: MANDIANT, INC.
To: FIREEYE SECURITY HOLDINGS US LLC
Reel/Frame 063287/0707 →
CHANGE OF NAME Recorded Mar 16, 2023
From: FIREEYE, INC.
To: MANDIANT, INC.
Reel/Frame 063287/0702 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0791 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0681 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 13, 2018
From: ISMAEL, OSMAN ABDOUL
To: FIREEYE, INC.
Reel/Frame 046078/0192 →
Continuity (2)
Division 14962497 · Dec 8, 2015
Provisional Application 62097499 · Dec 29, 2014
Cited By (5)
US 12,200,013 US 12,248,563 US 12,363,145 US 12,445,458 US 12,717,971