IP Library Granted Patent US 11,294,705
Granted Patent B1
US 11,294,705 · App. 16/572,537 · Granted Apr 5, 2022

Selective virtualization for security threat detection

Inventors: Sushant Paithane (Sunnyvale, CA); Michael Vincent (Sunnyvale, CA)
Assignee: FireEye Security Holdings US LLC
G06F9/45558G06F21/53H04L63/145G06F2009/45562G06F2009/45587G06F2009/45591G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,294,705
App. No.
16/572,537
Granted
Apr 5, 2022
Kind
B1
Abstract

Selective virtualization of resources is provided, where the resources may be intercepted and services or the resources may be intercepted and redirected. Virtualization logic monitors for one or more activities that are performed in connection with one or more resources and conducted during processing of an object within the virtual machine. The first virtualization logic further selectively virtualizes resources associated with the one or more activities that are initiated during the processing of the object within the virtual machine by at least redirecting a first request of a plurality of requests to a different resource than requesting by a monitored activity of the one or more activities.

Claims (34)

1. A platform comprising:

one or more hardware processors; and

a memory coupled to the one or more processors, the memory comprises one or more virtual machines that are configured to process of an object under analysis and a virtual machine monitor that manages operability of the one or more virtual machines and is configured to detect and control handling of requests initiated by the one or more virtual machines,

wherein the virtual machine monitor comprises

a first logic configured to (i) temporarily halt execution of a first virtual machine of the one or more virtual machines in response to detecting a request from the first virtual machine and (ii) maintain an instruction pointer at a first virtual memory address associated with the request,

a second logic configured to (i) determine whether the request is associated with a virtualized resource and (ii) select a virtualization scheme for producing virtualized data, wherein the virtualization scheme being selected from (a) intercepting and redirecting the request to a different portion of system code than originally targeted when the request is directed to a first subset of activities and (b) intercepting and servicing the request when the request is directed to a second subset of activities, and

a third logic in communication with the second logic, the third logic to determine a memory location within the memory for placement of the virtualized data and to subsequently modify the instruction pointer to a second virtual memory address so that, when the first virtual machine resumes execution, the request has been serviced.

2. The platform of claim 1 , wherein the virtual machine monitor corresponds to a type 1 hypervisor that runs directly on a hardware of the platform including the one or more hardware processors.

3. The platform of claim 1 , wherein the virtual machine monitor corresponds to a type 2 hypervisor that runs directly on a host operating system of the platform.

4. The platform of claim 1 , wherein the first logic includes virtual machine monitor (VMM) management logic.

5. The platform of claim 4 , wherein the VMM management logic invokes and passes operation control to the second logic operating as intercept logic.

6. The platform of claim 1 , wherein the second logic operating as an intercept logic accesses data to determine whether the request is associated with a prescribed interception point.

7. The platform of claim 6 , wherein the prescribed interception point is a hook or a break point.

8. The platform of claim 6 , wherein the prescribed interception point is an Application Programming Interface (API) call.

9. The platform of claim 6 , wherein responsive to the request being associated with the prescribed interception point, the intercept logic is configured to access one or more usage patterns to determine criteria for conducting virtualization of a requested resource.

10. The platform of claim 1 , wherein the second logic servicing the request by at least returning virtualized data to a process or a thread operating within the virtual machine that initiated the request.

11. The platform of claim 1 , wherein the second logic redirecting the request by at least generating a modified request operating as the request by changing a resource associated with the request and subsequently passing the request to system code for processing.

12. A computerized method comprising:

processing of an object under analysis by one or more virtual machines;

managing operability of the one or more virtual machines by a virtual machine monitor to detect and control handling of requests initiated by the one or more virtual machines;

temporarily halting execution of a first virtual machine of the one or more virtual machines in response to detecting a request from the first virtual machine;

maintaining an instruction pointer at a first virtual memory address associated with the request;

determining whether the request is associated with a virtualized resource;

selecting a virtualization scheme for producing virtualized data when the request is associated with a virtualization resource, wherein the virtualization scheme being selected from (a) intercepting and redirecting the request to a different portion of system code than originally targeted when the request is directed to a first subset of activities and (b) intercepting and servicing the request when the request is directed to a second subset of activities; and

determining a memory location within a virtual memory for placement of the virtualized data and to subsequently modify the instruction pointer to a second virtual memory address so that, when the first virtual machine resumes execution, the request has been serviced.

13. The computerized method of claim 12 , wherein the temporarily halting of the execution of the first virtual machine, the maintaining of the instruction pointer, the determining whether the request is associated with the virtualized resource, the selecting of the virtualization scheme, and the determining of the memory location is conducted by a virtual machine monitor corresponds to a type 1 hypervisor that runs directly on hardware.

14. The computerized method of claim 12 , wherein the temporarily halting of the execution of the first virtual machine, the maintaining of the instruction pointer, the determining whether the request is associated with the virtualized resource, the selecting of the virtualization scheme, and the determining of the memory location is conducted by a virtual machine monitor corresponds to a type 2 hypervisor that runs directly on a host operating system.

15. The computerized method of claim 12 , wherein the temporarily halting of the execution of the first virtual machine and the maintaining of the instruction pointer is conducted by management logic of a virtual machine monitor (VMM).

16. The computerized method of claim 15 , wherein the VMM management logic invokes and passes operation control to intercept logic of the VMM, the intercept logic being configured to determine whether the request is associated with the virtualized resource and select of the virtualization scheme.

17. The computerized method of claim 16 , wherein the intercept logic accesses data to determine whether the request is associated with a prescribed interception point.

18. The computerized method of claim 17 , wherein the prescribed interception point is a hook or a break point.

19. The computerized method of claim 16 , wherein the prescribed interception point is an Application Programming Interface (API) call.

20. The computerized method of claim 12 , wherein the servicing of the request includes at least returning virtualized data to a process or a thread operating within the virtual machine that initiated the request.

21. The computerized method of claim 12 , wherein the redirecting of the request includes at least generating a modified request operating as the request by changing a resource associated with the request and subsequently passing the request to system code for processing.

Assignments (13)
RELEASE OF SECURITY INTEREST Recorded Aug 16, 2024
From: STG PARTNERS, LLC
To: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
Reel/Frame 068671/0435 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068656/0098 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068657/0843 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 15, 2024
From: MUSARUBRA US LLC
To: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
Reel/Frame 068657/0764 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY HOLDINGS LLC; SKYHIGH SECURITY LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 068657/0666 →
INTELLECTUAL PROPERTY ASSIGNMENT AGREEMENT Recorded Aug 15, 2024
From: MAGENTA SECURITY INTERMEDIATE HOLDINGS LLC
To: MAGENTA SECURITY HOLDINGS LLC
Reel/Frame 068656/0920 →
MERGER Recorded Aug 13, 2024
From: FIREEYE SECURITY HOLDINGS US LLC
To: MUSARUBRA US LLC
Reel/Frame 068581/0279 →
SECURITY INTEREST Recorded Aug 1, 2024
From: MUSARUBRA US LLC; SKYHIGH SECURITY LLC
To: STG PARTNERS, LLC
Reel/Frame 068324/0731 →
CHANGE OF NAME Recorded Mar 16, 2023
From: FIREEYE, INC.
To: MANDIANT, INC.
Reel/Frame 063114/0766 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 16, 2023
From: MANDIANT, INC.
To: FIREEYE SECURITY HOLDINGS US LLC
Reel/Frame 063114/0701 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 19, 2022
From: PAITHANE, SUSHANT; VINCENT, MICHAEL
To: FIREEYE, INC.
Reel/Frame 058700/0901 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0791 →
FIRST LIEN PATENT SECURITY AGREEMENT Recorded Oct 11, 2021
From: FIREEYE SECURITY HOLDINGS US LLC
To: UBS AG, STAMFORD BRANCH, AS COLLATERAL AGENT
Reel/Frame 057772/0681 →
Continuity (2)
Continuation 15081775 · Mar 25, 2016
Provisional Application 62140963 · Mar 31, 2015