MALWARE PROTECTION FOR VIRTUAL MACHINES
A computer-implemented method at a data management system comprises receiving a write made to a virtual machine; computing, outside of the virtual machine, a fingerprint of the write; comparing, outside of the virtual machine, the computed fingerprint to malware fingerprints in a malware catalog; repeating the computing and comparing; and disabling the virtual machine if malware is detected based on a number of matches from the comparing breaching a predetermined threshold over a predetermined amount of time.
1 . A data management system, comprising:
a storage appliance configured to store a snapshot of a virtual machine;
one or more processors in communication with the storage appliance, the one or more processors configured to perform operations including:
receiving a write made to the virtual machine;
computing, outside of the virtual machine, a fingerprint of the write;
comparing, outside of the virtual machine, the computed fingerprint to malware fingerprints in a malware catalog;
repeating the computing and comparing; and
disabling the virtual machine if malware is detected based on a number of matches from the comparing breaching a predetermined threshold over a predetermined amount of time.
2 . The system of claim 1 , wherein the operations further include restoring the virtual machine using the snapshot stored in the storage appliance to a state before the predetermined threshold was breached.
3 . The system of claim 1 , wherein the operations further include transmitting a warning to a user of the virtual machine.
4 . The system of claim 1 , wherein the operations further include generating the malware catalog including generating fingerprints of binaries and compressed binaries of known malware.
5 . The system of claim 1 , wherein the operations further include repeatedly generating snapshots of the virtual machine over time.
6 . The system of claim 1 , wherein the operations are performed in a device that is not hosting the virtual machine.
7 . The system of claim 1 , wherein the disabling determines if malware is present based on whether a number of matches from the comparing exceeds a predetermined threshold over a predetermined amount of time.
8 . A computer-implemented method at a data management system, the method comprising:
receiving a write made to a virtual machine;
computing, outside of the virtual machine, a fingerprint of the write;
comparing, outside of the virtual machine, the computed fingerprint to malware fingerprints in a malware catalog;
repeating the computing and comparing; and
disabling the virtual machine if malware is detected based on a number of matches from the comparing breaching a predetermined threshold over a predetermined amount of time.
9 . The method of claim 8 , further comprising restoring the virtual machine using a snapshot stored in a storage appliance to a state before the predetermined threshold was breached.
10 . The method of claim 8 , further comprising transmitting a warning to a user of the virtual machine.
11 . The method of claim 8 , further comprising generating the malware catalog including generating fingerprints of binaries and compressed binaries of known malware.
12 . The method of claim 8 , further comprising repeatedly generating snapshots of the virtual machine over time.
13 . The method of claim 8 , wherein the method performed in a device that is not hosting the virtual machine.
14 . The method of claim 8 , wherein the disabling determines if malware is present based on whether a number of matches from the comparing exceeds a predetermined threshold over a predetermined amount of time.
15 . A non-transitory, machine-readable medium storing instructions which, when read by a machine, cause the machine to perform operations comprising, at least:
receiving a write made to a virtual machine;
computing, outside of the virtual machine, a fingerprint of the write;
comparing, outside of the virtual machine, the computed fingerprint to malware fingerprints in a malware catalog;
repeating the computing and comparing; and
disabling the virtual machine if malware is detected based on a number of matches from the comparing breaching a predetermined threshold over a predetermined amount of time.
16 . The machine-readable medium of claim 15 , wherein the operations further include restoring the virtual machine using a snapshot stored in a storage appliance to a state before the predetermined threshold was breached.
17 . The machine-readable medium of claim 15 , wherein the operations further include transmitting a warning to a user of the virtual machine.
18 . The machine-readable medium of claim 15 , wherein the operations further include generating the malware catalog including generating fingerprints of binaries and compressed binaries of known malware.
19 . The machine-readable medium of claim 15 , wherein the operations further include repeatedly generating snapshots of the virtual machine over time.
20 . The machine-readable medium of claim 15 , wherein the operations are performed in a device that is not hosting the virtual machine.
21 . The machine-readable medium of claim 15 , wherein the disabling determines if malware is present based on whether a number of matches from the comparing exceeds a predetermined threshold over a predetermined amount of time.