IP Library Patent Application 17948104
Patent Application
App. No. 17/948,104

HYPERVISOR-ASSISTED DATA BACKUP AND RECOVERY FOR NEXT GENERATION ANTI-VIRUS (NGAV) SYSTEMS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
17/948,104
Abstract

In one set of embodiments, an enhanced next generation anti-virus (NGAV) system is provided. In certain embodiments, this system includes a hypervisor-level agent that backs up VM data only when an instance of a guest application running in the VM has been flagged by the NGAV system as being potentially malicious (rather than on a constant, proactive basis). Further, the hypervisor-level agent performs this backup only with respect to data modified by that specific guest application instance (rather than backing up all data modified by the VM) and writes the backed-up data to a secure storage location which is inaccessible to the guest. The combination of these features addresses many of the problems and inefficiencies of existing NGAV systems.

Claims (47)

1 . A method comprising:

receiving, by a hypervisor of a host system, an indication of malicious activity with respect to an instance of a guest application running within a virtual machine (VM) of the host system;

receiving, by the hypervisor, information including a range of logical block addresses (LBAs) accessed by the instance;

monitoring, by the hypervisor, for input/output (I/O) activity directed to the range of LBAs; and

upon detecting a write to a data block in the range of LBAs, creating, by the hypervisor, a backup copy of data written via the write to a host-level storage of the host system.

2 . The method of claim 1 wherein the indication and the information is received from a next generation anti-virus (NGAV) engine in response to an initial determination made by the NGAV engine that the instance is likely malicious.

3 . The method of claim 1 wherein the host-level storage is inaccessible to the instance.

4 . The method of claim 1 wherein the range of LBAs corresponds to a file accessed by the instance, and wherein the information is a file map comprising mappings between the range of LBAs and a range of physical block addresses for the file.

5 . The method of claim 1 further comprising:

receiving another indication that the instance is not malicious; and

in response to receiving said another indication:

terminating the monitoring; and

deleting the backup copy from the host-level storage.

6 . The method of claim 5 wherein said another indication is received from a NGAV engine in response to a behavior-based analysis performed by the NGAV engine indicating that the instance is malicious.

7 . The method of claim 6 wherein the NGAV engine performs the behavior-based analysis using activity information regarding the instance that is collected by a NGAV sensor running within the VM.

8 . A non-transitory computer readable storage medium having stored thereon program code executable by a hypervisor of a computer system, the program code embodying a method comprising:

receiving an indication of malicious activity with respect to an instance of a guest application running within a virtual machine (VM) of the computer system;

receiving information including a range of logical block addresses (LBAs) accessed by the instance;

monitoring for input/output (I/O) activity directed to the range of LBAs; and

upon detecting a write to a data block in the range of LBAs, creating a backup copy of data written via the write to a host-level storage of the computer system.

9 . The non-transitory computer readable storage medium of claim 8 wherein the indication and the information is received from a next generation anti-virus (NGAV) engine in response to an initial determination made by the NGAV engine that the instance is likely malicious.

10 . The non-transitory computer readable storage medium of claim 8 wherein the host-level storage is inaccessible to the instance.

11 . The non-transitory computer readable storage medium of claim 8 wherein the range of LBAs corresponds to a file accessed by the instance, and wherein the information is a file map comprising mappings between the range of LBAs and a range of physical block addresses for the file.

12 . The non-transitory computer readable storage medium of claim 8 wherein the method further comprises:

receiving another indication that the instance is not malicious; and

in response to receiving said another indication:

terminating the monitoring; and

deleting the backup copy from the host-level storage.

13 . The non-transitory computer readable storage medium of claim 12 wherein said another indication is received from a NGAV engine in response to a behavior-based analysis performed by the NGAV engine indicating that the instance is malicious.

14 . The non-transitory computer readable storage medium of claim 13 wherein the NGAV engine performs the behavior-based analysis using activity information regarding the instance that is collected by a NGAV sensor running within the VM.

15 . A computer system comprising:

a processor; and

a non-transitory memory having stored thereon program code that, upon being executed by the processor, causes the processor to:

receive an indication of malicious activity with respect to an instance of a guest application running within a virtual machine (VM) of the computer system;

receive information including a range of logical block addresses (LBAs) accessed by the instance;

monitor for input/output (I/O) activity directed to the range of LBAs; and

upon detecting a write to a data block in the range of LBAs, create a backup copy of data written via the write to a host-level storage of the computer system.

16 . The computer system of claim 15 wherein the indication and the information is received from a next generation anti-virus (NGAV) engine in response to an initial determination made by the NGAV engine that the instance is likely malicious.

17 . The computer system of claim 15 wherein the host-level storage is inaccessible to the instance.

18 . The computer system of claim 15 wherein the range of LBAs corresponds to a file accessed by the instance, and wherein the information is a file map comprising mappings between the range of LBAs and a range of physical block addresses for the file.

19 . The computer system of claim 15 wherein the program code further causes the processor to:

receive another indication that the instance is not malicious; and

in response to receiving said another indication:

terminate the monitoring; and

delete the backup copy from the host-level storage.

20 . The computer system of claim 19 wherein said another indication is received from a NGAV engine in response to a behavior-based analysis performed by the NGAV engine indicating that the instance is malicious.

21 . The computer system of claim 20 wherein the NGAV engine performs the behavior-based analysis using activity information regarding the instance that is collected by a NGAV sensor running within the VM.

Assignments (2)
CHANGE OF NAME Recorded Feb 27, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 066692/0103 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 19, 2022
From: VIJAYVARGIYA, SHIRISH; DHANASEKAR, VASANTHA KUMAR; CHITNIS, BIDESH; OGALE, NAKUL RANJAN; CHANDRASEKHAR, BHARATH KUMAR; WEISSMAN, BORIS; SPEAKER, ROBERT JAMES
To: VMWARE INC.
Reel/Frame 061142/0275 →