IP Library Patent Application 17958538
Patent Application
App. No. 17/958,538

SYSTEM TO TERMINATE MALICIOUS PROCESS IN A DATA CENTER

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
17/958,538
Abstract

Example methods and systems for malicious process termination are described. In one example, a computer system may detect a first instance of a malicious network activity associated with a first virtualized computing instance. Termination of a first process implemented by the first virtualized computing instance may be triggered, the first instance of the malicious network activity being associated with the first process. The computer system may obtain event information associated with the first process and/or the first instance of the malicious network activity, and trigger termination of a second process implemented by a second virtualized computing instance based on the event information. Examples of the present disclosure may be implemented to leverage the detection of the first instance of the malicious network activity to terminate both the first process and the second process, and to block a second instance of a malicious network activity associated with the second process.

Claims (57)

1 . A method for a computer system to perform malicious process termination, wherein the method comprises:

detecting a first instance of a malicious network activity associated with a first virtualized computing instance;

triggering termination of a first process implemented by the first virtualized computing instance, the first instance of the malicious network activity being associated with the first process;

obtaining event information associated with the first process or the first instance of the malicious network activity, or both; and

triggering termination of a second process implemented by a second virtualized computing instance based on the event information, thereby leveraging the detection of the first instance of the malicious network activity to terminate both the first process and the second process, and to block a second instance of a malicious network activity associated with the second process.

2 . The method of claim 1 , wherein detecting the first instance of the malicious network activity comprises:

receiving an alert specifying the first instance of the malicious network activity, wherein the alert specifies address information associated with the first virtualized computing instance.

3 . The method of claim 2 , wherein detecting the first instance of the malicious network activity comprises:

receiving the alert from an entity capable of detecting the first instance of the malicious network activity based on one or more packets originating from, or destined for, the first virtualized computing instance.

4 . The method of claim 1 , wherein triggering termination of the first process comprises:

identifying a first malware protection service (MPS) instance associated with the first virtualized computing instance; and

generating and sending a first notification to the first MPS instance to trigger termination of the first process.

5 . The method of claim 1 , wherein triggering termination of the second process comprises:

disseminating the event information by generating and sending a second notification to at least one second MPS instance to trigger the termination of the second process, wherein the second process is implemented by the second virtualized computing instance (a) at the time the event information is disseminated or (b) after the event information is disseminated.

6 . The method of claim 5 , wherein triggering termination of the second process comprises:

generating the second notification based on the event information, wherein the second notification specifies a process hash information associated with both the first process and the second process.

7 . The method of claim 1 , wherein obtaining the event information comprises at least one of the following:

obtaining process event information that includes one or more of the following: process identifier (ID), process hash information, file name and certificate or license information; and

obtaining network event information that includes one or more of the following: source address information, destination address information, source port number, destination port number, protocol and uniform resource locator (URL).

8 . A non-transitory computer-readable storage medium that includes a set of instructions which, in response to execution by a processor of a computer system, cause the processor to perform a method of malicious process termination, wherein the method comprises:

detecting a first instance of a malicious network activity associated with a first virtualized computing instance;

triggering termination of a first process implemented by the first virtualized computing instance, the first instance of the malicious network activity being associated with the first process;

obtaining event information associated with the first process or the first instance of the malicious network activity, or both; and

triggering termination of a second process implemented by a second virtualized computing instance based on the event information, thereby leveraging the detection of the first instance of the malicious network activity to terminate both the first process and the second process, and to block a second instance of a malicious network activity associated with the second process.

9 . The non-transitory computer-readable storage medium of claim 8 , wherein detecting the first instance of the malicious network activity comprises:

receiving an alert specifying the first instance of the malicious network activity, wherein the alert specifies address information associated with the first virtualized computing instance.

10 . The non-transitory computer-readable storage medium of claim 9 , wherein detecting the first instance of the malicious network activity comprises:

receiving the alert from an entity capable of detecting the first instance of the malicious network activity based on one or more packets originating from, or destined for, the first virtualized computing instance.

11 . The non-transitory computer-readable storage medium of claim 8 , wherein triggering termination of the first process comprises:

identifying a first malware protection service (MPS) instance associated with the first virtualized computing instance; and

generating and sending a first notification to the first MPS instance to trigger termination of the first process.

12 . The non-transitory computer-readable storage medium of claim 8 , wherein triggering termination of the second process comprises:

disseminating the event information by generating and sending a second notification to at least one second MPS instance to trigger the termination of the second process, wherein the second process is implemented by the second virtualized computing instance (a) at the time the event information is disseminated or (b) after the event information is disseminated.

13 . The non-transitory computer-readable storage medium of claim 12 , wherein triggering termination of the second process comprises:

generating the second notification based on the event information, wherein the second notification specifies a process hash information associated with both the first process and the second process.

14 . The non-transitory computer-readable storage medium of claim 8 , wherein obtaining the event information comprises at least one of the following:

obtaining process event information that includes one or more of the following: process identifier (ID), process hash information, file name and certificate or license information; and

obtaining network event information that includes one or more of the following: source address information, destination address information, source port number, destination port number, protocol, and uniform resource locator (URL).

15 . A computer system, comprising a malware protection engine to:

detect a first instance of a malicious network activity associated with a first virtualized computing instance;

trigger termination of a first process implemented by the first virtualized computing instance, the first instance of the malicious network activity being associated with the first process;

obtain event information associated with the first process or the first instance of the malicious network activity, or both; and

trigger termination of a second process implemented by a second virtualized computing instance based on the event information, thereby leveraging the detection of the first instance of the malicious network activity to terminate both the first process and the second process, and to block a second instance of a malicious network activity associated with the second process.

16 . The computer system of claim 15 , wherein the malware protection engine is to detect the first instance of the malicious network activity by performing the following:

receive an alert specifying the first instance of the malicious network activity, wherein the alert specifies address information associated with the first virtualized computing instance.

17 . The computer system of claim 16 , wherein the malware protection engine is to detect the first instance of the malicious network activity by performing the following:

receive the alert from an entity capable of detecting the first instance of the malicious network activity based on one or more packets originating from, or destined for, the first virtualized computing instance.

18 . The computer system of claim 15 , wherein the malware protection engine is to trigger termination of the first process by performing the following:

identify a first malware protection service (MPS) instance associated with the first virtualized computing instance; and

generate and send a first notification to the first MPS instance to trigger termination of the first process.

19 . The computer system of claim 15 , wherein the malware protection engine is to trigger termination of the second process by performing the following:

disseminate the event information by generating and sending a second notification to at least one second MPS instance to trigger the termination of the second process, wherein the second process is implemented by the second virtualized computing instance (a) at the time the event information is disseminated or (b) after the event information is disseminated.

20 . The computer system of claim 19 , wherein the malware protection engine is to trigger termination of the second process by performing the following:

generate the second notification based on the event information, wherein the second notification specifies a process hash information associated with both the first process and the second process.

21 . The computer system of claim 15 , wherein the malware protection engine is to obtain the event information by performing the following at least one of the following:

obtain process event information that includes one or more of the following: process identifier (ID), process hash information, file name and certificate or license information; and

obtain network event information that includes one or more of the following: source address information, destination address information, source port number, destination port number, protocol, and uniform resource locator (URL).

Assignments (2)
CHANGE OF NAME Recorded May 8, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 067355/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 3, 2022
From: GAMBHIR PAREKH, MANISHA SAMEER
To: VMWARE, INC.
Reel/Frame 061285/0467 →