EXPLOIT DETECTION SYSTEM WITH THREAT-AWARE MICROVISOR

Patent №

US 9,507,935

Granted

2016-11-29

Filed 2014

Owner

FIREEYE, INC.

Lab

AI components

2

planning · hardware

Assignment

Recorded

Dataset

AIPD

2023_r1 edition

Application

14229580

An exploit detection system deploys a threat-aware microvisor to facilitate real-time security analysis, including exploit detection and threat intelligence, of an operating system process executing on a node of a network environment. The microvisor may be organized as a main protection domain representative of the operating system process. In response to the process attempting to access a kernel resource for which it does not have permission, a capability violation may be generated at the main protection domain of the microvisor and a micro-virtual machine (VM) may be spawned as a container configured to encapsulate the process. The main protection domain may then be cloned to create a cloned protection domain that is representative of the process and that is bound to the spawned micro-VM. Capabilities of the cloned protection domain may be configured to be more restricted than the capabilities of the main protection domain with respect to access to the kernel resource. The restricted capabilities may be configured to generate more capability violations than those generated by the capabilities of the main protection domain and, in turn, enable further monitoring of the process as it attempts to access the kernel resource.

PlanningAI hardwareG06F 21/552G06F 9/45533G06F 9/45558G06F 9/5027G06F 21/53G06F 21/629G06F 2009/45587

AI classification

Planning0.99
AI hardware0.82
Knowledge representation0.39
Natural language0.00
Evolutionary computation0.00
Machine learning0.00
Vision0.00
Speech0.00

Ownership

FIREEYE, INC.

assignment · 328030982

Assignors

ISMAEL, OSMAN ABDOUL, AZIZ, ASHAR

On an employer assignment, the assignors are typically the inventors.

From the same owner

© 2026 NYSGPT2525 LLC