Inventors
Micha Moffie, David Kaeli, Aviram Cohen, Javed Aslam, Malak Alshawabkeh, Jennifer Dy, Fatemeh Azmandian
Publication date
2014/5/6
Patent office
US
Patent number
8719936
Application number
12865795
Description
An intrusion detection system collects architectural level events from a Virtual Machine Monitor where the collected events represent operation of a corresponding Virtual Machine. The events are consolidated into features that are compared with features from a known normal operating system. If an amount of any differences between the collected features and the normal features exceeds a threshold value, a compromised Virtual Machine may be indicated. The comparison thresholds are determined by training on normal and abnormal systems and analyzing the collected events with machine learning algorithms to arrive at a model of normal operation.
Total citations
2013201420152016201720182019202020212022202320243712202012283524222611
Scholar articles
M Moffie, D Kaeli, A Cohen, J Aslam, M Alshawabkeh… - US Patent 8,719,936, 2014