CA2899201C

Method and system for intrusion and extrusion detection

Abstract

A hypervisor includes an analysis trigger monitoring system. One or more analysis trigger parameters are defined and analysis trigger data representing the analysis trigger parameters is generated. The analysis trigger data is then provided to the analysis trigger monitoring system and the analysis trigger monitoring system is used to monitor at least a portion of the message traffic sent to, and/or sent from, a virtual asset controlled by the hypervisor to detect any message including one or more of the one or more analysis trigger parameters. A copy of at least a portion of any detected message including one or more of the one or more analysis trigger parameters is then transferred to one or more analysis systems for further analysis.

CA2899201C, drawing sheet 1
Sheet 1 of 3

Term

8.2 yearsleft in the term

Expires 24 November 2034.

  1. Priority
  2. Filed
  3. Granted
  4. Today
  5. Expires

24 claims: 3 independent, 21 dependent

  1. 1
    A system for intrusion and extrusion detection comprising:at least one processor;and at least one memory coupled to the at least one processor, the at least one memory having stored therein instructions which when executed by any set of the one or more processors, perform a process for intrusion and extrusion detection, the process for intrusion and extrusion detection including: providing a network communications system, the network communications system controlling message traffic sent to, and/or sent from, a virtual asset;providing the network communications system an analysis trigger monitoring system;defining one or more analysis trigger parameters;generating analysis trigger data representing the analysis trigger parameters;providing the analysis trigger data to the analysis trigger monitoring system;using the analysis trigger monitoring system and the analysis trigger data to monitor at least a portion of the message traffic sent to, and/or sent from, the virtual asset controlled by the network communications system to detect any message including one or more of the one or more analysis trigger parameters, wherein all message traffic sent to and/or sent from the virtual asset is relayed by the network communications system using a first communication channel;classifying any detected message including one or more of the one or more analysis trigger parameters as a suspect message;for each suspect message generating suspect message copy data representing a copy of at least a portion of the suspect message;and -33Date Reçue/Date Received 2021-02-02 transferring the suspect message copy data to one or more analysis systems for further analysis, the suspect message copy data being transferred to the one or more analysis systems through an analysis communications channel that is distinct from the first communications channel.
  2. 9
    A system for hypervisor assisted intrusion and extrusion detection comprising:at least one processor;and at least one memory coupled to the at least one processor, the at least one memory having stored therein instructions which when executed by any set of the one or more processors, perform a process for hypervisor assisted intrusion and extrusion detection, the process for hypervisor assisted intrusion and extrusion detection including: providing a hypervisor, the hypervisor controlling a virtual asset;providing the hypervisor an analysis trigger monitoring system;defining one or more analysis trigger parameters;generating analysis trigger data representing the analysis trigger parameters;providing the analysis trigger data to the analysis trigger monitoring system;-36Date Reçue/Date Received 2021-02-02 using the analysis trigger monitoring system and the analysis trigger data to monitor at least a portion of the message traffic sent to, and/or sent from, the virtual asset controlled by the hypervisor to detect any message including one or more of the one or more analysis trigger parameters, wherein all message traffic sent to and/or sent from the virtual asset is relayed by the hypervisor using a first communication channel;classifying any detected message including one or more of the one or more analysis trigger parameters as a suspect message;for each suspect message generating suspect message copy data representing a copy of at least a portion of the suspect message;and transferring the suspect message copy data to one or more analysis systems for further analysis, the suspect copy data being transferred to the analysis system through an analysis communications channel that is distinct from the first communications channel.
  3. 17
    A system for hypervisor assisted intrusion and extrusion detection comprising:a host system, the host system hosting at least one virtual asset;a hypervisor controlling the at least one virtual asset, the hypervisor being associated with the host system;-39Date Reçue/Date Received 2021-02-02 a first communications channel through which all the message traffic sent to, and/or sent from, the at least one virtual asset controlled by the hypervisor;an analysis trigger monitoring module, the analysis trigger monitoring module being associated with the hypervisor;one or more analysis systems for performing analysis of copy data representing a copy of at least a portion of a suspect message;at least one analysis communications channel that is distinct from the first communications channel for transferring the suspect message copy data to the one or more analysis systems for further analysis;at least one processor;and at least one memory coupled to the at least one processor, the at least one memory having stored therein instructions which when executed by any set of the one or more processors, perform a process for hypervisor assisted intrusion and extrusion detection, the process for hypervisor assisted intrusion and extrusion detection including: defining one or more analysis trigger parameters;generating analysis trigger data representing the analysis trigger parameters;providing the analysis trigger data to the analysis trigger monitoring module;using the analysis trigger monitoring module and the analysis trigger data to monitor at least a portion of the message traffic sent to, and/or sent from, the one or more virtual assets to detect any message including one or more of the one or more analysis trigger parameters;classifying any detected message including one or more of the one or more analysis trigger parameters as a suspect message;for each suspect message generating suspect message copy data representing a copy of at least a portion of the suspect message;and -40Date Reçue/Date Received 2021-02-02 transferring the suspect message copy data to one or more of the one or more analysis systems for further analysis.