Palo Alto Networks, Inc.
Evaluating malware in a virtual machine using copy-on-write
Last updated:
Abstract:
Evaluating a potentially malicious sample using a copy-on-write overlay is disclosed. A first virtual machine instance is initialized as a copy-on-write overlay associated with an original virtual machine image. The first virtual machine image is started and a first sample is executed. A second virtual machine instance is initialized as a copy-on-write overlay associated with a second original virtual machine image. The second virtual machine image is started and a second sample is executed. The first and second samples are executed at an overlapping time.
Status:
Grant
Type:
Utility
Filling date:
6 Feb 2018
Issue date:
9 Jun 2020