Palo Alto Networks, Inc.
Evaluating malware in a virtual machine using copy-on-write

Last updated:

Abstract:

Evaluating a potentially malicious sample using a copy-on-write overlay is disclosed. A first virtual machine instance is initialized as a copy-on-write overlay associated with an original virtual machine image. The first virtual machine image is started and a first sample is executed. A second virtual machine instance is initialized as a copy-on-write overlay associated with a second original virtual machine image. The second virtual machine image is started and a second sample is executed. The first and second samples are executed at an overlapping time.

Status:
Grant
Type:

Utility

Filling date:

6 Feb 2018

Issue date:

9 Jun 2020