VMware, Inc.
SECURITY THREAT DETECTION BASED ON PROCESS INFORMATION
Last updated:
Abstract:
Example methods and systems for a computer system to perform security threat detection are described. In one example, a computer system may intercept an egress packet from a virtualized computing instance to pause forwarding of the egress packet towards a destination and obtain process information associated a process from which the egress packet originates. The computer system may initiate security analysis based on the process information. In response to determination that the process is a potential security threat based on the security analysis, the egress packet may be dropped, and a remediation action performed. Otherwise, the egress packet may be forwarded towards the destination.
Status:
Application
Type:
Utility
Filling date:
14 Jul 2020
Issue date:
20 Jan 2022