| CPC H04L 63/0254 (2013.01) [H04L 63/1491 (2013.01); H04L 63/205 (2013.01)] | 21 Claims |

|
1. A method, comprising:
intercepting a service query from a virtualized computing instance supported by the computer system to pause forwarding of the service query towards a destination;
obtaining, from a guest introspection agent running on a guest operating system of the virtualized computing instance, context information collected by the guest introspection agent and associated with an application, wherein the service query originates from the application running on the virtualized computing instance and the context information comprises information additional to an identity of the application; and
in response to determination that the service query is a potential security threat based on the context information, performing service query filtering to inspect the service query for malicious activity;
otherwise, in response to determination that the service query is not a potential security threat based on the context information, skipping the service query filtering and allowing forwarding of the service query towards the destination.
|