发明名称 THREAT-AWARE MICROVISOR
摘要 A threat-aware microvisor is configured to facilitate real-time security analysis, including exploit detection and threat intelligence, of operating system processes executing on a node of a network environment. The microvisor may be embodied as a module disposed or layered beneath (underlying) an operating system kernel executing on the node to thereby control privileges (i.e., access permissions) to kernel resources, such as one or more central processing units (CPUs), network interfaces, memory, and/or devices, of the node. Illustratively, the microvisor may be configured to control access to one or more of the resources in response to a request by an operating system process to access the resource.
申请公布号 US2015199513(A1) 申请公布日期 2015.07.16
申请号 US201414229533 申请日期 2014.03.28
申请人 FireEye, Inc. 发明人 Ismael Osman Abdoul;Aziz Ashar
分类号 G06F21/55 主分类号 G06F21/55
代理机构 代理人
主权项 1. A system comprising: a central processing unit (CPU) adapted to execute a process, an operating system kernel and a microvisor; and a memory configured to store the process, the operating system kernel and the microvisor, the microvisor including: a first protection domain having a plurality of execution contexts and scheduling contexts, each execution context linked to a scheduling context and interacting with capabilities, wherein the capabilities of the first protection domain are configured to specify access control permissions to kernel resources accessible by the process, the first protection domain associated with services provided to the process by ii the operating system kernel to control the kernel resources accessible by the process; anda second protection domain configured as a clone of the first protection domain except for the capabilities, wherein the capabilities of the second protection domain are configured to specify limited access control permissions to the kernel resources accessible by the process, the second protection domain associated with the process.
地址 Milpitas CA US