发明名称 Multilevel Introspection of Nested Virtual Machines
摘要 Described systems and methods allow software introspection and/or anti-malware operations in a hardware virtualization system comprising a nested hierarchy of hypervisors and virtual machines, wherein introspection is carried out to any level of the hierarchy from a central location on a host hypervisor. An introspection engine intercepts a processor event occurring in a virtual machine exposed by a nested hypervisor, to determine an address of a software object executing on the respective virtual machine. The address is progressively translated down through all levels of the virtualization hierarchy, to an address within a memory space controlled by the host hypervisor. Anti-malware procedures can thus be performed from the level of the host hypervisor, and may comprise techniques such as signature matching and/or protecting certain areas of memory of the nested virtual machine.
申请公布号 US2014053272(A1) 申请公布日期 2014.02.20
申请号 US201213590098 申请日期 2012.08.20
申请人 LUKACS SANDOR;LUTAS DAN H.;TOSA RAUL V. 发明人 LUKACS SANDOR;LUTAS DAN H.;TOSA RAUL V.
分类号 G06F21/00;G06F9/455 主分类号 G06F21/00
代理机构 代理人
主权项
地址