发明名称 Secure network optimizations when receiving data directly in a virtual machine's memory address space
摘要 Techniques are disclosed for increasing the security of a system where incoming network packets are directly placed into the memory space of a virtual machine (VM) operating system (OS) running on the system via direct memory access (DMA). In an embodiment, each packet is split into a first portion, which requires further processing, and a second portion, which may be immediately placed into the VM OS's memory address space. When the host OS running on the system completes processing the first portion, it places it directly before the second portion in the VM OS memory space and indicates to the VM OS that a packet is available. Techniques are further disclosed that mitigate the security risk in such systems related to VLAN ID configuration.
申请公布号 US7966620(B2) 申请公布日期 2011.06.21
申请号 US20080267444 申请日期 2008.11.07
申请人 MICROSOFT CORPORATION 发明人 MUNDKUR SAMBHRAMA MADHUSUDHAN;DABAGH ALIREZA
分类号 G06F13/00 主分类号 G06F13/00
代理机构 代理人
主权项
地址