×

Threat-aware architecture

  • US 10,740,456 B1
  • Filed: 04/16/2018
  • Issued: 08/11/2020
  • Est. Priority Date: 01/16/2014
  • Status: Active Grant
First Claim
Patent Images

1. A system comprising:

  • a central processing unit (CPU);

    a memory configured to store, for execution by the CPU, a process, an operating system kernel, a virtual machine monitor (VMM) and a virtualization module,wherein the virtualization module is configured to communicate with the VMM, the virtualization module being further configured to execute at a privilege level of the CPU to control access permissions to a plurality of kernel resources accessible by the process,wherein the VMM is configured to execute at a first privilege level of the virtualization module to expose one or more of the plurality of kernel resources to the operating system kernel, the operating system kernel being configured to execute at a second privilege level lower than the first privilege level of the virtualization module, the VMM being configured to instantiate a virtual machine including the operating system kernel, wherein access to the plurality of kernel resources is controlled by the VMM among the virtual machine.

View all claims
  • 5 Assignments
Timeline View
Assignment View
    ×
    ×