VIRTUAL MACHINE SYSTEM, SYSTEM FOR FORCING POLICY, METHOD FOR FORCING POLICY, AND VIRTUAL MACHINE CONTROL PROGRAM
1 Assignment
0 Petitions
Accused Products
Abstract
A virtual machine system that builds one or more virtual machines on a real machine has a hypervisor for realizing access to virtualized hardware by a guest OS that is an operating system running on the virtual machines or an application running on the guest OS by means of a physical device that the real machine has. The hypervisor includes a setting item information holding unit that holds setting item information in which a security policy is indicated by the setting value of a setting item; a setting detecting unit that monitors an instruction executed by the guest OS and the output of the physical device to detect the setting value that is set in the setting item of the setting item information holding unit or a setting value that is about to be changed therein; and a setting applying unit that, when the detected setting value and the setting value indicated by the setting item information differ from each other, applies the setting value indicated by the setting item information to the guest OS or application that is the setting target of the setting item.
38 Citations
26 Claims
-
1-14. -14. (canceled)
-
15. A virtual machine system that builds one or more virtual machines on a real machine, comprising
a hypervisor that realizes access to virtualized hardware by a guest OS that is an operating system running on said virtual machines or an application running on said guest OS by means of a physical device that said real machine has, said hypervisor including: -
a setting item information holding unit that holds setting item information in which a security policy to be applied to said virtual machine system is indicated as a setting value of a setting item corresponding to a type of said guest OS or a type of said application; a setting detecting unit that monitors an instruction executed by said guest OS and an output of said physical device, based on said setting item information, and detects the setting value that is set in said setting item of said setting item information holding unit or a setting value that is about to be changed; and a setting applying unit that, when the setting value detected by said setting detecting unit and the setting value indicated by said setting item information differ from each other, applies the setting value indicated by said setting item information to said guest OS or said application that is a setting target of said setting item, using hardware access from said guest OS or said application. - View Dependent Claims (16, 17, 18, 19, 20, 21, 22)
-
-
23. A policy forcing system that forces a security policy on a virtual machine system that builds one or more virtual machines on a real machine, comprising:
-
said virtual machine system; and a management system that manages said security policy to be applied to said virtual machine system, said virtual machine system including a hypervisor that realizes access to virtualized hardware by a guest OS that is an operating system running on said virtual machines or an application running on said guest OS by means of a physical device that said real machine has, said hypervisor including; a setting item information holding unit that holds setting item information in which said security policy to be applied to said virtual machine system is indicated as a setting value of a setting item corresponding to a type of said guest OS or a type of said application; a setting detecting unit that monitors an instruction executed by said guest OS and an output of said physical device, based on said setting item information, and detects the setting value that is set in said setting item of said setting item information holding unit or a setting value that is about to be changed; and a setting applying unit that, when the setting value detected by said setting detecting unit and the setting value indicated by said setting item information differ from each other, applies the setting value indicated by said setting item information to said guest OS or said application that is a setting target of said setting item, using hardware access from said guest OS or said application. - View Dependent Claims (24)
-
-
25. A policy forcing method for forcing a security policy on a virtual machine system that builds one or more virtual machines on a real machine,
said virtual machine system including a hypervisor that realizes access to virtualized hardware by a guest OS that is an operating system running on said virtual machines or an application running on said guest OS by means of a physical device that said real machine has, said policy forcing method comprising: -
holding setting item information in which said security policy to be applied to said virtual machine system is indicated as a setting value of a setting item corresponding to a type of said guest OS or a type of said application, said holding the setting item information being performed by said hypervisor; monitoring an instruction executed by said guest OS and an output of said physical device, based on said setting item information, to detect the setting value that is set in said setting item of said setting item information holding unit or a setting value that is about to be changed, said monitoring the instruction and the output being performed by said hypervisor; and when the setting value detected by said setting detecting unit and the setting value indicated by said setting item information differ from each other, applying the setting value indicated by said setting item information to said guest OS or said application that is a setting target of said setting item, using hardware access from said guest OS or said application, said applying the setting value being performed by said hypervisor. - View Dependent Claims (26)
-
Specification