×

Micro-virtualization architecture for threat-aware module deployment in a node of a network environment

  • US 9,946,568 B1
  • Filed: 01/28/2016
  • Issued: 04/17/2018
  • Est. Priority Date: 01/16/2014
  • Status: Active Grant
First Claim
Patent Images

1. A system comprising:

  • a central processing unit (CPU) adapted to execute a process, a single instance of an operating system kernel, a virtual machine monitor (VMM) and a virtualization module;

    a memory configured to store the process, the operating system kernel, the VMM and the virtualization module,the virtualization module disposed beneath the operating system kernel and configured to communicate with the VMM, the virtualization module further configured to execute at a highest privilege level of the CPU to control access permissions to a plurality of kernel resources accessible by the process, andthe VMM configured as a pass-through module executing at a highest privilege level of the virtualization module to expose the kernel resources to the operating system kernel, the operating system kernel configured to execute at a privilege level lower than the highest privilege level of the virtualization module, the VMM configured to instantiate a virtual machine containing the operating system kernel, the VMM further configured to instantiate a micro-virtual machine restricted to containing the process, wherein access to the kernel resources is controlled by the VMM among the virtual machine and the micro-virtual machine.

View all claims
  • 5 Assignments
Timeline View
Assignment View
    ×
    ×