×

Systems and methods involving features of hardware virtualization such as separation kernel hypervisors, hypervisors, hypervisor guest context, hypervisor contest, rootkit detection/prevention, and/or other features

  • US 9,218,489 B2
  • Filed: 06/02/2014
  • Issued: 12/22/2015
  • Est. Priority Date: 06/26/2012
  • Status: Active Grant
First Claim
Patent Images

1. A method for processing information securely, the method comprising:

  • partitioning hardware platform resources via a separation kernel hypervisor into a plurality of guest operating system virtual machine protection domains; and

    isolating the domains in time and/or space from each other;

    hosting the plurality of quest operating system virtual machine protection domains by the separation kernel hypervisor;

    providing a dedicated virtualization assistance layer (VAL) including a virtual representation of the hardware platform in each of the quest operating system virtual machine protection domains such that the dedicated VAL security processing is not performed in the separation kernel hypervisor;

    hosting at least one malicious code defense mechanism that executes within the virtual hardware platform in each of the plurality of quest operating system virtual machine protection domains via the separation kernel hypervisor;

    upon detection of a disk sector access attempt, securely transition execution to the malicious code defense mechanism within the VAL in a manner isolated from the quest operating system;

    securely determining, via the malicious code defense mechanism, a policy decision regarding the disk sector access attempt; and

    transitioning execution back to the separation kernel hypervisor to continue processing regarding enforcement of or taking action in connection with the policy decision.

View all claims
  • 3 Assignments
Timeline View
Assignment View
    ×
    ×