The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Feb. 04, 2020

Filed:

Jan. 05, 2018
Applicant:

Vmware, Inc., Palo Alto, CA (US);

Inventors:

Jason A. Lango, Mountain View, CA (US);

Dennis Ramdass, Mountain View, CA (US);

James J. Voll, Palo Alto, CA (US);

Assignee:

VMware, Inc., Palo Alto, CA (US);

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 12/14 (2006.01); G06F 21/55 (2013.01); G06F 9/455 (2018.01); G06F 21/56 (2013.01); G06F 21/62 (2013.01);
U.S. Cl.
CPC ...
G06F 21/554 (2013.01); G06F 9/45558 (2013.01); G06F 21/56 (2013.01); G06F 21/6218 (2013.01); G06F 2009/45587 (2013.01); G06F 2221/034 (2013.01);
Abstract

In an approach, an intermediary guest manager operates within a virtual machine hosted by a host machine and managed by a hypervisor. The intermediary guest manager manages one or more guest operating systems operating within the virtual machine and implements one or more security services for the guest operating systems. The security services provided to the guest operating systems may include system call filtering, memory protections, secure memory dumps, and others. In some cases, the intermediary guest manager consults a threat defense policy which contains a number of records, where each record has one or more triggers representing suspicious activity and one or more actions to take in response to being triggered. When the intermediary guest manager identifies a request, such as a system call or memory access, that meets the trigger of a particular record, the intermediary guest manager executes the associated actions to remediate the suspicious activity.


Find Patent Forward Citations

Loading…