Invention Grant
- Patent Title: Virtual machine security policy implementation
-
Application No.: US17008293Application Date: 2020-08-31
-
Publication No.: US11748140B2Publication Date: 2023-09-05
- Inventor: Michael Tsirkin , Amnon Ilan
- Applicant: RED HAT, INC.
- Applicant Address: US NC Raleigh
- Assignee: Red Hat, Inc.
- Current Assignee: Red Hat, Inc.
- Current Assignee Address: US NC Raleigh
- Agency: Lowenstein Sandler LLP
- Main IPC: G06F9/455
- IPC: G06F9/455 ; H04L9/40 ; G06F8/61

Abstract:
The technology disclosed herein enables a hypervisor to send a security policy to a virtual machine, which may use the security policy to validate system call invocations requested by a guest operating system. The system call invocations may be validated prior to being received by the hypervisor. The hypervisor may also validate system call invocations that are successfully validated by the virtual machine. An example method may include: identifying, by a hypervisor on a host machine, a security policy associated with a virtual machine, wherein the security policy specifies one or more validation rules, causing, by the hypervisor, the security policy to be imported into a guest operating system of the virtual machine from the hypervisor, and responsive to receiving, by the guest operating system, a first request to perform a system call, validating, by the guest operating system, the first request in accordance with the validation rules.
Public/Granted literature
- US20220066808A1 SECURITY FOR VIRTUAL MACHINES Public/Granted day:2022-03-03
Information query