FIELD: information technologies.
SUBSTANCE: invention relates to the field of computer security. Processor is configured to generate a virtual machine (VM) suspend event (e.g., exiting from VM or virtualisation exclusion) when a guest instruction executing within a guest VM implements a memory access violation. In some embodiments, the processor is further configured to delay generation of the VM suspend event until the execution stage of the pipeline for the guest instruction is completed, and for storing the execution step results in a special area (e.g., a special processor register read by the security software) before event generation.
EFFECT: providing computer security of a virtual machine.
21 cl, 11 dwg
Title | Year | Author | Number |
---|---|---|---|
PAGE ERROR INSERTION IN VIRTUAL MACHINES | 2014 |
|
RU2659472C2 |
MEMORY INTROSPECTION ENGINE FOR PROTECTING INTEGRITY OF VIRTUAL MACHINES | 2014 |
|
RU2640300C2 |
EVALUATION OF PROCESS OF MALWARE DETECTION IN VIRTUAL MACHINES | 2014 |
|
RU2634205C2 |
COMPUTER SECURITY SYSTEMS AND METHODS USING ASYNCHRONOUS INTROSPECTION EXCEPTIONS | 2016 |
|
RU2703156C2 |
EVENT FILTERING FOR SECURITY APPLICATIONS OF VIRTUAL MACHINES | 2017 |
|
RU2723668C1 |
SYSTEM AND METHODS FOR DECRYPTING NETWORK TRAFFIC IN A VIRTUALIZED ENVIRONMENT | 2017 |
|
RU2738021C2 |
COMPLEX CLASSIFICATION FOR DETECTING MALWARE | 2014 |
|
RU2645268C2 |
DOUBLE SELF-TEST OF MEMORY FOR PROTECTION OF MULTIPLE NETWORK ENDPOINTS | 2016 |
|
RU2714607C2 |
SYSTEM AND METHODS FOR AUDITING A VIRTUAL MACHINE | 2017 |
|
RU2691187C1 |
SYSTEMS AND METHODS FOR MULTILEVEL PROCESSING OF INTERCEPTIONS IN VIRTUAL MACHINE ENVIRONMENT | 2006 |
|
RU2412468C2 |
Authors
Dates
2019-04-29—Published
2015-08-11—Filed