IP Library Granted Patent US 7,581,085
Granted Patent B1
US 7,581,085 · App. 11/530,080 · Granted Aug 25, 2009

Fast stub and frame technology for virtual machine optimization

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,581,085
App. No.
11/530,080
Granted
Aug 25, 2009
Kind
B1
Abstract

A method and system for handling of potential unsafe instructions and/or for handling transfers of control in a Virtual Machine, that includes generating a frame composed of pages of analyzed code based on original guest code; identifying instructions within the frame that transfer control (or are otherwise unsafe); replacing instructions that transfer the control with an interrupt that transfers control to a stub in non-privileged code; wherein the stub checks whether the control transfer (or instruction) is safe or unsafe, and (i) for unsafe control transfers/unsafe instructions, switches the context to Virtual Machine Monitor; and (ii) for safe control transfers, executes the control transfer in non-privileged mode. The instructions that transfer control can include any of JMP, CALL, RET and RET(n). The instructions that transfer control can also include interrupts.

Claims (41)

1. A method for handling potentially unsafe instructions in a Virtual Machine, comprising:

(a) generating a frame composed of pages of analyzed code, the frame being based on original guest code and being a contiguous combination of sequential pages, such that when executing the analyzed code, a value of guest Execution Instruction Pointer (EIP) is the same as a value of the real EIP;

(b) identifying potentially unsafe instructions within the frame; and

(c) replacing selected potentially unsafe instructions with control transfer to a stub in non-privileged code and in a separate memory area from the analyzed code, wherein the stub checks whether executing the potentially unsafe instruction is safe or unsafe, and

(i) for instruction identified as unsafe, the stub switches a Virtual Machine Monitor context to full emulation; and

(ii) for instruction identified as safe, the stub bypasses the instruction in the Virtual Machine context.

2. The method of claim 1 , wherein the potentially unsafe instructions include transfer control instructions.

3. The method of claim 2 , wherein the transfer control instructions include any of JMP, CALL, RET and RET(n).

4. The method of claim 2 , wherein the stub checks the address to which control transfers and make decision about instruction is safe or unsafe based on the address.

5. The method of claim 1 , wherein control is transferred to the stub using an INT(n).

6. The method of claim 1 , wherein control is transferred to the stub using a jump.

7. A method for handling potentially unsafe instructions in a Virtual Machine, comprising:

(a) generating a frame composed of pages of analyzed code based on original guest code and being a contiguous combination of sequential pages, such that when executing the analyzed code, a value of guest Execution Instruction Pointer (EIP) is the same as a value of the real EIP;

(b) generating shadow frames corresponding to analyzed code frames;

(c) identifying the potentially unsafe instructions within the frame;

(d) replacing the potentially unsafe instructions with control transfer instructions to corresponding shadow frames;

(e) placing code overwritten by the control transfer instruction in the shadow frames;

(f) adding, to the shadow frame, instructions that transfers control to a stub in non-privileged code, the stub being located in a separate memory area from the analyzed code;

(g) wherein the stub checks whether the potentially unsafe instruction execution is safe or unsafe, and

(i) for the instruction identified as unsafe, the stub switches Virtual Machine Monitor context to full emulation; and

(ii) for the instruction identified as safe, the stub executes the control transfer in a non-privileged mode.

8. The method of claim 7 , further comprising grouping multiple frames of analyzed code into a superframe having a contiguous address space.

9. The method of claim 7 , further comprising grouping multiple frames of analyzed code and multiple shadow frames into a superframe having a contiguous address space.

10. A computer useable storage medium having computer program logic stored thereon for executing on a processor for handling potentially unsafe instructions, the computer program logic comprising:

(a) computer program code means for generating a frame composed of pages of analyzed code, the frame being based on original guest code and being a contiguous combination of sequential pages, such that when executing the analyzed code, a value of guest Execution Instruction Pointer (EIP) is the same as a value of the real EIP;

(b) computer program code means for identifying potentially unsafe instructions within the frame; and

(c) computer program code means for replacing selected potentially unsafe instructions with control transfer to a stub in non-privileged code, the stub being located in a separate memory area from the analyzed code, wherein the stub checks whether executing the potentially unsafe instruction is safe or unsafe, and

(i) for instruction identified as unsafe, the stub switches a Virtual Machine Monitor context to full emulation; and

(ii) for instruction identified as safe, the stub bypasses the instruction in the Virtual Machine context.

11. A method for handling transfers of control in a Virtual Machine, comprising:

(a) analyzing original guest code to identify potentially unsafe instructions in the original guest code;

(b) generating analyzed code with the potentially unsafe instructions replaced by breakpoints;

(c) placing the analyzed code into a frame, wherein the frame comprises a plurality of sequential consecutive pages in memory, and each page of the frame corresponds to a page of original guest code;

(d) wherein a page sequence in the frame corresponds to a page sequence of the original guest code, and a linear address space of the original guest code corresponds to a linear address space of the analyzed code, except for a base address of the linear address space;

(e) associating the frame with a memory segment, such that a processor can address the analyzed code in the frame using segment-based addressing, and such that an EIP of the executed analyzed code is the same as an EIP of the original guest code, if the original guest code were being executed.

12. The method of claim 11 , further comprising grouping multiple frames of analyzed code into a superframe having a contiguous linear address space.

13. The method of claim 11 , further comprising:

(a) generating a shadow frame such that code in the shadow frame is executed instead of the analyzed code when the analyzed contains an unsafe transfer of control instruction;

(b) replacing the unsafe transfer of control instruction in the frame with control transfer instructions to code in the shadow frames;

(c) replacing code overwritten by the control transfer instruction in the shadow frame; and

(d) adding, to the shadow frame, instructions that transfer control to a stub in non-privileged code, the stub being located in a separate memory area from the analyzed code.

Assignments (12)
RELEASE OF SECURITY INTEREST Recorded Jul 18, 2019
From: UBS AG, STAMFORD BRANCH, AS ADMINISTRATIVE AND COLLATERAL AGENT
To: COREL CORPORATION; CLEARSLIDE, INC.; PARALLELS INTERNATIONAL GMBH
Reel/Frame 049787/0073 →
RELEASE OF SECURITY INTEREST RECORDED AT : REEL 047973 FRAME 0797 Recorded Jul 17, 2019
From: UBS AG, STAMFORD BRANCH
To: PARALLELS INTERNATIONAL GMBH
Reel/Frame 049773/0590 →
SECURITY INTEREST Recorded Dec 21, 2018
From: PARALLELS INTERNATIONAL GMBH
To: UBS AG, STAMFORD BRANCH
Reel/Frame 047973/0797 →
MERGER Recorded Mar 6, 2018
From: PARALLELS IP HOLDINGS GMBH
To: PARALLELS INTERNATIONAL GMBH
Reel/Frame 045122/0592 →
RELEASE OF SECURITY INTEREST Recorded Dec 14, 2015
From: SILICON VALLEY BANK
To: PARALLELS SOFTWARE INTERNATIONAL, INC.
Reel/Frame 037287/0638 →
RELEASE OF SECURITY INTEREST Recorded Dec 14, 2015
From: SILICON VALLEY BANK
To: PARALLELS HOLDINGS LTD. (F/K/A SWSOFT HOLDINGS LTD.)
Reel/Frame 037289/0685 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 25, 2012
From: PARALLELS HOLDINGS, LTD.
To: PARALLELS IP HOLDINGS GMBH
Reel/Frame 027595/0187 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 31, 2011
From: PARALLELS SOFTWARE INTERNATIONAL, INC.
To: PARALLELS HOLDINGS, LTD.
Reel/Frame 027467/0328 →
SECURITY AGREEMENT Recorded Jun 23, 2011
From: PARALLELS HOLDINGS LTD. (F/K/A SWSOFT HOLDINGS LTD.)
To: SILICON VALLEY BANK
Reel/Frame 026480/0957 →
SECURITY AGREEMENT Recorded Apr 3, 2010
From: PARALLELS HOLDINGS, LTD.
To: SILICON VALLEY BANK
Reel/Frame 024170/0853 →
SECURITY AGREEMENT Recorded Nov 26, 2007
From: PARALLELS SOFTWARE INTERNATIONAL, INC.
To: SILICON VALLEY BANK
Reel/Frame 020154/0915 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 8, 2006
From: KORYAKIN, ALEXEY B.; KUZKIN, MAXIM A.; DOBROVOLSKIY, NIKOLAY N.; OMELYANCHUK, ANDREY A.; TORMASOV, ALEXANDER G.; BELOUSSOV, SERGUEI M.; PROTASSOV, STANISLAV S.
To: PARALLELS SOFTWARE INTERNATIONAL, INC.
Reel/Frame 018219/0733 →