VIRTUAL MACHINE CONFIGURATION SHARING BETWEEN HOST AND VIRTUAL MACHINES AND BETWEEN VIRTUAL MACHINES
In embodiments of the present invention improved capabilities are described for presenting a physical computing machine including a virtual computer machine monitor and a one or more of virtual computing machines, where each of the virtual computing machines runs its own operating system, presenting one of the multiple virtual computing machines as a host, and the remaining multiple virtual computing machines as guests, and providing for a virtual machine protected environment, where suspicious file information is shared between the virtual machine protected environment and other virtual machines.
1 . A method comprising:
presenting a physical computing machine including a virtual computer machine monitor and a plurality of virtual computing machines, where each of the plurality of virtual computing machines runs its own operating system;
presenting one of the plurality of virtual computing machines as a host, and the remaining plurality of virtual computing machines as guest virtual computing machines;
providing at least one of the guest virtual computer machines as a protected environment, where the protected environment is used to isolate suspicious files from at least one of the host and other guest virtual computing machines; and
communicating suspicious file information from at least one of the host and guest machines to a protected environment virtual machine for isolation.
2 . The method of claim 1 wherein the virtual machine acts as a sandbox.
3 . The method of claim 2 wherein the sandbox runs an executable code in simulation.
4 . The method of claim 3 wherein after the simulation has terminated, errors are identified.
5 . The method of claim 3 wherein after the simulation has terminated, changes are searched for and analyzed for indications of malware.
6 . The method of claim 1 wherein the protected environment is used for testing.
7 . The method of claim 1 wherein the protected environment is associated with malware detection.
8 . (canceled)
9 . The method of claim 7 wherein the protected environment is launched to scan a file.
10 . The method of claim 7 wherein the malware detection is associated with the examination of files.
11 - 12 . (canceled)
13 . The method of claim 10 wherein examination of files is associated with repairing the file.
14 . The method of claim 10 wherein examination of files is associated with quarantining the file.
15 . (canceled)
16 . The method of claim 7 wherein the malware detection is associated with the identification of suspicious behavior from a computer program.
17 - 18 . (canceled)
19 . The method of claim 1 wherein information is shared between the virtual machine as a protected environment and at least one of the other virtual computing machines including the host, the virtual computer machine monitor, and a guest.
20 - 24 . (canceled)
25 . A system comprising:
a physical computing machine including a virtual computer machine monitor and a plurality of virtual computing machines, where each of the plurality of virtual computing machines runs its own operating system;
one of the plurality of virtual computing machines as a host, and the remaining plurality of virtual computing machines as guest virtual computing machines;
at least one of the guest virtual computer machines as a protected environment, where the protected environment is used to isolate suspicious files from at least one of the host and other guest virtual computing machines; and
suspicious file information communicated from at least one of the host and guest machines to a protected environment virtual machine for isolation.
26 . The system of claim 25 wherein the virtual machine acts as a sandbox.
27 - 30 . (canceled)
31 . The system of claim 25 wherein the protected environment is associated with malware detection.
32 . (canceled)
33 . The system of claim 31 wherein the protected environment is launched to scan a file.
34 . The system of claim 31 wherein the malware detection is associated with the examination of files.
35 - 36 . (canceled)
37 . The system of claim 34 wherein examination of files is associated with repairing the file.
38 . The system of claim 34 wherein examination of files is associated with quarantining the file.
39 . (canceled)
40 . The system of claim 31 wherein the malware detection is associated with the identification of suspicious behavior from a computer program.
41 - 42 . (canceled)
43 . The system of claim 25 wherein information is shared between the virtual machine as a protected environment and at least one of the other virtual computing machines including the host, the virtual computer machine monitor, and a guest.
44 - 48 . (canceled)