IP Library Granted Patent US 8,869,265
Granted Patent B2
US 8,869,265 · App. 13/723,445 · Granted Oct 21, 2014

System and method for enforcing security policies in a virtual environment

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,869,265
App. No.
13/723,445
Granted
Oct 21, 2014
Kind
B2
Abstract

A method in one example implementation includes intercepting a request associated with an execution of an object (e.g., a kernel module or a binary) in a computer configured to operate in a virtual machine environment. The request is associated with a privileged domain of the computer that operates logically below one or more operating systems. The method also includes verifying an authorization of the object by computing a checksum for the object and comparing the checksum to a plurality of stored checksums in a memory element. The execution of the object is denied if it is not authorized. In other embodiments, the method can include evaluating a plurality of entries within the memory element of the computer, wherein the entries include authorized binaries and kernel modules. In other embodiments, the method can include intercepting an attempt from a remote computer to execute code from a previously authorized binary.

Claims (41)

1. A method, comprising:

intercepting, by a security layer, a request for an execution of an object in a computer wherein the request for the execution is from a user space of a privileged domain;

verifying an authorization of the object by linking a particular module into a kernel space associated with the privileged domain, wherein the particular module is configured to compute a checksum for the object, access an inventory of a plurality of stored checksums in a memory element, and compare the checksum to the plurality of stored checksums; and

denying the execution of the object if it is not authorized;

wherein the security layer is in a kernel of a privileged domain of a computer configured to operate in a virtual machine environment, wherein the privileged domain of the computer manages a virtual machine monitor (VMM) and operates at a higher priority than one or more guest operating systems.

2. The method of claim 1 , further comprising:

evaluating a plurality of entries within the memory element of the computer, wherein the entries include authorized binaries and kernel modules.

3. The method of claim 1 , further comprising:

intercepting an attempt from a remote computer to execute code from a previously authorized binary; and

evaluating an origination address of a hypercall associated with the code before executing the code.

4. The method of claim 1 , wherein the object is a kernel module or a binary.

5. The method of claim 1 , wherein the verifying of the authorization of the object includes comparing the object to an inventory of authorized objects stored in a user space of the computer, and wherein a log is created if the execution of the object is not authorized.

6. The method of claim 1 , wherein the object is a kernel module that is interacting with a hypercall, which attempts to access one or more privileged domain areas within the computer.

7. A logic encoded in one or more tangible non-transitory media that includes code for execution and when executed by a processor is operable to perform operations comprising:

intercepting, by a security layer, a request for an execution of an object in a computer wherein the request for the execution is from a user space of a privileged domain;

verifying an authorization of the object by linking a particular module into a kernel space associated with the privileged domain, wherein the particular module is configured to compute a checksum for the object, access an inventory of a plurality of stored checksums in a memory element, and compare the checksum to the plurality of stored checksums; and

denying the execution of the object if it is not authorized;

wherein the security layer is configured to operate in a kernel of a privileged domain of a computer configured to operate in a virtual machine environment, wherein the privileged domain of the computer is configured to manage a virtual machine monitor (VMM) and operate at a higher priority than one or more guest operating systems.

8. The logic of claim 7 , the processor being operable to perform operations comprising:

evaluating a plurality of entries within the memory element of the computer, wherein the entries include authorized binaries and kernel modules.

9. The logic of claim 7 , the processor being operable to perform operations comprising:

intercepting an attempt from a remote computer to execute code from a previously authorized binary; and

evaluating an origination address of a hypercall associated with the code before executing the code.

10. The logic of claim 7 , wherein the object is a kernel module or a binary.

11. The logic of claim 7 , wherein the object is a kernel module that is interacting with a hypercall, which attempts to access one or more privileged domain areas within the computer.

12. The logic of claim 7 , wherein the verifying of the authorization of the object includes comparing the object to an inventory of authorized objects stored in a user space of the computer, and wherein a log is created if the execution of the object is not authorized.

13. An apparatus, comprising:

a virtual machine element;

a memory element configured to store data; and

a processor operable to execute instructions associated with the data, wherein the virtual machine element is configured to:

intercept, by a security layer, a request for an execution of an object in a computer wherein the request for the execution is from a user space of a privileged domain;

verify an authorization of the object by linking a particular module into a kernel space associated with the privileged domain, wherein the particular module is configured to compute a checksum for the object, access an inventory of a plurality of stored checksums in a memory element, and compare the checksum to the plurality of stored checksums; and

deny the execution of the object if it is not authorized;

wherein the security layer is configured to operate in a kernel of a privileged domain of a computer configured to operate in a virtual machine environment, wherein the privileged domain of the computer is configured to manage a virtual machine monitor (VMM) and operate at a higher priority than one or more guest operating systems.

14. The apparatus of claim 13 , wherein the virtual machine element is further configured to:

evaluate a plurality of entries within the memory element of the computer, wherein the entries include authorized binaries and kernel modules.

15. The apparatus of claim 13 , wherein the virtual machine element is further configured to:

intercept an attempt from a remote computer to execute code from a previously authorized binary; and

evaluate an origination address of a hypercall associated with the code before executing the code.

16. The apparatus of claim 13 , wherein the object is a kernel module or a binary.

17. The apparatus of claim 13 , wherein the object is a kernel module that is interacting with a hypercall, which attempts to access one or more privileged domain areas within the computer.

Assignments (9)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →