IP Library Granted Patent US 9,430,647
Granted Patent B2
US 9,430,647 · App. 13/840,051 · Granted Aug 30, 2016

Peer-aware self-regulation for virtualized environments

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,430,647
App. No.
13/840,051
Granted
Aug 30, 2016
Kind
B2
Abstract

Technologies for self-regulation for virtualized environments may include, by a virtual machine on an electronic device, detecting an attempted anti-malware operation by a monitored module, determining anti-malware operation levels of one or more other virtual machines on the electronic device, and, based on the attempted anti-malware operation and upon the anti-malware operation levels, determining whether to allow the attempted operation.

Claims (88)

1. A method for self-regulation of a virtualized environment, comprising:

by a first virtual machine on an electronic device:

detecting a first attempted anti-malware operation by a first monitored module; and

first anti-malware operation levels of one or more other virtual machines on the electronic device;

by a second virtual machine on the electronic device:

detecting a second attempted anti-malware operation by a second monitored module;

determining second anti-malware operation levels of one or more other virtual machines on the electronic device;

based on the second attempted anti-malware operation and upon the second anti-malware operation levels, determining whether to allow the second attempted anti-malware operation; and

broadcasting a second indication of whether the second attempted anti-malware operation was performed to the other virtual machines on the electronic device; and

by the first virtual machine on the electronic device:

based on the first attempted anti-malware operation, the first anti-malware operation levels, and whether the second indication was received, determining whether to allow the first attempted anti-malware operation; and

broadcasting a first indication to the other virtual machines, the first indication to indicate whether the first attempted anti-malware operation was performed.

2. The method of claim 1 , wherein the first attempted anti-malware operation includes an anti-malware scan.

3. The method of claim 1 , wherein:

the first attempted anti-malware operation includes an installation of anti-malware information; and

the method further comprises determining whether to allow the first attempted anti-malware operation further based upon whether installation of anti-malware information is occurring in the one or more other virtual machines on the electronic device.

4. The method of claim 1 , wherein:

the first attempted anti-malware operation includes generating one or more execution threads; and

the first anti-malware operation levels of one or more other virtual machines on the electronic device include a quantification of one or more threads associated with anti-malware operations.

5. The method of claim 1 , wherein the first anti-malware operation levels of one or more other virtual machines on the electronic device include a quantification of resources used by one or more other anti-malware operations.

6. The method of claim 1 , wherein:

the first attempted anti-malware operation includes one mode of a plurality of modes of anti-malware scanning; and

the first anti-malware operation levels of one or more other virtual machines on the electronic device include a quantification of the mode of anti-malware scanning.

7. The method of claim 1 , wherein determining first anti-malware operation levels of one or more other virtual machines on the electronic device includes sending a message to a subnetwork communicatively coupled to the first virtual machine.

8. The method of claim 1 , further comprising, by the second virtual machine:

receiving the first indication;

evaluating whether the first indication applies to the operation of the second attempted anti-malware operation; and

based upon a determination that the first indication does not apply to the operation of the second attempted anti-malware operation, discarding the first indication.

9. A system for self-regulation of virtualized environments, comprising:

a virtualization module configured to virtualize access to one or more resources of an electronic device for one or more virtual machines;

a processor coupled to a computer readable medium;

a first monitor module comprising computer-executable instructions carried on the computer readable medium, the instructions readable by the processor, the instructions, when read and executed, for configuring the first monitor module to:

by a first virtual machine on the electronic device, detect a first attempted anti-malware operation by a first monitored module, the first virtual machine configured to access one or more virtualized resources provided by the virtualization module;

by the first virtual machine on the electronic device, determine first anti-malware operation levels of one or more other virtual machines on the electronic device; and

based on the first attempted anti-malware operation and upon the first anti-malware operation levels, determine whether to allow the first attempted anti-malware operation; and

a second monitor module comprising computer-executable instructions carried on the computer readable medium, the instructions readable by the processor, the instructions, when read and executed, for configuring the second monitor module to:

by a second virtual machine on the electronic device, detect a second attempted anti-malware operation by a second monitored module, the second virtual machine configured to access one or more virtualized resources provided by the virtualization module;

by the second virtual machine on the electronic device, determine second anti-malware operation levels of one or more other virtual machines on the electronic device; and

based on the second attempted anti-malware operation and upon the second anti-malware operation levels, determine whether to allow the second attempted anti-malware operation;

wherein:

the second monitor module is further configured to broadcast a second indication of whether the second attempted anti-malware operation was performed to the other virtual machines on the electronic device; and

the first monitor module is further configured to:

broadcast a first indication to the other virtual machines, the first indication to indicate whether the first attempted anti-malware operation was performed; and

determine whether to allow the first attempted anti-malware operation further based upon whether the second indication was received.

10. The system of claim 9 , wherein the first attempted anti-malware operation includes an anti-malware scan.

11. The system of claim 9 , wherein:

the first attempted anti-malware operation includes an installation of anti-malware information; and

the first monitor module is further configured to determine whether to allow the first attempted anti-malware operation further based upon whether installation of anti-malware information is occurring in the one or more other virtual machines on the electronic device.

12. The system of claim 9 , wherein:

the first attempted anti-malware operation includes generating one or more execution threads; and

the first anti-malware operation levels of one or more other virtual machines on the electronic device include a quantification of one or more threads associated with anti-malware operations.

13. The system of claim 9 , wherein the first anti-malware operation levels of one or more other virtual machines on the electronic device include a quantification of resources used by one or more other anti-malware operations.

14. The system of claim 9 , wherein:

the first attempted anti-malware operation includes one mode of a plurality of modes of anti-malware scanning; and

the first anti-malware operation levels of one or more other virtual machines on the electronic device include a quantification of the mode of anti-malware scanning.

15. The system of claim 9 , wherein determining first anti-malware operation levels of one or more other virtual machines on the electronic device includes sending a message to a subnetwork communicatively coupled to the first virtual machine.

16. The system of claim 9 , wherein the second monitor module is further configured to:

receive the first indication from the first monitor module;

evaluate whether the first indication applies to the operation of the second attempted anti-malware operation; and

based upon a determination that the first indication does not apply to the operation of the second attempted anti-malware operation, discard the first indication.

17. At least one machine readable non-transitory storage medium, comprising computer-executable instructions carried on the machine readable non-transitory storage medium, the instructions readable by a processor, the instructions, when read and executed, for causing the processor to:

by a first virtual machine on an electronic device:

detect a first attempted anti-malware operation by a first monitored module; and

determine first anti-malware operation levels of one or more other virtual machines on the electronic device;

by a second virtual machine on the electronic device:

detect a second attempted anti-malware operation by a second monitored module;

determine second anti-malware operation levels of one or more other virtual machines on the electronic device;

based on the second attempted anti-malware operation and upon the second anti-malware operation levels, determine whether to allow the second attempted anti-malware operation; and

broadcast a second indication of whether the second attempted anti-malware operation was performed to the other virtual machines on the electronic device; and

by the first virtual machine:

based on the first attempted anti-malware operation, the first anti-malware operation levels, and whether the second indication was received, determine whether to allow the first attempted anti-malware operation; and

broadcast a first indication to the other virtual machines, the first indication to indicate whether the first attempted anti-malware operation was performed.

18. The medium of claim 17 , wherein the first attempted anti-malware operation includes an anti-malware scan.

19. The medium of claim 17 , wherein:

the first attempted anti-malware operation includes an installation of anti-malware information; and

the medium further comprises instructions for causing the processor to determine whether to allow the first attempted anti-malware operation further based upon whether installation of anti-malware information is occurring in the one or more other virtual machines on the electronic device.

20. The medium of claim 17 , wherein:

the first attempted anti-malware operation includes generating one or more execution threads; and

the first anti-malware operation levels of one or more other virtual machines on the electronic device include a quantification of one or more threads associated with anti-malware operations.

21. The medium of claim 17 , wherein the first anti-malware operation levels of one or more other virtual machines on the electronic device include a quantification of resources used by one or more other anti-malware operations.

22. The medium of claim 17 , wherein:

the first attempted anti-malware operation includes one mode of a plurality of modes of anti-malware scanning; and

the first anti-malware operation levels of one or more other virtual machines on the electronic device include a quantification of the mode of anti-malware scanning.

23. The medium of claim 17 , wherein determining first anti-malware operation levels of one or more other virtual machines on the electronic device includes sending a message to a subnetwork communicatively coupled to the first virtual machine.

24. The medium of claim 17 , further comprising instructions for causing the processor to, by the second virtual machine:

receive the first indication;

evaluate whether the first indication applies to the operation of the second attempted anti-malware operation; and

based upon a determination that the first indication does not apply to the operation of the second attempted anti-malware operation, discard the first indication.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 23, 2013
From: GALLELLA, RON; DODGE, JOSEPH; ROBBINS, VIRGINIA; SHERWOOD, BEN; SPEAR, PAUL R.
To: MCAFEE, INC.
Reel/Frame 031458/0256 →