IP Library Granted Patent US 10,579,792
Granted Patent B2
US 10,579,792 · App. 15/169,248 · Granted Mar 3, 2020

Extracting malicious instructions on a virtual machine

Inventors: Jeffery Ray Schilling (Murphy, TX); Chase Cooper Cunningham (Frisco, TX); Tawfiq Mohan Shah (Argyle, TX); Srujan Das Kotikela (Dallas, TX)
Assignee: Armor Defense Inc.
G06F21/53G06F9/45545G06F9/45558G06F12/1009G06F16/245G06F16/285G06F21/54G06F21/552G06F21/56G06F21/561G06F21/565G06F21/566H04L63/0227H04L63/1408H04L63/1416H04L63/1425G06F21/567G06F2009/45579G06F2009/45583G06F2009/45587G06F2009/45591G06F2009/45595G06F2212/1052G06F2212/152G06F2212/154G06F2221/034G06F2221/2149
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,579,792
App. No.
15/169,248
Granted
Mar 3, 2020
Kind
B2
Abstract

A system including a hypervisor and a guest virtual machine. The hypervisor is configured to communicate a measurement request that identifies virtual machine operating characteristics metadata, to receive packets comprising virtual machine operating characteristics, and to communicate packets comprising virtual machine operating characteristics to a virtual vault machine for processing. The guest virtual includes one or more virtual machine measurement points and a hypervisor control point. The hypervisor control point is configured to receive the measurement request, to determine one or more of the one or more virtual machine measurement points to collect the virtual machine operating characteristics metadata, and to receive virtual machine operating characteristics metadata from the determined one or more virtual machine measurement points. The hypervisor control points is further configured to generate a packet that comprises at least a portion of the virtual machine operating characteristics metadata and to communicate the packet to the hypervisor.

Claims (17)

1. A system comprising: a hypervisor configured to: communicate a measurement request that identifies virtual machine operating characteristics metadata; receive packets comprising virtual machine operating characteristics; and communicate packets comprising virtual machine operating characteristics to a virtual vault machine for processing; and a guest virtual machine in communication with the hypervisor, the guest virtual machine comprising: one or more virtual machine measurement points implemented by a processor; and a hypervisor control point implemented by the processor, and configured to: receive the measurement request; determine one or more of the one or more virtual machine measurement points to collect the virtual machine operating characteristics metadata; receive virtual machine operating characteristics metadata from the determined one or more virtual machine measurement points; generate a packet that comprises at least a portion of the virtual machine operating characteristics metadata; and communicate the packet to the hypervisor; wherein the hypervisor control point operates solely in a kernel space of the guest virtual machine, and wherein the processor configured to implement the hypervisor control point is isolated from one or more other processors available to the guest virtual machine; wherein the virtual machine operating characteristics metadata comprises at least one of the following operating characteristics of the guest virtual machine: stream processing unit usage, central processing unit usage, a memory map, and network usage; and wherein the virtual machine measurement points are software instructions implemented by a processor to at least monitor the guest virtual machine.

2. The system of claim 1 , wherein the virtual machine measurement points are configured to collect the virtual machine operating characteristics metadata from a kernel space of the guest virtual machine.

3. The system of claim 1 , wherein the virtual machine measurement points are configured to collect the virtual machine operating characteristics metadata from a user space of the guest virtual machine.

4. The system of claim 1 , wherein: generating the packet comprises inserting the at least a portion of the virtual machine operating characteristics metadata as a payload of the packet; and the packet does not comprise a destination address.

5. The system of claim 1 , wherein the packet is sent to the hypervisor via a tunnel connection comprising one or more virtual switches.

6. The system of claim 1 , wherein the virtual machine measurement points operate in a kernel space of the guest virtual machine.

7. A virtual machine intrusion detection method comprising: receiving, at a hypervisor control point implemented by a processor, a measurement request identifying virtual machine operating characteristics metadata from a hypervisor associated with a guest virtual machine, wherein the guest virtual machine comprises the hypervisor control point, wherein the hypervisor control point operates solely in a kernel space of the guest virtual machine, and wherein the processor configured to implement the hypervisor control point is isolated from one or more other processors available to the guest virtual machine; determining, by the hypervisor control point, one or more virtual machine measurement points implemented by the processor to collect the virtual machine operating characteristics metadata; receiving, by the hypervisor control point, virtual machine operating characteristics metadata from the virtual machine measurement points; generating, by the hypervisor control point, a packet that comprises at least a portion of the virtual machine operating characteristics metadata; communicating, by the hypervisor control point, the packet to the hypervisor; wherein the virtual machine operating characteristics metadata comprises at least one of the following operating characteristics of the guest virtual machine: stream processing unit usage, central processing unit usage, a memory map, and network usage; and wherein the virtual machine measurement points are software instructions implemented by a processor to at least monitor the guest virtual machine.

8. The method of claim 7 , wherein selecting the one or more virtual machine measurement points triggers the selected virtual machine measurement points to collect the virtual machine operating characteristics metadata from a kernel space of the guest virtual machine.

9. The method of claim 7 , wherein selecting the one or more virtual machine measurement points triggers the selected virtual machine measurement points to collect the virtual machine operating characteristics metadata from a user space of the guest virtual machine.

10. The method of claim 7 , wherein: generating the packet comprises inserting the at least a portion of the virtual machine operating characteristics metadata as a payload of the packet; and the packet does not comprise a destination address.

11. The method of claim 7 , wherein the packet is sent to the hypervisor via a tunnel connection comprising one or more virtual switches.

12. The method of claim 7 , wherein the virtual machine measurement points operate in a kernel space of the guest virtual machine.

13. An apparatus comprising: virtual machine measurement points implemented by a processor; and a hypervisor control point implemented by the processor, and configured to: receive a measurement request that identifies virtual machine operating characteristics metadata associated with a guest virtual machine, wherein the guest virtual machine comprises the hypervisor control point, wherein the hypervisor control point operates solely in a kernel space of the guest virtual machine, and wherein the processor configured to implement the hypervisor control point is isolated from one or more other processors available to the guest virtual machine; determine one or more of the virtual machine measurement points to collect the virtual machine operating characteristics metadata; receive virtual machine operating characteristics metadata from the selected virtual machine measurement points; generate a packet that comprises at least a portion of the virtual machine operating characteristics metadata; communicate the packet to a hypervisor; and wherein the virtual machine operating characteristics metadata comprises at least one of the following operating characteristics of the guest virtual machine: stream processing unit usage, central processing unit usage, a memory map, and network usage.

14. The apparatus of claim 13 , wherein the virtual machine measurement points are configured to collect the virtual machine operating characteristics metadata from at least one of a kernel space of the guest virtual machine and a user space of the guest virtual machine.

15. The apparatus of claim 13 , wherein: generating the packet comprises inserting the at least a portion of the virtual machine operating characteristics metadata as a payload of the packet; and the packet does not comprise a destination address.

16. The apparatus of claim 13 , wherein the packet is sent to the hypervisor via a tunnel connection comprising one or more virtual switches.

17. The apparatus of claim 13 , wherein the virtual machine measurement points operates in a kernel space of the guest virtual machine.

Assignments (6)
RELEASE OF SECURITY INTEREST Recorded Apr 6, 2026
From: ESCALATE CAPITAL IV, LP
To: ARMOR DEFENSE INC.; ARMOR DEFENSE LIMITED
Reel/Frame 074284/0469 →
RELEASE OF SECURITY INTEREST Recorded Apr 6, 2026
From: SILICON VALLEY BANK
To: ARMOR DEFENSE LIMITED; ARMOR DEFENSE INC.
Reel/Frame 074284/0476 →
SECURITY INTEREST Recorded Oct 1, 2024
From: ARMOR DEFENSE INC.
To: SUNFLOWER BANK , N.A.
Reel/Frame 068758/0972 →
SECURITY INTEREST Recorded Dec 23, 2020
From: ARMOR DEFENSE INC.; ARMOR DEFENSE LIMITED
To: ESCALATE CAPITAL IV, LP
Reel/Frame 054741/0749 →
SECURITY INTEREST Recorded Oct 16, 2019
From: ARMOR DEFENSE, INC.
To: SILICON VALLEY BANK
Reel/Frame 050730/0113 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 31, 2016
From: SCHILLING, JEFFERY RAY; CUNNINGHAM, CHASE COOPER; SHAH, TAWFIQ MOHAN; KOTIKELA, SRUJAN DAS
To: ARMOR DEFENSE INC.
Reel/Frame 038753/0622 →
Continuity (2)
Provisional Application 62258730 · Nov 23, 2015
Related Publication 20170147816A1 · May 25, 2017