IP Library Granted Patent US 10,409,983
Granted Patent B2
US 10,409,983 · App. 15/169,230 · Granted Sep 10, 2019

Detecting malicious instructions in a virtual machine memory

Inventors: Jeffrey Ray Schilling (Murphy, TX); Chase Cooper Cunningham (Frisco, TX); Tawfiq Mohan Shah (Argyle, TX); Srujan Das Kotikela (Dallas, TX)
Assignee: Armor Defense, Inc.
G06F21/53G06F9/45545G06F9/45558G06F12/1009G06F16/245G06F16/285G06F21/54G06F21/552G06F21/56G06F21/561G06F21/565G06F21/566H04L63/0227H04L63/1408H04L63/1416H04L63/1425G06F21/567G06F2009/45579G06F2009/45583G06F2009/45587G06F2009/45591G06F2009/45595G06F2212/1052G06F2212/152G06F2212/154G06F2221/034G06F2221/2149
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,409,983
App. No.
15/169,230
Granted
Sep 10, 2019
Kind
B2
Abstract

A system that includes a guest virtual machine is in communication with a hypervisor. The guest virtual machine comprises virtual machine measurement points and a hypervisor control point. The hypervisor control point is configured to collect virtual machine memory metadata from the guest virtual machine and from the hypervisor, and to compare the virtual machine memory metadata to the hypervisor memory metadata. The hypervisor control point is further configured to determine whether the virtual machine memory metadata is the same as the hypervisor memory metadata and to communicate the virtual machine memory metadata to the virtual vault machine in response to determining that the virtual machine memory metadata is the same as the hypervisor memory metadata. The virtual vault machine is in communication with the hypervisor and configured to classify the state of the guest virtual based on the virtual machine memory metadata.

Claims (51)

1. A system comprising:

a hypervisor associated with a guest virtual machine;

the guest virtual machine in communication with the hypervisor, and comprising:

virtual machine measurement points implemented by a processor; and

a hypervisor control point implemented by the processor, and configured to:

collect virtual machine memory metadata from the guest virtual machine using a first virtual machine measurement point;

collect hypervisor memory metadata that corresponds with the virtual machine memory metadata from the hypervisor using a second virtual machine measurement point;

compare the virtual machine memory metadata to the hypervisor memory metadata;

determine whether the virtual machine memory metadata is the same as the hypervisor memory metadata; and

communicate the virtual machine memory metadata to a virtual vault machine in response to determining that the virtual machine memory metadata is the same as the hypervisor memory metadata; and

the virtual vault machine in communication with the hypervisor, and configured to classify the state of the guest virtual based on the virtual machine memory metadata;

wherein the virtual machine memory metadata comprises data from one or more memory locations in the guest virtual machine; and

wherein the hypervisor memory metadata comprises data from one or more memory locations in the hypervisor.

2. The system of claim 1 , wherein the virtual machine memory metadata comprises a page table.

3. The system of claim 2 , wherein the page table maps virtual memory of the guest virtual machine to physical memory of the guest virtual machine.

4. The system of claim 1 , wherein the virtual machine memory metadata comprises a memory page from a guest page table executing on the guest virtual machine.

5. The system of claim 1 , wherein the virtual machine memory metadata comprises information about currently executing memory pages on the guest virtual machine.

6. The system of claim 1 , wherein the hypervisor control point is configured to trigger an alarm in response to determining that the virtual machine memory metadata and the hypervisor memory metadata are different.

7. A virtual machine intrusion detection method comprising:

collecting, by a hypervisor control point implemented by a processor, virtual machine memory metadata from a guest virtual machine using a first virtual machine measurement point from a plurality of virtual machine measurement points implemented by the processor;

collecting, by the hypervisor control point, hypervisor memory metadata that corresponds with the virtual machine memory metadata from a hypervisor associated with the guest virtual machine using a second virtual machine measurement point from the plurality of virtual machine measurement points;

comparing, by the hypervisor control point, the virtual machine memory metadata to the hypervisor memory metadata;

determining, by the hypervisor control point, whether the virtual machine memory metadata is the same as the hypervisor memory metadata;

communicating, by the hypervisor control point, the virtual machine memory metadata to a virtual vault machine in response to determining that the virtual machine memory metadata is the same as the hypervisor memory metadata; and

wherein the virtual machine memory metadata comprises data from one or more memory locations in the guest virtual machine; and

wherein the hypervisor memory metadata comprises data from one or more memory locations in the hypervisor.

8. The method of claim 7 , wherein the virtual machine memory metadata comprises a page table.

9. The method of claim 8 , wherein the page table maps virtual memory of the guest virtual machine to physical memory of the guest virtual machine.

10. The method of claim 7 , wherein the virtual machine memory metadata comprises a memory page from a guest page table executing on the guest virtual machine.

11. The method of claim 7 , wherein the virtual machine memory metadata comprises information about currently executing memory pages on the guest virtual machine.

12. The method of claim 7 , wherein:

the virtual machine memory metadata is collected from a random access memory of the guest virtual machine; and

the hypervisor memory metadata is collected from a random access memory of the hypervisor.

13. The method of claim 7 , wherein the hypervisor control point is configured to trigger an alarm in response to determining that the virtual machine memory metadata and the hypervisor memory metadata are different.

14. An apparatus comprising:

virtual machine measurement points implemented by a processor; and

a hypervisor control point implemented by the processor, and configured:

collect virtual machine memory metadata from a guest virtual machine using a first virtual machine measurement point;

collect hypervisor memory metadata that corresponds with the virtual machine memory metadata from a hypervisor associated with the guest virtual machine using a second virtual machine measurement point;

compare the virtual machine memory metadata to the hypervisor memory metadata;

determine whether the virtual machine memory metadata is the same as the hypervisor memory metadata;

communicate the virtual machine memory metadata to a virtual vault machine in response to determining that the virtual machine memory metadata is the same as the hypervisor memory metadata; and

wherein the virtual machine memory metadata comprises data from one or more memory locations in the guest virtual machine; and

wherein the hypervisor memory metadata comprises data from one or more memory locations in the hypervisor.

15. The apparatus of claim 14 , wherein the virtual memory metadata comprises a page table that maps virtual memory of the guest virtual machine to physical memory of the guest virtual machine.

16. The apparatus of claim 14 , wherein the virtual machine memory metadata comprises a memory page from a guest page table executing on the guest virtual machine.

17. The apparatus of claim 14 , wherein the virtual machine memory metadata comprises information about currently executing memory pages on the guest virtual machine.

18. The apparatus of claim 14 , wherein:

the virtual machine memory metadata is collected from a random access memory of the guest virtual machine; and

the hypervisor memory metadata is collected from a random access memory of the hypervisor.

19. The apparatus of claim 14 , wherein the hypervisor control point is configured to trigger an alarm in response to determining that the virtual machine memory metadata and the hypervisor memory metadata are different.

Assignments (6)
RELEASE OF SECURITY INTEREST Recorded Apr 6, 2026
From: ESCALATE CAPITAL IV, LP
To: ARMOR DEFENSE INC.; ARMOR DEFENSE LIMITED
Reel/Frame 074284/0469 →
RELEASE OF SECURITY INTEREST Recorded Apr 6, 2026
From: SILICON VALLEY BANK
To: ARMOR DEFENSE LIMITED; ARMOR DEFENSE INC.
Reel/Frame 074284/0476 →
SECURITY INTEREST Recorded Oct 1, 2024
From: ARMOR DEFENSE INC.
To: SUNFLOWER BANK , N.A.
Reel/Frame 068758/0972 →
SECURITY INTEREST Recorded Dec 23, 2020
From: ARMOR DEFENSE INC.; ARMOR DEFENSE LIMITED
To: ESCALATE CAPITAL IV, LP
Reel/Frame 054741/0749 →
SECURITY INTEREST Recorded Oct 16, 2019
From: ARMOR DEFENSE, INC.
To: SILICON VALLEY BANK
Reel/Frame 050730/0113 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 31, 2016
From: SCHILLING, JEFFERY RAY; CUNNINGHAM, CHASE COOPER; SHAH, TAWFIQ MOHAN; KOTIKELA, SRUJAN DAS
To: ARMOR DEFENSE INC.
Reel/Frame 038753/0584 →
Continuity (2)
Provisional Application 62258730 · Nov 23, 2015
Related Publication 20170149801A1 · May 25, 2017