IP Library › Granted Patent US 12,647,454
Granted Patent B2
US 12,647,454 · App. 17/900,128 · Granted Jun 2, 2026

Timeout handling for virtual devices

Inventor: Michael Tsirkin (Raanana, IL)
Assignee: Red Hat, LLC
H04L63/1458G06F9/45558G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,647,454
App. No.
17/900,128
Granted
Jun 2, 2026
Kind
B2
Abstract

A virtual device can be provided to a virtual machine from a hypervisor. The virtual can correspond to a backend element accessible to the VM via communications with the virtual device. The hypervisor can intercept a communication from the VM directed to the backend element via the virtual device. The hypervisor can set a timer. The timer can track an elapsed time from the communication to a response from the backend element. The hypervisor can send the communication from the virtual machine to the backend element. The timer can then be determined to have expired without a response being received. The virtual device can then be disabled.

Claims (56)

1 . A method comprising:

generating, by a hypervisor executing on a computing device comprising a processor device, a virtual machine (VM) that provides to a user access to computational resources of the computing device;

providing, to the VM from the hypervisor, a virtual device, the virtual device corresponding to a backend element accessible to the VM via communications with the virtual device, wherein the hypervisor is configured to intercept communications with the virtual device by the VM;

intercepting, by the hypervisor, a communication from the VM directed to the backend element via the virtual device, determining a period of time to receive a response from the backend element based at least in part on historical processing data of the computing device;

setting, by the hypervisor, a timer to the period of time to receive the response from the backend element;

sending, by the hypervisor to the backend element, the communication from the VM;

determining that the timer has expired and that the backend element has not responded to the communication;

in response to determining that the timer has expired and that the backend element has not responded to the communication, disabling, by the hypervisor and without coordination with a guest operating system of the VM, the virtual device from accessing the backend element, wherein disabling the virtual device comprises an emulated hard removal of the virtual device, wherein the emulated hard removal comprises ignoring future write and read requests from the virtual device: and reporting ignored write and read requests by setting flags in a PCI controller;

intercepting, by the hypervisor, a second communication from the virtual device directed to the backend element; and

preventing, by the hypervisor, transmission of the second communication based on the virtual device being disabled from accessing the backend element.

2 . The method of claim 1 , wherein disabling the virtual device from accessing the backend element comprises unmapping the virtual device from the VM.

3 . The method of claim 1 , further comprising:

in response to determining that the timer has expired and that the backend element has not responded to the communication, generating a notification, wherein the notification is descriptive of the virtual device being disabled; and

providing the notification for display via a user interface.

4 . The method of claim 1 , wherein disabling the virtual device from accessing the backend element comprises invalidating one or more table page entries of the computing device, wherein the one or more table page entries are associated with the virtual device.

5 . The method of claim 1 , wherein disabling the virtual device from accessing the backend element comprises blocking virtual device access to a memory of the computing device.

6 . The method of claim 1 , further comprising:

generating, via the hypervisor, a plurality of virtual machines, wherein each of the plurality of virtual machines are allocated a portion of computing resources of the computing device, and wherein each of the plurality of virtual machines operate in isolation from other virtual machines of the plurality of virtual machines.

7 . The method of claim 6 , further comprising:

providing, via the hypervisor, the VM in parallel with other virtual machines of the plurality of virtual machines.

8 . The method of claim 1 , wherein the backend element comprises a networking device to:

obtain backend data, wherein the backend data is descriptive of information for interacting with backend resources.

9 . The method of claim 1 , wherein the backend element comprises an operating device to:

adjust operating system data, wherein the operating system data comprises information for providing the guest operating system of the VM.

10 . The method of claim 1 , wherein determining that the timer has expired comprises: determining an elapsed time of the timer is above a threshold time.

11 . The method of claim 1 , further comprising:

providing a notification to the guest operating system of the VM, wherein the notification is descriptive of a removal of the virtual device without coordination with the guest operating system.

12 . The method of claim 1 , wherein the virtual device comprises a virtual storage device, and wherein the backend element comprises a storage device.

13 . The method of claim 1 , wherein the hypervisor is communicatively connected with the VM, wherein the hypervisor is communicatively connected with hardware of the computing device, and wherein the hypervisor facilitates usage of the hardware of the computing device by the VM.

14 . The method of claim 1 , wherein the virtual device comprises a virtual network interface, and wherein the backend element comprises a network interface.

15 . A computing system comprising: a memory; and a processor device coupled to the memory to:

generate, by a hypervisor executing on a computing device comprising a processor device, a virtual machine (VM) that provides to a user access to computational resources of the computing device;

provide, to the VM from the hypervisor, a virtual device, the virtual device corresponding to a backend element accessible to the VM via communications with the virtual device, wherein the hypervisor is configured to intercept communications with the virtual device by the VM;

intercept, by the hypervisor, a communication from the VM directed to the backend element via the virtual device;

determine a period of time to receive a response from the backend element based at least in part on historical processing data of the computing device;

set, by the hypervisor, a timer to the period of time to receive the response from the backend element;

send, by the hypervisor to the backend element, the communication from the VM; determine that the timer has expired and that the backend element has not responded to the communication;

in response to determining that the timer has expired and that the backend element has not responded to the communication, disable, by the hypervisor and without coordination with a guest operating system of the VM, the virtual device from accessing the backend element, wherein disabling the virtual device comprises an emulated hard removal of the virtual device, wherein the emulated hard removal comprises ignoring future write and read requests from the virtual device; and report ignored write and read requests by setting flags in a PCI controller;

intercept, by the hypervisor, a second communication from the virtual device directed to the backend element; and

prevent, by the hypervisor, transmission of the second communication based on the virtual device being disabled from accessing the backend element.

16 . The computing system of claim 15 , wherein to set the timer, the processor device is further to:

access, via the hypervisor, an internal clock of the computing device; and tracking, via the hypervisor, an elapsed time.

17 . The computing system of claim 15 , wherein the processor device is further to:

provide, via the VM, a user interface of the guest operating system of the VM; and wherein the backend element is associated with a host operating system.

18 . A non-transitory computer-readable storage medium that includes executable instructions to cause one or more processor devices of one or more computing devices to:

generate, by a hypervisor, a plurality of virtual machines, wherein each of the plurality of virtual machines are associated with a respective portion of computational resources of a computing device;

provide a particular virtual machine of the plurality of virtual machines to a user, wherein the particular virtual machine comprises a guest operating system;

receive a backend request from a virtual device to receive configuration access to the particular virtual machine, wherein the configuration access is associated with accessing computational resources of the computing device to provide the virtual device to the particular virtual machine, wherein the virtual device is communicatively paired with the hypervisor;

transmit, by the hypervisor via the virtual device, a data query received from the particular virtual machine, to a backend driver;

determine a threshold time to receive a response from the backend driver based at least in part on historical processing data of the computing device; determine the threshold time has elapsed without the response from the backend driver;

in response to determining that the threshold time has elapsed without the response from the backend driver, provide a simulated hard removal of the virtual device, wherein the simulated hard removal of the virtual device comprises blocking resource access privileges for the virtual device, wherein the simulated hard removal of the virtual device comprises disabling, by the hypervisor and without coordination with the guest operating system, the virtual device from accessing the backend driver, wherein disabling the virtual device comprises ignoring future write and read requests from the virtual device; and reporting ignored write and read requests by setting flags in a PCI controller;

intercept, by the hypervisor, a second communication from the virtual device directed to the backend element; and

prevent, by the hypervisor, transmission of the second communication based on the virtual device being disabled from accessing the backend driver.

19 . The non-transitory computer-readable medium of claim 18 , wherein the simulated hard removal comprises:

blocking resource access privileges for the virtual device; and

providing a notification via the particular virtual machine, wherein the notification is descriptive of the virtual device being removed.

Assignments (2)
MERGER AND CHANGE OF NAME Recorded May 1, 2026
From: RED HAT, INC.; RED HAT, LLC
To: RED HAT, LLC
Reel/Frame 075352/0548 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 31, 2022
From: TSIRKIN, MICHAEL
To: RED HAT, INC.
Reel/Frame 060954/0013 →
Continuity (1)
Related Publication 20240073243A1 · Feb 29, 2024
References Cited (13)
US 8291414B2 · Bansal · 2012 [cited by examiner]
US 20130297802A1 · Laribi · 2013 [cited by examiner]
US 20170046187A1 · Tsirkin · 2017 [cited by examiner]
US 20190087215A1 · Bhandari · 2019 [cited by examiner]
US 20200341785A1 · Tsirkin · 2020 [cited by examiner]
US 20210208918A1 · Singleton et al. · 2021 [cited by applicant]
He, Zecheng et al., “Machine Learning Based DDoS Attack Detection from Source Side in Cloud,” 2017 IEEE 4th International Conference on Cyber Security and Cloud Computing, https://www.researchgate.net/publication/318666… [cited by applicant]
Khanh, Tran Nam et al., “Attempt TCP ACK-Storm based Virtual Network Attacks and Defence Solutions,” https://assets.researchsquare.com/files/rs-420162/v1_covered.pdf?c=1641510704 (preprint), Jan. 6, 2022, 12 pages. [cited by applicant]
Krishna, E. S. Phalguna et al., “Managing DDoS Attacks on Virtual Machines by Segregated Policy Management,” Global Journal of Computer Science and Technology: Network, Web & Security, vol. 1, Issue 6, Version 1.0, Glob… [cited by applicant]
Nguyen, Son Doc et al., “SVTester: Finding DoS Vulnerabilities of Virtual Switches,” Journal of Information Processing, vol. 29, 581-591, DOI: 10.2197/ipsjip.29.581, https://www.jstage.jst.go.jp/article/ipsjip/29/0/29_5… [cited by applicant]
Ruo, Ando et al., “A Load Balancing System for Mitigating DDoS Attacks Using Live Migration of Virtual Machines,” https://www.researchgate.net/publication/294785868, Jun. 2008, 7 pages. [cited by applicant]
Salahuddin, Mohammad A. et al., “Chronos: DDoS Attack Detection using Time-based Autoencoder,” IEEE Transactions on Network and Service Management, DOI: 10.1109/TNSM.2021.3088326, https://www.researchgate.net/publicatio… [cited by applicant]
Zhijun, Wu et al., “Low-Rate DDoS Attack Detection Based on Factorization Machine in Software Defined Network,” IEEE Access, https://ieeexplore.ieee.org/stamp/stamp.jsp?arnnumber=8962081, Jan. 17, 2020, 15 pages. [cited by applicant]