Device virtualization security layer
Abstract
A processing system of a device having at least one processor may obtain a set of codes from a virtual machine orchestrator via a virtualization security controller of the processing system, obtain a first virtual machine configuration file from the virtual machine orchestrator via a hypervisor of the processing system, and pass at least one code of the set of codes from the virtualization security controller to the hypervisor. The processing system may then apply, via the hypervisor, a decryption to the first virtual machine configuration file using the at least one code, determine that a threshold percentage of content of the first virtual machine configuration file comprises dictionary-recognizable words in accordance with the decryption, and instantiate, via the hypervisor, a first virtual machine in accordance with the first virtual machine configuration file when it is determined that the threshold percentage of the content comprises dictionary-recognizable words.
Claims
exact text as granted — not AI-modifiedWhat is claimed is:
1 . A method comprising:
obtaining, by a processing system of a device including at least one processor, an indication of available memory resources of the device, wherein the indication of available memory resources is obtained via a virtualization security controller of the processing system from a hypervisor of the processing system; writing, by the processing system, via the virtualization security controller, a set of data to at least a portion of the available memory resources of the device; determining, by the processing system via the virtualization security controller, that a memory conflict exists in response to the writing; generating, by the processing system via the virtualization security controller, an alert of a possible unauthorized memory usage in response to determining the memory conflict.
2 . The method of claim 1 , wherein the virtualization security controller operates in a logical layer of the device that is between a hardware layer of the device and the hypervisor.
3 . The method of claim 1 , wherein the indication of available memory resources of the device includes information regarding memory allocations of one or more virtual machines that are installed on the device and that are managed via the hypervisor.
4 . The method of claim 3 , wherein the indication of available memory resources of the device further includes memory allocations of one or more authorized processes that are operating in accordance with a host operating system of the device.
5 . The method of claim 1 , wherein the memory conflict is determined by a failure of the writing of the set of data.
6 . The method of claim 1 , wherein the memory conflict is determined by inspecting the at least the portion of the available memory resources of the device, after the writing, and detecting that the set of data is changed.
7 . The method of claim 1 , further comprising:
identifying a virtual machine that is operating on at least the portion of the available memory.
8 . The method of claim 7 , further comprising:
terminating the virtual machine that is identified.
9 . A non-transitory computer-readable medium storing instructions which, when executed by a processing system of a device including at least one processor, cause the processor to perform operations comprising:
obtaining an indication of available memory resources of the device, wherein the indication of available memory resources is obtained via a virtualization security controller of the processing system from a hypervisor of the processing system; writing via the virtualization security controller, a set of data to at least a portion of the available memory resources of the device; determining, via the virtualization security controller, that a memory conflict exists in response to the writing; generating, via the virtualization security controller, an alert of a possible unauthorized memory usage in response to determining the memory conflict.
10 . The non-transitory computer-readable medium of claim 9 , wherein the virtualization security controller operates in a logical layer of the device that is between a hardware layer of the device and the hypervisor.
11 . The non-transitory computer-readable medium of claim 9 , wherein the indication of available memory resources of the device includes information regarding memory allocations of one or more virtual machines that are installed on the device and that are managed via the hypervisor.
12 . The non-transitory computer-readable medium of claim 11 , wherein the indication of available memory resources of the device further includes memory allocations of one or more authorized processes that are operating in accordance with a host operating system of the device.
13 . The non-transitory computer-readable medium of claim 9 , wherein the memory conflict is determined by a failure of the writing of the set of data.
14 . The non-transitory computer-readable medium of claim 9 , wherein the memory conflict is determined by inspecting the at least the portion of the available memory resources of the device, after the writing, and detecting that the set of data is changed.
15 . The non-transitory computer-readable medium of claim 9 , the operations further comprising:
identifying a virtual machine that is operating on at least the portion of the available memory.
16 . The non-transitory computer-readable medium of claim 15 , the operations further comprising:
terminating the virtual machine that is identified.
17 . An apparatus comprising:
a processing system of a device including at least one processor; and a non-transitory computer-readable medium storing instructions which, when executed by the processing system, cause the processing system to perform operations, the operations comprising:
obtaining an indication of available memory resources of the device, wherein the indication of available memory resources is obtained via a virtualization security controller of the processing system from a hypervisor of the processing system;
writing via the virtualization security controller, a set of data to at least a portion of the available memory resources of the device;
determining, via the virtualization security controller, that a memory conflict exists in response to the writing;
generating, via the virtualization security controller, an alert of a possible unauthorized memory usage in response to determining the memory conflict.
18 . The apparatus of claim 17 , wherein the virtualization security controller operates in a logical layer of the device that is between a hardware layer of the device and the hypervisor.
19 . The apparatus of claim 17 , wherein the indication of available memory resources of the device includes information regarding memory allocations of one or more virtual machines that are installed on the device and that are managed via the hypervisor.
20 . The apparatus of claim 19 , wherein the indication of available memory resources of the device further includes memory allocations of one or more authorized processes that are operating in accordance with a host operating system of the device.Join the waitlist — get patent alerts
Track US2022121471A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.