MY151284A

Computer security management, such as in a virtual machine or hardened operating system

Abstract

A SECURITY SCHEME PROVIDES SECURITY TO ONE OR MORE SELF-CONTAINED OPERATING ENVIRONMENT INSTANCES EXECUTING ON A COMPUTER (100). THE SECURITY SCHEME MAY INCLUDE IMPLEMENTING A SET OF SECURITY APPLICATIONS (202) THAT MAY BE CONTROLLED BY A SUPERVISORY PROCESS (128), OR THE LIKE. BOTH THE SET OF SECURITY APPLICATIONS (202) AND THE SUPERVISORY PROCESS (128) MAY OPERATE ON A HOST SYSTEM (102) OF THE COMPUTER, WHICH MAY ALSO PROVIDE A PLATFORM FOR EXECUTION OF THE ONE OR MORE SELF-CONTAINED OPERATING ENVIRONMENTS. THE SECURITY SCHEME PROTECTS PROCESSES RUNNING IN THE ONE OR MORE SELF-CONTAINED OPERATING ENVIRONMENT AND PROCESSES RUNNING ON THE COMPUTER OUTSIDE OF THE SELF-CONTAINED OPERATING ENVIRONMENTS. FIGURE FOR PUBLICATION: 2

MY151284A, drawing sheet 1
Sheet 1 of 10

Term

No projected expiry on record.

  1. Priority
  2. Filed
  3. Published
  4. Today

20 claims: 3 independent, 17 dependent

  1. 1
    CLAIMS We claim:1. In a computer, a method for monitoring and protecting multiple instances of a contained process execution environment, wherein each of the multiple instances accesses emulated resources of the computer, the method comprising: executing, on the computer, at least one security application that monitors each of the multiple instances of a contained process execution environment to detect harmful processes, wherein the at least one security application executes external to the multiple instances of a contained process execution environment;and facilitating scanning of virtual resources of the each of the multiple instances of a contained process execution environment by the single set of security applications, wherein the virtual resources include the emulated resources of the computer, and wherein the facilitating includes configuring the set of security applications to be aware of the resources as perceived by a primary operating system of the computer.
  2. 11
    A method in a computer system for protecting an operating system against damage caused by undesirable process actions, the method comprising:pausing a kernel running on the operating system, wherein the operating system is at least partially isolated from core aspects of the computer system's infrastructure;checking the kernel to determine whether there is evidence of an undesirable process action, wherein the checking is performed, at least in part, by a supervisory process that is separate from the at least partially isolated operating system;and where there is evidence of an undesirable process action in the at least partially isolated operating system, taking steps to contain the undesirable process action.
  3. 15
    A computer system for securing access to privileged operations associated with core components of the computer system, the system comprising:a processor;a primary memory storage in communication with the processor;a secondary storage device;an operating system;and a host system, wherein the host system includes: one or more virtual machines, wherein each of the one or more virtual machines is isolated from the core components of the computer system such that harmful processes cannot directly access the core components when running in an environment associated with the virtual machine, and wherein each one of the one or more virtual machines includes an instance of a virtual operating system, access to a virtual memory, and at least one virtual driver;and at least one supervisory process used to monitor the one or more virtual machines in combination with a security application, wherein the monitoring includes the possible detection of a harmful process, and wherein the at least one supervisory process and the security application are isolated from the virtual machine.