Invention Grant
- Patent Title: System and method for protecting memory pages associated with a process using a virtualization layer
-
Application No.: US15199879Application Date: 2016-06-30
-
Publication No.: US10216927B1Publication Date: 2019-02-26
- Inventor: Udo Steinberg
- Applicant: FireEye, Inc.
- Applicant Address: US CA Milpitas
- Assignee: FireEye, Inc.
- Current Assignee: FireEye, Inc.
- Current Assignee Address: US CA Milpitas
- Agency: Rutan & Tucker, LLP
- Main IPC: G06F11/14
- IPC: G06F11/14 ; G06F12/00 ; G06F21/53 ; G06F12/14 ; G06F9/455

Abstract:
A computerized method is provided for protecting processes operating within a computing device. The method comprises an operation for identifying, by a virtualization layer operating in a host mode, when a guest process switch has occurred. The guest process switch corresponds to a change as to an operating state of a process within a virtual machine. Responsive to an identified guest process switch, an operation is conducted to determine, by the virtualization layer, whether hardware circuitry within the computing device is to access a different nested page table for use in memory address translations. The different nested page table alters page permissions for one or more memory pages associated with at least the process that are executable in the virtual machine.
Information query