Invention Grant
- Patent Title: Guest netfilter protection by virtual machine function
-
Application No.: US15251462Application Date: 2016-08-30
-
Publication No.: US10257166B2Publication Date: 2019-04-09
- Inventor: Michael Tsirkin
- Applicant: Red Hat Israel, Ltd.
- Applicant Address: IL Ra'anana
- Assignee: Red Hat Israel, Ltd
- Current Assignee: Red Hat Israel, Ltd
- Current Assignee Address: IL Ra'anana
- Agency: K&L Gates LLP
- Main IPC: H04L29/06
- IPC: H04L29/06 ; G06F12/1009 ; G06F9/455

Abstract:
A system and method for guest netfilter protection using a virtual machine function includes a memory, one or more processors, in communication with the memory, a virtual machine, a hypervisor, and a virtual network interface controller on the virtual machine. The virtual machine and the hypervisor are configured to execute on the one or more processors. The hypervisor is configured to boot a guest operating system on the virtual machine. Then, the guest operating system is configured to send a list of networking filter rules to a virtual machine function executing on the virtual machine. The virtual machine function is configured to store the list of networking filter rules in a virtual machine function memory. The hypervisor is further configured to prevent the guest operating system from directly accessing the virtual network interface controller and allow the virtual machine function to access the virtual network interface controller.
Public/Granted literature
- US20180063083A1 GUEST NETFILTER PROTECTION BY VIRTUAL MACHINE FUNCTION Public/Granted day:2018-03-01
Information query