VMware, Inc.
HYPERCALL AUTHENTICATION IN A GUEST-ASSISTED VIRTUAL MACHINE INTROSPECTION (VMI) IMPLEMENTATION

Last updated:

Abstract:

Example methods are provided to use a guest monitoring mode (GMM) module in a hypervisor to authenticate hypercalls sent by a guest agent to the GMM module. The GMM module uses reference information, including thread information associated with a thread, to determine whether a hypercall associated with the thread was issued by the trusted guest agent or by potentially malicious code.

Status:
Application
Type:

Utility

Filling date:

27 Jul 2020

Issue date:

16 Dec 2021