VMware, Inc.
HYPERCALL AUTHENTICATION IN A GUEST-ASSISTED VIRTUAL MACHINE INTROSPECTION (VMI) IMPLEMENTATION
Last updated:
Abstract:
Example methods are provided to use a guest monitoring mode (GMM) module in a hypervisor to authenticate hypercalls sent by a guest agent to the GMM module. The GMM module uses reference information, including thread information associated with a thread, to determine whether a hypercall associated with the thread was issued by the trusted guest agent or by potentially malicious code.
Status:
Application
Type:
Utility
Filling date:
27 Jul 2020
Issue date:
16 Dec 2021