VMware, Inc.
IMPLEMENTING DEFERRED GUEST CALLS IN A HOST-BASED VIRTUAL MACHINE INTROSPECTION SYSTEM
Last updated:
Abstract:
Example methods are provided for virtual machine introspection in which a guest monitoring mode (GMM) module monitors the execution of guest calls by an agent that resides in a virtual machine (VM). The GMM module sets a bit in bit mask that corresponds to a guest call that the agent needs to execute, and inserts an invisible breakpoint in the code of the guest call. If the GMM module detects that despite the setting of the bit in the bit mask, the agent does not complete the execution of the code (due to the invisible breakpoint not being triggered), then the GMM module considers this condition as a potential hijack of the VM by malicious code.
Status:
Application
Type:
Utility
Filling date:
12 Feb 2020
Issue date:
29 Apr 2021