Invention Publication
- Patent Title: ENDPOINT INCIDENT RESPONSE FROM A SECURE ENCLAVE THROUGH DYNAMIC INSERTION OF AN INTERRUPT
-
Application No.: US17979482Application Date: 2022-11-02
-
Publication No.: US20240143763A1Publication Date: 2024-05-02
- Inventor: Mandar NANIVADEKAR , Sachin SHINDE , Bharath Kumar CHANDRASEKHAR
- Applicant: VMware, Inc.
- Applicant Address: US CA Palo Alto
- Assignee: VMware, Inc.
- Current Assignee: VMware, Inc.
- Current Assignee Address: US CA Palo Alto
- Main IPC: G06F21/56
- IPC: G06F21/56 ; G06F21/53 ; G06F21/54

Abstract:
A method of protecting an endpoint against a security threat detected at the endpoint, wherein the endpoint includes, in memory pages of the endpoint, an operating system (OS), a separate software entity, and remediation code, includes the steps of: transferring control of virtual CPUs (vCPUs) of the endpoint from the OS to the separate software entity; and while the separate software entity controls the vCPUs, storing, in an interrupt dispatch table, an instruction address corresponding to an interrupt, wherein the remediation code is stored at the instruction address, and replacing a next instruction to be executed by the OS, with an interrupt instruction, wherein the interrupt is raised when the OS executes the interrupt instruction, and the remediation code is executed as a result of handling of the interrupt that is raised.
Public/Granted literature
- US12254091B2 Endpoint incident response from a secure enclave through dynamic insertion of an interrupt Public/Granted day:2025-03-18
Information query