Abstract: A formally verified trusted computing base with active security and policy enforcement is described. The formally verified trusted computing base includes a formally verified microkernel and multiple formally verified hyper-processes including a virtual machine monitor (VMM), virtual machine introspection (VMI), policy enforcers including an active security policy enforcer (ASPE), and a virtual switch. The active security and policy enforcement continuously monitors for semantic behavior detection or policy violations and enforces the policies at the virtualization layer. Further, policies can be attached to the network layer to provide granular control of the communication of the computing device.
Type:
Grant
Filed:
October 13, 2021
Date of Patent:
September 13, 2022
Assignee:
BedRock Systems, Inc.
Inventors:
Osman Abdoul Ismael, Ashar Aziz, Jonas Pfoh