Have you considered utilizing a Nexus 1000V as your virtual switch? It provides granular QoS capabilities at the VM level.
http://www.cisco.com/en/US/prod/collateral/switches/ps9441/ps9902/qa_c67-556624.html
With that being said, you can also apply a policing policy to the ingress interface of your VM host. See the following link for full details:
http://www.cisco.com/en/US/products/hw/switches/ps700/products_tech_note09186a00801c8c4b.shtml
The basic concept is that you create an ACL to match your AV server's update traffic, create a class map that uses the ACL as its match criteria, create a service policy that polices that class, and finally apply it to the ingress interface.
Hope this helps.
Regards,
Matt