IP Library Granted Patent US 9,552,497
Granted Patent B2
US 9,552,497 · App. 12/615,521 · Granted Jan 24, 2017

System and method for preventing data loss using virtual machine wrapped applications

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,552,497
App. No.
12/615,521
Granted
Jan 24, 2017
Kind
B2
Abstract

A method in one example implementation includes selecting at least one criterion for controlling data transmission from within a virtual machine. At least one application is included within the virtual machine, which includes a policy module. The selected criterion corresponds to at least one policy associated with the policy module. The method also includes evaluating the selected criterion of the policy to permit an attempt to transmit the data from within the virtual machine. In more specific embodiments, the policy may include a plurality of criteria with a first selected criterion permitting transmission of the data to a first application and a second selected criterion prohibiting transmission of the data to a second application. In another specific embodiment, the method may include updating the policy module through an administration module to modify the selected criterion.

Claims (44)

1. A method, comprising:

receiving a request from a host operating system outside a virtual machine for access to a data from a browser within the virtual machine;

evaluating a criterion of a policy to determine whether to permit the access to the data, wherein the evaluating is performed in response to a determination that a master image is not available, the master image corresponding to a version of the virtual machine;

downloading the browser, in response to a determination that the browser is not being used;

comparing the browser to the master image to determine if the browser is current;

updating the browser if the browser is determined, based on the master image, to not be current, wherein the browser is part of an application suite wrapped in the virtual machine; and

creating a buffer for manipulating the data within the virtual machine, based on the criterion of the policy, wherein the buffer cannot be accessed by the host operating system.

2. The method of claim 1 , further comprising:

updating the policy through an administration module included in a virtual machine monitor to modify the criterion.

3. The method of claim 1 , wherein the policy includes a criterion permitting an attempt to transmit the data to another application.

4. The method of claim 1 , wherein a criterion of the policy permits a transmission of the data to a client device if the client device is requesting the access to the browser from within a secured network environment, and prohibits the transmission of the data to the client device if the client device is requesting the access to the browser from an unsecured network environment.

5. The method of claim 1 , further comprising:

creating a log for recording an entry corresponding to data transmitted from the virtual machine.

6. The method of claim 1 , further comprising:

sending an email message from a mail client within a virtual machine to a secure mail proxy; and

extracting data from the email message if a criterion of the policy indicates that a recipient of the email message is not authorized to receive the extracted data.

7. One or more non-transitory computer readable storage media that include codes for execution that, when executed by a processor, are operable to perform operations comprising:

receiving a request from a host operating system outside a virtual machine for access to a data from a browser within the virtual machine;

evaluating a criterion of a policy to determine whether to permit the access to the data, wherein the evaluating is performed in response to a determination that a master image is not available, the master image corresponding to a version of the virtual machine;

downloading the browser, in response to a determination that the browser is not being used;

comparing the browser to the master image to determine if the browser is current;

updating the browser if the browser is determined, based on the master image, to not be current, wherein the browser is part of an application suite wrapped in the virtual machine; and

creating a buffer for manipulating the data within the virtual machine, based on the criterion of the policy, wherein the buffer cannot be accessed by the host operating system.

8. The media of claim 7 , the operations further comprising:

updating the policy through an administration module included in a virtual machine monitor to modify the criterion.

9. The media of claim 7 , wherein the policy includes a criterion permitting an attempt to transmit the data to another application.

10. The media of claim 7 , wherein a criterion of the policy permits a transmission of the data to a client device if the client device is requesting the access to the browser from within a secured network environment, and prohibits the transmission of the data to the client device if the client device is requesting the access to the browser from an unsecured network environment.

11. An apparatus, comprising:

a memory element; and

a processor that executes instructions associated with the memory element, wherein the apparatus is configured for

receiving a request from a host operating system outside a virtual machine for access to a data from at least one browser within the virtual machine;

evaluating, in response to a determination that a master image is not available, a criterion of a policy to determine whether to permit the access to the data, the master image corresponding to a version of the virtual machine;

downloading the at least one browser, in response to a determination that the at least one browser is not being used;

comparing the at least one browser to the master image to determine if the at least one browser is current;

updating the at least one browser if the at least one browser is determined, based on the master image, to not be current, wherein the at least one browser is part of an application suite wrapped in the virtual machine; and

creating a buffer for manipulating the data within the virtual machine, based on the criterion of the policy, wherein the buffer cannot be accessed by the host operating system.

12. The apparatus of claim 11 , wherein the policy includes a criterion permitting an attempt to transmit the data to another application.

13. The apparatus of claim 11 , wherein a criterion of the policy permits a transmission of the data to a client device if the client device is requesting the access to the at least one browser from within a secured network environment, and prohibits the transmission of the data to the client device if the client device is requesting the access to the at least one browser from an unsecured network environment.

14. The apparatus of claim 11 , wherein the buffer is within the virtual machine.

15. The apparatus of claim 11 , wherein the processor is configured to

send an email message from a mail client within a virtual machine to a secure mail proxy; and

extract data from the email message if a criterion of the policy indicates that a recipient of the email message is not authorized to receive the extracted data.

16. The media of claim 7 , wherein the policy is configured in the virtual machine before the virtual machine is deployed.

17. The media of claim 7 , wherein if a client has the version of the virtual machine, access to the virtual machine is allowed.

Assignments (8)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →