IP Library Granted Patent US 8,732,791
Granted Patent B2
US 8,732,791 · App. 13/527,726 · Granted May 20, 2014

Multi-part internal-external process system for providing virtualization security protection

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,732,791
App. No.
13/527,726
Granted
May 20, 2014
Kind
B2
Abstract

In embodiments of the present invention improved capabilities are described for a host machine that manages a plurality of virtual machines associated with an enterprise through a supervisory process, the host machine including a threat management facility coupled in a communicating relationship with the plurality of virtual machines and enforcing a security policy of the enterprise for the plurality of virtual machines; and a first virtual machine from among the plurality of virtual machines, the first virtual machine capable of operating in a first state on the host machine wherein the security policy is enforced by the threat management facility, and the first virtual machine capable of operating in a second state wherein a local security facility executable on the first virtual machine autonomously enforces the security policy in the absence of the threat management facility.

Claims (28)

1. A system comprising:

a host machine that manages a plurality of virtual machines associated with an enterprise through a supervisory process, the host machine including a threat management facility coupled in a communicating relationship with the plurality of virtual machines and enforcing a security policy of the enterprise for the plurality of virtual machines; and

a first virtual machine from among the plurality of virtual machines, the first virtual machine capable of operating in a first state on the host machine wherein the security policy is enforced by the threat management facility, and the first virtual machine capable of operating in a second state wherein a local security facility executable on the first virtual machine autonomously enforces the security policy in the absence of the threat management facility.

2. The system of claim 1 , wherein a transition from the first state to the second state is initiated automatically when the virtual machine loses the communicating relationship with the host machine.

3. The system of claim 1 , wherein a transition from the first state to the second state is initiated automatically when the virtual machine loses the communicating relationship with the threat management facility.

4. The system of claim 1 , wherein the first virtual machine is executing on the host machine while operating in the second state.

5. The system of claim 1 , wherein the threat management facility is operating on a virtual machine separate from the plurality of virtual machines.

6. The system of claim 1 , wherein the security policy implemented by the local security facility is a subset of the security policy implemented by the threat management facility.

7. The system of claim 1 , wherein the security facilities provide protection against at least one of malicious code, a malicious application, and an unwanted application.

8. The system of claim 1 , further comprising a hardware-computing device independent from the host machine, wherein the first virtual machine is executing on the hardware-computing device while operating in the second state.

9. The system of claim 8 , wherein a user of the hardware-computing device initiates a transition from the first state to the second state in order to operate the first virtual machine on the hardware-computing device independently of the host machine.

10. The system of claim 8 , wherein the host machine initiates a transition from the first state to the second state.

11. A method comprising:

providing a host machine that manages a plurality of virtual machines associated with an enterprise through a supervisory process,

executing a threat management facility on the host machine coupled in a communicating relationship with the plurality of virtual machines, the threat management facility enforcing a security policy of the enterprise for the plurality of virtual machines;

operating a first virtual machine from among the plurality of virtual machines in a first state on the host machine wherein the security policy is enforced by the threat management facility; and

operating the first virtual machine in a second state wherein a local security facility executable on the first virtual machine autonomously enforces the security policy in the absence of the threat management facility.

12. The method of claim 11 , wherein a transition from the first state to the second state is initiated automatically when the virtual machine loses the communicating relationship with the threat management facility.

13. The method of claim 11 , wherein the first virtual machine is executing on the host machine while operating in the second state.

14. The method of claim 11 , further comprising a hardware-computing device independent from the host machine, wherein the first virtual machine is executing on the hardware-computing device while operating in the second state.

15. The method of claim 11 , wherein the security facilities provide protection against at least one of malicious code, a malicious application, and an unwanted application.

16. A computer program product comprising computer executable code embodied in a non-transitory computer readable medium that, when executing on one or more computing devices, provides a virtual machine configured to perform the steps of:

operating in a first state on a host machine that hosts a plurality of virtual machines and provides a threat management facility for enforcing a security policy for the virtual machine; and

operating in a second state, wherein the second state includes a local security facility configured to autonomously enforce the security policy in the absence of the threat management facility.

17. The computer program product of claim 16 , wherein a transition from the first state to the second state is initiated automatically when the virtual machine loses a communicating relationship with the threat management facility of the host machine.

18. The computer program product of claim 16 , wherein the first virtual machine is executing on the host machine while operating in the second state.

19. The computer program product of claim 16 , further comprising a hardware-computing device independent from the host machine, wherein the first virtual machine is executing on the hardware-computing device while operating in the second state.

20. The computer program product of claim 16 , wherein the security facilities provide protection against at least one of malicious code, a malicious application, and an unwanted application.

Assignments (7)
RELEASE OF SECURITY INTEREST IN PATENTS AT R/F 053476/0681 Recorded Mar 9, 2021
From: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
To: SOPHOS LIMITED
Reel/Frame 056469/0815 →
RELEASE OF SECURITY INTEREST Recorded Jul 28, 2020
From: DEUTSCHE BANK AG NEW YORK BRANCH
To: SOPHOS LIMITED
Reel/Frame 053334/0220 →
PATENT SECURITY AGREEMENT FIRST LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 053124/0350 →
PATENT SECURITY AGREEMENT SECOND LIEN Recorded Jul 6, 2020
From: SOPHOS LIMITED
To: OWL ROCK CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 053476/0681 →
SECURITY AGREEMENT Recorded Feb 3, 2014
From: SOPHOS LIMITED
To: DEUTSCHE BANK AG NEW YORK BRANCH, AS COLLATERAL AGENT
Reel/Frame 032152/0896 →
CHANGE OF NAME Recorded Apr 11, 2013
From: SOPHOS PLC
To: SOPHOS LIMITED
Reel/Frame 030194/0299 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 20, 2012
From: CHOUDRIE, SUNIL CERI
To: SOPHOS PLC
Reel/Frame 028408/0742 →