IP Library Granted Patent US 9,355,256
Granted Patent B2
US 9,355,256 · App. 13/950,014 · Granted May 31, 2016

Sanitization of virtual machine images

Inventors: Suresh N. Chari (Tarrytown, NY); Ashish Kundu (Elmsford, NY)
Assignee: International Business Machines Corporation
G06F21/60G06F9/45558G06F21/53H04L63/105G06F2009/45587G06F2221/2113G06F2221/2149
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,355,256
App. No.
13/950,014
Granted
May 31, 2016
Kind
B2
Abstract

Sanitizing a virtual machine image of sensitive data is provided. A label for a sensitivity level is attached to identified sensitive data contained within each software component in a plurality of software components of a software stack in a virtual machine image based on labeling policies. In response to receiving an input to perform a sanitization of the identified sensitive data having attached sensitivity level labels contained within software components of the software stack in the virtual machine image, the sanitization of the identified sensitive data having the attached sensitivity level labels contained within the software components of the software stack in the virtual machine image is performed based on sanitization policies.

Claims (20)

1. A computer-implemented method for sanitizing a virtual machine image of sensitive data, the computer-implemented method comprising:

inserting, by a computer, a labeler module and a sanitizer module into each software component in a plurality of software components of a software stack in the virtual machine image;

identifying, by the computer, labeling dependencies and sanitization dependencies between the plurality of software components of the software stack in the virtual machine image based on labeling execution policies located in the labeler module and sanitization execution policies located in the sanitizer module, respectively;

attaching, by the computer using the labeler module, a sensitivity level label of a plurality of sensitivity labels to identified sensitive data from the sensitive data contained within the plurality of software components of the software stack in the virtual machine image based on the identified labeling dependencies between the plurality of software components of the software stack; and

responsive to the computer receiving an input to perform a sanitization of the identified sensitive data having attached sensitivity level labels contained within the plurality of software components of the software stack in the virtual machine image, performing, by the computer using the sanitizer module, the sanitization of the identified sensitive data having the attached sensitivity level labels contained within the plurality of software components of the software stack in the virtual machine image based on the identified sanitization dependencies between the plurality of software components of the software stack.

2. The computer-implemented method of claim 1 , further comprising:

executing, by the computer, a labeling program in the each software component in the plurality of software components of the software stack in the virtual machine image based on the labeling execution policies.

3. The computer-implemented method of claim 2 , further comprising:

identifying, by the computer, a partial order in the labeling execution policies, wherein the labeling program is executed in the partial order; and

handling, by the computer, failures during labeling of the virtual machine image.

4. The computer-implemented method of claim 1 , further comprising:

executing, by the computer, a sanitization program in the each software component in the plurality of software components of the software stack in the virtual machine image based on the sanitization execution policies.

5. The computer-implemented method of claim 4 , further comprising:

identifying, by the computer, a partial order in the sanitization execution policies, wherein the sanitization program is executed in the partial order; and

handling, by the computer, failures during sanitization of the virtual machine image.

6. The computer-implemented method of claim 1 , wherein the sensitivity level label of the plurality of sensitivity labels is one of a high sensitivity level label, a medium sensitivity level label, and a low sensitivity level label.

7. The computer-implemented method of claim 1 , wherein the plurality of software components of the software stack in the virtual machine image is an applications software component, a middleware software component, a guest operating system software component, and a virtual storage software component.

8. The computer-implemented method of claim 1 , wherein the virtual machine image is one of a virtual machine instance, a virtual machine snapshot, or a virtual machine clone.

9. The computer-implemented method of claim 1 , wherein the sanitization of the identified sensitive data having the attached sensitivity level labels is one of a delete sanitization action, an overwrite sanitization action, an encrypt sanitization action, and a backup deleted or overwritten data sanitization action.

10. The computer-implemented method of claim 1 , wherein the computer identifies the labeling dependencies using a directed acyclic graph of labeling dependencies in the labeling execution policies and identifies the sanitization dependencies using a directed acyclic graph of sanitization dependencies in the sanitization execution policies.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 24, 2013
From: CHARI, SURESH N.; KUNDU, ASHISH
To: INTERNATIONAL BUSINESS MACHINES CORPORATION
Reel/Frame 030870/0137 →
Continuity (1)
Related Publication 20150033221A1 · Jan 29, 2015