IP Library Granted Patent US 9,817,687
Granted Patent B2
US 9,817,687 · App. 14/615,546 · Granted Nov 14, 2017

System and method for isolated virtual image and appliance communication within a cloud environment

Inventors: Igal Weinstein (Modi'in, IL); Nir Barak (Karmi Yosef, IL)
Assignee: CA, Inc.
G06F9/45558G06F2009/45587G06F2009/45595
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,817,687
App. No.
14/615,546
Granted
Nov 14, 2017
Kind
B2
Abstract

Provided herein are systems and methods for providing isolated virtual image communication in a virtual computing environment. Initially, a guest virtual machine that is activated in a virtual computing environment may be isolated into a private network. A service request may then be formulated at the guest virtual machine and addressed to a predetermined non-existent address. The request is then ostensibly sent to the predetermined address, whereupon the service request is actually transmitted to a shared resource with a security appliance machine in the virtual computing environment. The request is then forwarded to the security appliance machine and a reply formulated. The reply is sent back to the guest virtual machine via the shared resource.

Claims (41)

1. A method to provide isolated virtual image communication in a virtual computing environment, the method executed by a processor configured to perform a plurality of operations comprising:

isolating a guest virtual machine in the virtual computing environment, and the guest virtual machine's one or more clients, within a virtual network such that the guest virtual machine is unreachable from outside the virtual network, the one or more clients being outside the virtual computing environment;

formulating, on the guest virtual machine, a request to a resource, or for a service, outside the virtual network;

after the formulating of the request, attempting to send the request, whereupon the request is transmitted to a software resource, wherein the guest virtual machine shares the software resource with a security appliance machine software program, and the software resource shared with the security appliance machine software program, the guest virtual machine and the security appliance machine software program are hosted in the virtual computing environment;

forwarding the request from the software resource shared with the security appliance machine software program to the security appliance machine software program; and

after the forwarding of the request, formulating a reply to the request at the security appliance machine software program for transmittal to the guest virtual machine, the formulating the reply comprising:

formulating the reply using first information in the request, and

further formulating the reply using second information received at the security appliance machine software program from the resource with respect to which the request is formulated on the guest virtual machine or from the service with respect to which the request is formulated on the guest virtual machine.

2. The method of claim 1 , wherein the request is addressed to a predetermined address that comprises a non-existent address for the resource or the service outside the virtual network.

3. The method of claim 2 , wherein the resource or the service outside the virtual network is not located at the predetermined address.

4. The method of claim 1 , wherein the software resource shared with the security appliance machine software program is a network filter.

5. The method of claim 1 , wherein the software resource shared with the security appliance machine software program runs on a hypervisor that supports the guest virtual machine and the security appliance machine software program.

6. The method of claim 1 , wherein the formulating the reply to the request comprises formulating the reply using third information from the security appliance machine software program.

7. The method of claim 1 , wherein the formulating the reply to the request further comprises determining, at the security appliance machine software program, that an address in the request indicates that the guest virtual machine is isolated within the virtual network.

8. The method of claim 1 , wherein the formulating the reply to the request further comprises determining, at the security appliance machine software program, what resources are needed to service the request by inspecting an information content of the request.

9. The method of claim 1 , wherein the formulating the request is performed because the guest virtual machine has been moved from a first host to a second host, and wherein the request relates to verification of the second host.

10. The method of claim 1 , wherein the request relates to a software update.

11. A system to provide isolated virtual image communication in a virtual computing environment, the system comprising:

a processor configured to:

isolate a guest virtual machine in the virtual computing environment, and the guest virtual machine's one or more clients, within a virtual network such that the guest virtual machine is unreachable from outside the virtual network, the one or more clients being outside the virtual computing environment;

formulate, on the guest virtual machine, a request to a resource, or for a service, outside the virtual network;

after formulating the request, attempt to send the request, whereupon the request is transmitted to a software resource, wherein the guest virtual machine shares the software resource with a security appliance machine software program, and the software resource shared with the security appliance machine software program, the guest virtual machine and the security appliance machine software program are hosted in the virtual computing environment;

forward the request from the software resource shared with the security appliance machine software program to the security appliance machine software program; and

after the forwarding the request, formulate a reply to the request at the security appliance machine software program for transmittal to the guest virtual machine, wherein to formulate the reply, the processor is configured to:

formulate the reply using first information in the request, and

further formulate the reply using second information received at the security appliance machine software program from the resource with respect to which the request is formulated on the guest virtual machine or from the service with respect to which the request is formulated on the guest virtual machine.

12. The system of claim 11 , wherein the request is addressed to a predetermined address that comprises a non-existent address for the resource or the service outside the virtual network.

13. The method of claim 12 , wherein the resource or the service outside the virtual network is not located at the predetermined address.

14. The system of claim 11 , wherein the software resource shared with the security appliance machine software program is a network filter.

15. The system of claim 11 , wherein the software resource shared with the security appliance machine software program runs on a hypervisor that supports the guest virtual machine and the security appliance machine software program.

16. The system of claim 11 , wherein the reply to the request is formulated using third information from the security appliance machine software program.

17. The system of claim 11 , wherein the processor configured to formulate the reply to the request is further configured to determine, at the security appliance machine software program, that an address in the request indicates that the guest virtual machine is isolated within the virtual network.

18. The system of claim 11 , wherein the processor configured to formulate the reply to the request is further configured to determine, at the security appliance machine software program, what resources are needed to service the request by inspection of an information content of the request.

19. The system of claim 11 , wherein the formulating the request is performed because the guest virtual machine has been moved from a first host to a second host, and wherein the request relates to verification of the second host.

20. A non-transitory computer-readable medium having computer-executable instructions thereon, to provide isolated virtual image communication in a virtual computing environment, the computer-executable instructions, when executed by a processor cause the processor to perform a plurality of operations comprising:

isolating a guest virtual machine in the virtual computing environment, and the guest virtual machine's one or more clients, within a virtual network such that the guest virtual machine is unreachable from outside the virtual network, the one or more clients being outside the virtual computing environment;

formulating, on the guest virtual machine, a request to a resource, or for a service, outside the virtual network;

after the formulating of the request, attempting to send the request, whereupon the request is transmitted to a software resource, wherein the guest virtual machine shares the software resource with a security appliance machine software program, and the software resource shared with the security appliance machine software program, the guest virtual machine and the security appliance machine software program are hosted in the virtual computing environment;

forwarding the request from the software resource shared with the security appliance machine software program to the security appliance machine software program; and

after the forwarding of the request, formulating a reply to the request at the security appliance machine software program for transmittal to the guest virtual machine, the formulating the reply comprising:

formulating the reply using first information in the request, and further formulating the reply using second information received at the security appliance machine software program from the resource with respect to which the request is formulated on the guest virtual machine or from the service with respect to which the request is formulated on the guest virtual machine.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 6, 2015
From: WEINSTEIN, IGAL; BARAK, NIR
To: COMPUTER ASSOCIATES THINK, INC.
Reel/Frame 034904/0050 →
MERGER Recorded Feb 6, 2015
From: COMPUTER ASSOCIATES THINK, INC.
To: CA, INC.
Reel/Frame 034904/0154 →
Continuity (2)
Continuation 13406088 · Feb 27, 2012
Related Publication 20150154043A1 · Jun 4, 2015