IP Library Patent Application 14672167
Patent Application
App. No. 14/672,167

MANAGEMENT OF AGENTLESS VIRTUAL MACHINES VIA SECURITY VIRTUAL APPLIANCE

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
14/672,167
Abstract

In an example, a virtual data center includes a plurality of agentless virtual machines (VMs) protected by a security virtual appliance (SVA). Because the VMs are agentless, they cannot internally manage, update, or enforce VM-specific security policies. However, each VM includes an API that provides an interface for monitoring events such as turn on, turn off, heartbeats, and file events, as well as an interface for ordering an on-demand scan. The SVA builds a policy table, with entries for each VM or class of VMs, and using the API, monitors appropriate events, such as file events, to enforce VM-specific policies. Because the policy table is lightweight, it can be efficiently ported between multiple hypervisors, thus ensuring that a VMs policy remains intact, even if that VM is ported to a different hypervisor.

Claims (36)

1 . A computing apparatus for providing policy per virtual machine (PPVM) on a plurality of virtual machines (VMs) on a hypervisor, comprising:

a security virtual appliance (SVA) comprising a policy management engine operable for:

receiving a policy rule set to define a security policy for a virtual machine (VM);

building a policy table comprising a security policy entry for the VM;

receiving an application programming interface (API) event notification from the VM; and

issuing an API instruction to the VM to enforce the security policy entry.

2 . The computing apparatus of claim 1 , wherein the policy table includes policy entries for a plurality of VMs.

3 . The computing apparatus of claim 2 , wherein at least some of the VMs are identified by a universally unique identifier (UUID).

4 . The computing apparatus of claim 3 , wherein issuing the API instruction to the VM to enforce the security policy entry comprises correlating the security policy entry to a UUID for the VM in the policy table.

5 . The computing apparatus of claim 1 , wherein issuing the API instruction to the VM to enforce the security policy entry comprises issuing a file read instruction, and comparing a result of the file read instruction to a hash or fingerprint of a known malware object.

6 . The computing apparatus of claim 1 , wherein issuing the API instruction to the VM to enforce the security policy entry comprises issuing an API instruction to quarantine or inoculate a file.

7 . The computing apparatus of claim 1 , wherein issuing the API instruction to the VM to enforce the security policy entry comprises issuing an API instruction to perform a registry read.

8 . The computing apparatus of claim 1 , wherein issuing the API instruction to the VM to enforce the security policy entry comprises issuing an API instruction to perform a registry write.

9 . The computing apparatus of claim 1 , wherein the API event is a file event.

10 . The computing apparatus of claim 9 , wherein the file event is selected from the group consisting of read, write, access, create, delete, or replace.

11 . The computing apparatus of claim 1 , wherein the policy management engine is further operable for issuing an API scan instruction.

12 . The computing apparatus of claim 11 , wherein the API scan instruction is operable for generating a file access event for some or all files of the VM.

13 . The computing apparatus of claim 1 , wherein the policy management engine is further operable for detecting that the VM has been displaced to a second hypervisor, and replicating at least part of the policy table to the second hypervisor.

14 . One or more computer-readable mediums having stored thereon software instructions for provisioning a security virtual appliance (SVA) within a hypervisor, the SVA comprising a policy management engine operable for:

receiving a policy rule set to define a security policy for a virtual machine (VM);

building a policy table comprising a security policy entry for the VM;

receiving an application programming interface (API) event notification from the VM; and

issuing an API instruction to the VM to enforce the security policy entry.

15 . The one or more computer-readable mediums of claim 14 , wherein the policy table includes policy entries for a plurality of VMs.

16 . The one or more computer-readable mediums of claim 15 , wherein at least some of the VMs are identified by a universally unique identifier (UUID).

17 . The one or more computer-readable mediums of claim 16 , wherein issuing the API instruction to the VM to enforce the security policy entry comprises correlating the security policy entry to a UUID for the VM in the policy table.

18 . The one or more computer-readable mediums of claim 14 , wherein issuing the API instruction to the VM to enforce the security policy entry comprises issuing a file read instruction, and comparing a result of the file read instruction to a hash or fingerprint of a known malware object.

19 . The one or more computer-readable mediums of claim 14 , wherein issuing the API instruction to the VM to enforce the security policy entry comprises issuing an API instruction to quarantine or inoculate a file.

20 . The one or more computer-readable mediums of claim 14 , wherein issuing the API instruction to the VM to enforce the security policy entry comprises issuing an API instruction to perform a registry read or write.

21 . The one or more computer-readable mediums of claim 14 , wherein the API event is a file event.

22 . The one or more computer-readable mediums of claim 14 , wherein the policy management engine is further operable for issuing an API scan instruction operable for generating a file access event for some or all files of the VM.

23 . The one or more computer-readable mediums of claim 14 , wherein the policy management engine is further operable for detecting that the VM has been displaced to a second hypervisor, and replicating at least part of the policy table to the second hypervisor.

24 . A management console apparatus, comprising:

a security management engine operable for interfacing with one or more security virtual appliances (SVAs), the one or more SVAs configured to provide a user-configurable policy per virtual machine (PPVM) security framework to a plurality of agentless virtual machines via virtual machine (VM) application programming interface (API) instructions; and

a user interface driver operable for receiving a user input to configure the configurable PPVM.

25 . The management console apparatus of claim 24 , wherein the security management engine is further operable for providing a persistent PPVM to a virtual machine upon the virtual machine moving from a first hypervisor to a second hypervisor.

Assignments (8)
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 21, 2015
From: MEHTA, KUNAL
To: MCAFEE, INC.
Reel/Frame 035459/0911 →