IP Library Patent Application 15010444
Patent Application
App. No. 15/010,444

SECURING INTERNAL SERVICES IN AN APPLIANCE

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
15/010,444
Abstract

Disclosed herein are methods, systems, and processes to secure internal services in an appliance. A service call initiated by a client process of a client is intercepted. The service call is a request for an internal service provided by a server. The client and the server are deployed in an appliance. The service call includes an identifier, and the identifier identifies the internal service. If one or more rules are specified for the identifier, attribute(s) of at least one specified and/or defined rule are processed. The service call is then forwarded to the server if the processing indicates that the forwarding the service call is allowable.

Claims (83)

1 . A method comprising:

intercepting a service call initiated by a client process of a client, wherein

the service call is a request for an internal service,

the internal service is provided by a server,

the client and the server are deployed in an appliance,

the service call comprises an identifier, and

the identifier identifies the internal service;

determining whether one or more rules of a plurality of rules are specified for the identifier; and

in response to a determination that the one or more rules are specified for the identifier, processing one or more attributes of the one or more rules, and

forwarding the service call to the server, if the processing indicates that the forwarding the service call is allowable.

2 . The method of claim 1 , further comprising:

retrieving one or more client process properties of a plurality of client process properties associated with the client process from kernel memory.

3 . The method of claim 1 , wherein

the identifier is a port identifier or a port number.

4 . The method of claim 2 , wherein

the plurality of client process properties comprise a user context, a user group context, a client program name, a parent process name, or a terminal type.

5 . The method of claim 2 , further comprising:

forwarding the service call to the server if each attribute of the one or more attributes of at least one rule matches a corresponding client process property of the one or more client process properties.

6 . The method of claim 2 , further comprising:

forwarding the service call to the server without accessing the kernel memory, if no rule is specified for the internal service identified by the identifier.

7 . The method of claim 5 , further comprising:

generating a reject notification if at least one client process property of the one or more client process properties does not match each attribute, and

sending the reject notification to the client.

8 . The method of claim 7 , wherein

a first attribute of the one or more attributes of a first rule of the one or more rules corresponds to a first client process property of the one or more client process properties, and

a second attribute of the one or more attributes of a second rule of the one or more rules corresponds to a second client process property of the one or more client process properties.

9 . The method of claim 2 , wherein

the plurality of rules are part of a rule set,

the rule set is part of a service call filter module, and

the service call filter module is part of kernel.

10 . The method of claim 9 , further comprising:

accessing the rule set to determine whether the internal service identified by the identifier is unprotected or protected.

11 . The method of claim 10 , wherein

the internal service is protected if the rule set comprises at least one rule of the plurality of rules for the identifier specified in the service call, and

the internal service is unprotected if the rule set does not comprise at least one rule of the plurality of rules for the internal service specified in the service call.

12 . The method of claim 11 , further comprising:

forwarding the service call to the server if

the internal service is unprotected, or

each attribute of the at least one rule matches the corresponding client process property of the one or more client process properties.

13 . A non-transitory computer readable storage medium storing program instructions executable to:

intercept a service call initiated by a client process of a client, wherein

the service call is a request for an internal service,

the internal service is provided by a server,

the client and the server are deployed in an appliance,

the service call comprises an identifier, and

the identifier identifies the internal service;

determine whether one or more rules of a plurality of rules are specified for the identifier; and

in response to a determination that the one or more rules are specified for the identifier, process one or more attributes of the one or more rules, and

forward the service call to the server, if the processing indicates that the forwarding the service call is allowable.

14 . The non-transitory computer readable storage medium of claim 13 , further comprising:

retrieving one or more client process properties of a plurality of client process properties associated with the client process from kernel memory, wherein

the identifier is a port identifier or a port number, and

the plurality of client process properties comprise a user context, a user group context, a client program name, a parent process name, or a terminal type.

15 . The non-transitory computer readable storage medium of claim 14 , further comprising:

forwarding the service call to the server if each attribute of at least one rule matches a corresponding client process property, or

forwarding the service call to the server without accessing the kernel memory, if no rule is specified for the internal service identified by the identifier.

16 . The non-transitory computer readable storage medium of claim 15 , further comprising:

accessing the rule set to determine whether the internal service identified by the identifier is unprotected or protected, wherein

the internal service is protected if the rule set comprises at least one rule for the identifier specified in the service call, and

the internal service is unprotected if the rule set does not comprise at least one rule for the internal service specified in the service call.

17 . A system comprising:

one or more processors; and

a memory coupled to the one or more processors, wherein the memory stores program instructions executable by the one or more processors to:

intercept a service call initiated by a client process of a client, wherein

the service call is a request for an internal service,

the internal service is provided by a server,

the client and the server are deployed in an appliance,

the service call comprises an identifier, and

the identifier identifies the internal service;

determine whether one or more rules of a plurality of rules are specified for the identifier; and

in response to a determination that the one or more rules are specified for the identifier,

process one or more attributes of the one or more rules, and

forward the service call to the server, if the processing indicates that the forwarding the service call is allowable.

18 . The system of claim 17 , wherein

the plurality of rules are part of a rule set,

the rule set is part of a service call filter module, and

the service call filter module is part of kernel.

19 . The system of claim 17 , further comprising:

retrieving one or more client process properties of a plurality of client process properties associated with the client process from kernel memory, wherein

the plurality of client process properties comprise a user context, a user group context, a client program name, a parent process name, or a terminal type.

20 . The system of claim 19 , further comprising:

forwarding the service call to the server if each attribute of the one or more attributes of at least one rule matches a corresponding client process property of the one or more client process properties, or

forwarding the service call to the server without accessing the kernel memory, if no rule is specified for the internal service identified by the identifier.

Assignments (8)
RELEASE OF SECURITY INTEREST Recorded Dec 13, 2024
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: VERITAS TECHNOLOGIES LLC
Reel/Frame 069632/0613 →
RELEASE OF SECURITY INTEREST Recorded Dec 13, 2024
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: VERITAS TECHNOLOGIES LLC
Reel/Frame 069634/0584 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS AT R/F 052426/0001 Recorded Nov 30, 2020
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
To: VERITAS TECHNOLOGIES LLC
Reel/Frame 054535/0565 →
SECURITY INTEREST Recorded Aug 20, 2020
From: VERITAS TECHNOLOGIES LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 054370/0134 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Apr 16, 2020
From: VERITAS TECHNOLOGIES, LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 052426/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 12, 2017
From: SYMANTEC CORPORATION
To: VERITAS TECHNOLOGIES LLC
Reel/Frame 044362/0859 →
PATENT SECURITY AGREEMENT Recorded Nov 23, 2016
From: VERITAS TECHNOLOGIES LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 040679/0466 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 16, 2016
From: GOEL, VIKAS
To: SYMANTEC CORPORATION
Reel/Frame 037744/0500 →