IP Library › Granted Patent US 9,858,108
Granted Patent B2
US 9,858,108 · App. 15/050,670 · Granted Jan 2, 2018

Virtual switch interceptor

Inventors: Ashvin Sanghvi (Sammamish, WA); Ilarie Letca (Redmond, WA); Alexandre Coelho (Redmond, WA)
Assignee: MICROSOFT TECHNOLOGY LICENSING, LLC
G06F9/45558G06F9/45533H04L41/06H04L49/70G06F2009/45591G06F2009/45595H04L41/04H04L41/22H04L45/586
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,858,108
App. No.
15/050,670
Granted
Jan 2, 2018
Kind
B2
Abstract

Application management is facilitated by observing messages communicated amongst virtual applications external to application-hosting virtual machines. In one instance, the messages can be observed from within a virtual switch outside hosting virtual machines. One or more actions can subsequently be performed as a function of the messages such as but not limited to application monitoring as well as message routing, filtering, and/or transformation.

Claims (31)

1. A physical computing device comprising:

a processor;

memory that is coupled to the processor and that includes computer-executable instructions that, based on execution by the processor, configure the physical computing device to perform actions comprising:

instantiating, by the physical computing device, a plurality of virtual machines that are communicatively coupled to a virtual switch;

processing, by the physical computing device, messages communicated between an application hosted by one of the plurality of virtual machines and another entity, the processing based on an identification of the application and on credentials associated with the messages, the processing comprising:

parsing, by the physical computing device, at least a portion of the messages at any layer of a protocol stack via which at least a portion of the messages are communicated between the application and the another entity, and

identifying, by the physical computing device, a request/reply pair in the parsed messages, where the identified request/reply pair is from a particular layer of the protocol stack; and

performing, by the physical computing device, an action based at least on one of the processed messages.

2. The physical computing device of claim 1 where the virtual switch is hosted on the physical computing device.

3. The physical computing device of claim 1 where the processing further comprises associating the messages with specific applications.

4. The physical computing device of claim 1 where the processing further comprises decrypting, based on the credentials, the identified request/reply pair.

5. The physical computing device of claim 4 where the credentials are provided for the decrypting by the one of the plurality of virtual machines.

6. A method performed on a physical computing device, the method comprising:

instantiating, by the physical computing device, a plurality of virtual machines that are communicatively coupled to a virtual switch;

processing, by the physical computing device, messages communicated between an application hosted by one of the plurality of virtual machines and another entity, the processing based on an identification of the application and on credentials associated with the messages, the processing comprising:

parsing, by the physical computing device, at least a portion of the messages at any layer of a protocol stack via which at least a portion of the messages are communicated between the application and the another entity, and

identifying, by the physical computing device, a request/reply pair in the parsed messages, where the identified request/reply pair is from a particular layer of the protocol stack; and

performing, by the physical computing device, an action based at least on one of the processed messages.

7. The method of claim 6 where the virtual switch is hosted on the physical computing device.

8. The method of claim 6 where the processing further comprises associating the messages with specific applications.

9. The method of claim 6 where the processing further comprises decrypting, based on the credentials, the identified request/reply pair.

10. The method device of claim 9 where the credentials are provided for the decrypting by the one of the plurality of virtual machines.

11. At least one hardware computer-readable storage device that includes computer-executable instructions that, based on execution by a physical computing device, configure the physical computing device to perform actions comprising:

instantiating, by the physical computing device, a plurality of virtual machines that are communicatively coupled to a virtual switch;

processing, by the physical computing device, messages communicated between an application hosted by one of the plurality of virtual machines and another entity, the processing based on an identification of the application and on credentials associated with the messages, the processing comprising:

parsing, by the physical computing device, at least a portion of the messages at any layer of a protocol stack via which at least a portion of the messages are communicated between the application and the another entity, and

identifying, by the physical computing device, a request/reply pair in the parsed messages, where the identified request/reply pair is from a particular layer of the protocol stack; and

performing, by the physical computing device, an action based at least on one of the processed messages.

12. The at least one hardware computer-readable storage device of claim 11 where the processing further comprises associating the messages with specific applications.

13. The at least one hardware computer-readable storage device of claim 11 where the processing further comprises decrypting, based on the credentials, the identified request/reply pair.

14. The at least one hardware computer-readable storage device of claim 13 where the credentials are provided for the decrypting by the one of the plurality of virtual machines.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 11, 2016
From: SANGHVI, ASHVIN; LETCA, ILARIE; COELHO, ALEXANDRE
To: MICROSOFT CORPORATION
Reel/Frame 037961/0276 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 11, 2016
From: MICROSOFT CORPORATION
To: MICROSOFT TECHNOLOGY LICENSING, LLC
Reel/Frame 037961/0287 →
Continuity (2)
Continuation 13025042 · Feb 10, 2011
Related Publication 20160170795A1 · Jun 16, 2016