IP Library Granted Patent US 10,437,683
Granted Patent B1
US 10,437,683 · App. 15/615,070 · Granted Oct 8, 2019

Systems and methods for protecting data affected by system changes

Inventors: Alex Kois (Tallinn, EE); Roman Vassiljev (Tallinn, EE)
Assignee: Symantec Corporation
G06F11/1451G06F11/1471G06F11/1446
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,437,683
App. No.
15/615,070
Granted
Oct 8, 2019
Kind
B1
Abstract

The disclosed computer-implemented method for protecting data affected by system changes may include (i) receiving, at an installation application, a request to perform a system change on an endpoint computing device, (ii) identifying, via the installation application, one or more data items currently installed on the endpoint computing device that will be modified when the system change is performed, (iii) using the installation application to protect the data items such that the system change becomes revertible, and (iv) after protecting the data items, using the installation application to perform the system change. Various other methods, systems, and computer-readable media are also disclosed.

Claims (67)

1. A computer-implemented method for protecting data affected by system changes, at least a portion of the method being performed by a computing device comprising at least one processor, the method comprising:

receiving, at an installation application, a request to perform a system change on an endpoint computing device;

identifying, via the installation application, one or more data items currently installed on the endpoint computing device that will be modified when the system change is performed by:

obtaining one or more packages to be installed as part of the system change;

identifying a list of data items contained in each of the one or more packages; and

determining, for each data item within the list of data items, whether the data item already exists on the endpoint computing device;

using the installation application to protect the currently installed data items such that the system change becomes revertible, wherein protecting the data items comprises creating, on the endpoint device, a container comprising a local backup of the currently installed data items; and

after protecting the currently installed data items, using the installation application to perform the system change.

2. The method of claim 1 , wherein the container further comprises at least one of:

a list of the currently installed data items; and

meta-information relating to the currently installed data items.

3. The method of claim 1 , wherein, after the installation application creates the container, a third-party backup system installed on the endpoint computing device includes the data items within the container in a general backup in response to obtaining the data items from the container.

4. The method of claim 1 , wherein the currently installed data items comprise at least one of:

a file;

a data block;

metadata; and

system data.

5. The method of claim 1 , wherein the request to perform the system change comprises a request to install at least one of:

new software; and

an update to existing software.

6. The method of claim 1 , wherein identifying the currently installed data items that will be modified when the system change is performed further comprises identifying an RPMDB file located in /var/lib/rpmdb/ based on a policy to always identify the RPMDB file when identifying data items that will be modified by a system change.

7. The method of claim 1 , further comprising:

installing the one or more packages using a dry-run operation that installs the one or more packages in dry-run mode, wherein the dry-run operation returns a list of one or more dependent packages;

identifying a list of data items contained in each of the one or more dependent packages; and

determining, for each data item within the list of data items contained in each of the one or more dependent packages, whether the data item already exists on the endpoint computing device.

8. The method of claim 1 , wherein identifying the currently installed data items that will be modified when the system change is performed comprises identifying a package installation scriptlet that identifies data items that will be affected by the system change.

9. The method of claim 1 , wherein, after the installation application performs the system change, a restoration process reverts the system change by copying each data item within the protected data items to its original location.

10. A system for protecting data affected by installation packages, the system comprising:

a receiving module, stored in memory, that receives, at an installation application, a request to perform a system change on an endpoint computing device;

an identification module, stored in memory, that identifies, via the installation application, one or more data items currently installed on the endpoint computing device that will be modified when the system change is performed by:

obtaining one or more packages to be installed as part of the system change;

identifying a list of data items contained in each of the one or more packages; and

determining, for each data item within the list of data items, whether the data item already exists on the endpoint computing device;

a protection module, stored in memory, that uses the installation application to protect the currently installed data items such that the system change becomes revertible, wherein protecting the data items comprises creating, on the endpoint device, a container comprising a local backup of the currently installed data items;

a change module, stored in memory, that, after the protection module protects the currently installed data items, uses the installation application to perform the system change; and

at least one physical processor configured to execute the receiving module, the identification module, the protection module, and the change module.

11. The system of claim 10 , wherein t container further comprises at least one of:

a list of the currently installed data items; and

meta-information relating to the currently installed data items.

12. The system of claim 10 , wherein, after the installation application creates the container, a third-party backup system installed on the endpoint computing device includes the data items within the container in a general backup in response to obtaining the data items from the container.

13. The system of claim 10 , wherein the currently installed data items comprise at least one of:

a file;

a data block;

metadata; and

system data.

14. The system of claim 10 , wherein the request to perform the system change comprises a request to install at least one of:

new software; and

an update to existing software.

15. The system of claim 10 , wherein the identification module additionally identifies the currently installed data items that will be modified when the system change is performed by identifying an RPMDB file located in /var/lib/rpmdb/ based on a policy to always identify the RPMDB file when identifying data items that will be modified by a system change.

16. The system of claim 10 , wherein the identification module identifies the currently installed data items that will be modified when the system change is performed by identifying a package installation scriptlet that identifies data items that will be affected by the system change.

17. The system of claim 10 , wherein, after the installation application performs the system change, a restoration process reverts the system change by copying each data item within the protected identified data items to its original location.

18. A non-transitory computer-readable medium comprising one or more computer-readable instructions that, when executed by at least one processor of a computing device, cause the computing device to:

receive, at an installation application, a request to perform a system change on an endpoint computing device;

identify, via the installation application, one or more data items currently installed on the endpoint computing device that will be modified when the system change is performed by:

obtaining one or more packages to be installed as part of the system change;

identifying a list of data items contained in each of the one or more packages; and

determining, for each data item within the list of data items, whether the data item already exists on the endpoint computing device;

use the installation application to protect the currently installed data items such that the system change becomes revertible, wherein protecting the data items comprises creating, on the endpoint device, a container comprising a local backup of the currently installed data items; and

after protecting the currently installed data items, use the installation application to perform the system change.

19. The non-transitory computer-readable medium of claim 18 , wherein the container further comprises at least one of:

a list of the currently installed data items; and

meta-information relating to the currently installed data items.

20. The non-transitory computer-readable medium of claim 18 , wherein the data items comprise at least one of:

a file;

a data block;

metadata; and

system data.

Assignments (2)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 21, 2019
From: SYMANTEC CORPORATION
To: CA, INC.
Reel/Frame 051144/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 6, 2017
From: KOIS, ALEX; VASSILJEV, ROMAN
To: SYMANTEC CORPORATION
Reel/Frame 042616/0103 →
Cited By (1)
US 12,367,402