IP Library Granted Patent US 11,030,057
Granted Patent B2
US 11,030,057 · App. 16/028,679 · Granted Jun 8, 2021

System and method for critical virtual machine protection

Inventors: Shelesh Chopra (Bangalore, IN); Sunil Yadav (Bangalore, IN); Manish Sharma (Bangalore, IN)
Assignee: EMC IP Holding Company LLC
G06F11/1464G06F9/45558G06F11/1469H04L63/20G06F2009/45583G06F2009/45587G06F2201/815
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,030,057
App. No.
16/028,679
Granted
Jun 8, 2021
Kind
B2
Abstract

A backup agent for facilitating restorations of virtual machines includes a persistent storage and a backup/restoration policy updater. The persistent storage stores backup/restoration policies. The backup/restoration policy updater identifies a change of a label associated with data of a production host and, in response to identifying change in the label, identifies a virtual machine of the virtual machines associated with the data; performs a threat analysis of the identified virtual machine to determine a new security policy for the identified virtual machine; and updates a policy of the backup/restoration policies associated with the identified virtual machine based on the identified new security policy.

Claims (41)

1. A backup agent for facilitating restorations of virtual machines, comprising:

a persistent storage that stores backup/restoration policies; and

a backup/restoration policy updater programmed to:

identify a change of a label associated with a portion of data of a production host, wherein the label specifies a characteristic ascribed to the data by a client that utilizes services provided by a virtual machine of the virtual machines, wherein the characteristic indicates a level of importance of the portion of the data to the client;

in response to identifying the change in the label:

perform a threat analysis, using the changed label, of a virtual machine of the virtual machines to determine a new security policy for the virtual machine; and

update a policy of the backup/restoration policies associated with the virtual machine based on the new security policy,

wherein the updated policy specifies that a first quantity of computing resources are to be used to generate a backup of the portion of the data, the policy specifies that a second quantity of the computing resource are to be used to generate the backup of the portion of the data, and the first quantity is different from the second quantity.

2. The backup agent of claim 1 , wherein the backup/restoration policy updater is further programmed to:

perform a backup of the virtual machine using the updated policy to store a backup of the virtual machine in a backup storage of a plurality of backup storages.

3. The backup agent of claim 1 , wherein the backup/restoration policy updater is further programmed to:

perform a restoration of the virtual machine using the updated policy to restore the virtual machine.

4. The backup agent of claim 1 , wherein performing the threat analysis of the virtual machine to determine the new security policy for the virtual machine comprises:

obtaining a new virtual machine tag for the virtual machine based on the change of the label associated with the data of the production host.

5. The backup agent of claim 1 , wherein the portion of the data is a file-system block, wherein a second file-system block is labeled with a second label ascribing a second characteristic by the client that is different from the characteristic.

6. The backup agent of claim 1 , wherein the first quantity of computing resources is based on level of importance of the portion of the data to the client.

7. The backup agent of claim 1 , wherein performing the threat analysis also uses a second label associated with the portion of data to determine the new security policy.

8. The backup agent of claim 2 , wherein the updated policy specifies a first number of users that are credentialed to initiate performance of the backup, the policy specifies a second number of users that are credentialed to initiate performance of the backup, and the first number is smaller than the second number.

9. The backup agent of claim 2 , wherein the updated policy specifies a first number of target storage locations for storage of the backup, the policy specifies a second number of storage locations for storage of the backup, and the first number is smaller than the second number.

10. The backup agent of claim 3 , wherein performing the restoration of the virtual machine returns the virtual machine to a prior state.

11. The backup agent of claim 4 , wherein the label associated with the data of the production host is set by a user of the client of the virtual machine.

12. The backup agent of claim 4 , wherein performing the threat analysis of the virtual machine to determine the new security policy for the virtual machine further comprises:

obtaining a new security classification for the virtual machine based on the obtained new virtual machine tag.

13. The backup agent of claim 12 , wherein performing the threat analysis of the virtual machine to determine the new security policy for the virtual machine further comprises:

identifying a security policy corresponding to the obtained new security classification.

14. The backup agent of claim 13 , wherein the security policy specifies a limited set of users authorized to initiate performance of a restoration of the virtual machine.

15. The backup agent of claim 7 , wherein performing the threat analysis also uses a third label associated with the portion of data to determine the new security policy, wherein the third label is ascribed by a second client.

16. A method for facilitating restorations of virtual machines using backup/restoration policies, comprising:

identifying a change of a label associated with a portion of data of a production host that hosts at least one virtual machine of the virtual machines, wherein the label specifies a characteristic ascribed to the data by a client that utilizes services provided by the virtual machine of the virtual machines, wherein the characteristic indicates a level of importance of the portion of the data to the client;

in response to identifying the change in the label:

performing a threat analysis, using the changed label, of a virtual machine of the virtual machines associated with the portion of data to determine a new security policy for the virtual machine; and

updating a policy of the backup/restoration policies associated with the virtual machine based on the new security policy,

wherein the updated policy specifies that a first quantity of computing resources are to be used to generate a backup of the portion of the data, the policy specifies that a second quantity of the computing resource are to be used to generate the backup of the portion of the data, and the first quantity is different from the second quantity.

17. The method of claim 16 , wherein performing the threat analysis also uses a second label associated with the portion of data to determine the new security policy.

18. A non-transitory computer readable medium comprising computer readable program code, which when executed by a computer processor enables the computer processor to perform a method for facilitating restorations of virtual, the method comprising:

identifying a change of a label associated with a portion of data of a production host that hosts at least one virtual machine of the virtual machines, wherein the label specifies a characteristic ascribed to the data by a client that utilizes services provided by the virtual machine of the virtual machines, wherein the characteristic indicates a level of importance of the portion of the data to the client;

in response to identifying the change in the label:

performing a threat analysis, using the changed label, of a virtual machine of the virtual machines associated with the data to determine a new security policy for the virtual machine; and

updating a policy of the backup/restoration policies associated with the virtual machine based on the new security policy,

wherein the updated policy specifies that a first quantity of computing resources are to be used to generate a backup of the portion of the data, the policy specifies that a second quantity of the computing resource are to be used to generate the backup of the portion of the data, and the first quantity is different from the second quantity.

19. The non-transitory computer readable medium of claim 18 , wherein performing the threat analysis also uses a second label associated with the portion of data to determine the new security policy.

Assignments (8)
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (053546/0001) Recorded Jun 23, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL MARKETING L.P. (ON BEHALF OF ITSELF AND AS SUCCESSOR-IN-INTEREST TO CREDANT TECHNOLOGIES, INC.); DELL INTERNATIONAL L.L.C.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; DELL MARKETING CORPORATION (SUCCESSOR-IN-INTEREST TO FORCE10 NETWORKS, INC. AND WYSE TECHNOLOGY L.L.C.); EMC IP HOLDING COMPANY LLC
Reel/Frame 071642/0001 →
RELEASE OF SECURITY INTEREST IN PATENTS PREVIOUSLY RECORDED AT REEL/FRAME (047648/0422) Recorded May 20, 2022
From: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS NOTES COLLATERAL AGENT
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 060160/0862 →
RELEASE OF SECURITY INTEREST AT REEL 047648 FRAME 0346 Recorded Nov 2, 2021
From: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH
To: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
Reel/Frame 058298/0510 →
SECURITY AGREEMENT Recorded Apr 22, 2020
From: CREDANT TECHNOLOGIES INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 053546/0001 →
SECURITY AGREEMENT Recorded Mar 21, 2019
From: CREDANT TECHNOLOGIES, INC.; DELL INTERNATIONAL L.L.C.; DELL MARKETING L.P.; DELL PRODUCTS L.P.; DELL USA L.P.; EMC CORPORATION; FORCE10 NETWORKS, INC.; WYSE TECHNOLOGY L.L.C.; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A.
Reel/Frame 049452/0223 →
PATENT SECURITY AGREEMENT (CREDIT) Recorded Oct 12, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: CREDIT SUISSE AG, CAYMAN ISLANDS BRANCH, AS COLLATERAL AGENT
Reel/Frame 047648/0346 →
PATENT SECURITY AGREEMENT (NOTES) Recorded Oct 12, 2018
From: DELL PRODUCTS L.P.; EMC CORPORATION; EMC IP HOLDING COMPANY LLC
To: THE BANK OF NEW YORK MELLON TRUST COMPANY, N.A., AS COLLATERAL AGENT
Reel/Frame 047648/0422 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 6, 2018
From: CHOPRA, SHELESH; YADAV, SUNIL; SHARMA, MANISH
To: EMC IP HOLDING COMPANY LLC
Reel/Frame 046283/0612 →