IP Library Granted Patent US 11,593,491
Granted Patent B2
US 11,593,491 · App. 16/668,964 · Granted Feb 28, 2023

Identifying a software vulnerability

Inventor: Di Wu (Newark, CA)
Assignee: Rubrik, Inc.
G06F21/577G06F8/65G06F9/45558G06F16/128G06F2009/45591G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,593,491
App. No.
16/668,964
Granted
Feb 28, 2023
Kind
B2
Abstract

Systems and methods to identify a software vulnerability are described. The system receives a message identifying a software vulnerability. The system identifies snapshot images taken of a production machine and stored in a database. The snapshot images include a snapshot image including a virtual machine. The snapshot images are identified being based on the message. The system identifies whether the snapshot images include the software vulnerability. The system registers the software vulnerability in association with a snapshot image in the database responsive to the identification of the snapshot image of the virtual machine including the software vulnerability.

Claims (35)

1. A system comprising:

at least one processor and memory having instructions that, when executed, cause the at least one processor to perform operations, at a backup machine, comprising:

receiving a message identifying a software vulnerability the message including a vulnerability start time;

identifying a first plurality of snapshot images in a database, the first plurality of snapshot images being taken of a production machine and stored in the database, the first plurality of snapshot images including a first snapshot image taken of a first virtual machine, the identifying being based on a search window including a start time and an end time, the start time being computed based on the vulnerability start time and a parameter that is configurable;

identifying whether the first plurality of snapshot images includes the software vulnerability, the identifying including identifying whether the software vulnerability is included in the first virtual machine in the first snapshot image; and

registering the software vulnerability in association with the first snapshot image in the database responsive to the identifying the first snapshot image of the first virtual machine includes the software vulnerability.

2. The system of claim 1 , wherein the identifying the first plurality of snapshot images includes identifying the first plurality of snapshot images based on a timestamp associated with the software vulnerability.

3. The system of claim 1 , wherein the parameter that is configurable includes a period of time.

4. The system of claim 1 , wherein the registering the software vulnerability comprises:

storing a virtual machine identifier in association with a software vulnerability identifier in the database; and

pushing patch information to the first virtual machine in the production machine based on the software vulnerability.

5. The system of claim 4 , wherein the software vulnerability identifier identifies the software vulnerability and wherein the virtual machine identifier identifies the first virtual machine.

6. The system of claim 1 , wherein the message includes a software vulnerability identifier.

7. The system of claim 1 , wherein the software vulnerability includes a common vulnerability exposure.

8. The system of claim 1 , wherein the message further includes patch information for remediating the software vulnerability and further comprising pushing the patch information to the production machine based on the software vulnerability.

9. A method comprising:

receiving a message identifying a software vulnerability, the message including a vulnerability start time;

identifying a first plurality of snapshot images in a database, the first plurality of snapshot images being taken of a production machine and stored in the database, the first plurality of snapshot images including a first snapshot image taken of a first virtual machine, the identifying being based on a search window including a start time and an end time, the start time being computed based on the vulnerability start time and a parameter that is configurable:

identifying whether the first plurality of snapshot images includes the software vulnerability, the identifying including identifying whether the software vulnerability is included in the first virtual machine in the first snapshot image; and

registering the software vulnerability in association with the first snapshot image in the database responsive to the identifying the first snapshot image of the first virtual machine includes the software vulnerability.

10. The method of claim 9 , wherein the identifying the first plurality of snapshot images includes identifying the first plurality of snapshot images based on a timestamp associated with the software vulnerability.

11. The method of claim 9 , wherein the parameter that is configurable includes a period of time.

12. The method of claim 9 , wherein the registering the software vulnerability comprises:

storing a virtual machine identifier in association with a software vulnerability identifier in the database; and

pushing patch information to the first virtual machine in the production machine based on the software vulnerability.

13. The method of claim 12 , wherein the software vulnerability identifier identifies the software vulnerability and wherein the virtual machine identifier identifies the first virtual machine.

14. The method of claim 9 , wherein the message includes a software vulnerability identifier.

15. The method of claim 9 , wherein the software vulnerability includes a common vulnerability exposure.

16. The method of claim 9 , wherein the message further includes patch information for remediating the software vulnerability and further comprising pushing the patch information to the production machine based on the software vulnerability.

17. A non-transitory, machine-storage medium storing a set of instructions that, when executed by a processor, causes a machine to perform operations comprising:

receiving a message identifying a software vulnerability, the message including a vulnerability start time;

identifying a first plurality of snapshot images in a database, the first plurality of snapshot images being taken of a production machine and stored in the database, the first plurality of snapshot images including a first snapshot image taken of a first virtual machine, the identifying being based on a search window including a start time and an end time, the start time being computed based on the vulnerability start time and a parameter that is configurable;

identifying whether the first plurality of snapshot images includes the software vulnerability, the identifying including identifying whether the software vulnerability is included in the first virtual machine in the first snapshot image; and

registering the software vulnerability in association with the first snapshot image in the database responsive to the identifying the first snapshot image of the first virtual machine includes the software vulnerability.

18. The non-transitory, machine-storage medium of claim 17 , wherein the identifying the first plurality of snapshot images includes identifying the first plurality of snapshot images based on a timestamp associated with the software vulnerability.

Assignments (3)
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 60333/0323 Recorded Jun 13, 2025
From: GOLDMAN SACHS BDC, INC., AS COLLATERAL AGENT
To: RUBRIK, INC.
Reel/Frame 071565/0602 →
GRANT OF SECURITY INTEREST IN PATENT RIGHTS Recorded Jun 10, 2022
From: RUBRIK, INC.
To: GOLDMAN SACHS BDC, INC., AS COLLATERAL AGENT
Reel/Frame 060333/0323 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 18, 2020
From: WU, DI
To: RUBRIK, INC.
Reel/Frame 051840/0823 →
Cited By (1)
US 12,462,036