IP Library Granted Patent US 11,604,876
Granted Patent B2
US 11,604,876 · App. 16/774,661 · Granted Mar 14, 2023

Malware protection for virtual machines

Inventors: Abhay Mitra (Santa Clara, CA); Vijay Karthik (Santa Clara, CA); Vivek Sanjay Jain (Palo Alto, CA); Avishek Ganguli (San Mateo, CA); Arohi Kumar (Palo Alto, CA); Kushaagra Goyal (Mountain View, CA); Christopher Wong (Mountain View, CA)
Assignee: Rubrik, Inc.
G06F21/564G06F9/45558G06F11/1469G06F21/85H04L9/0643G06F2009/45575G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,604,876
App. No.
16/774,661
Granted
Mar 14, 2023
Kind
B2
Abstract

A computer-implemented method at a data management system comprises: receiving, at a storage appliance from a server hosting a virtual machine, a write made to the virtual machine; computing, at the storage appliance, a fingerprint of the transmitted write; comparing, at the storage appliance, the computed fingerprint to malware fingerprints in a malware catalog; repeating the computing and comparing; and disabling the virtual machine if a number of matches from the comparing breaches a predetermined threshold over a predetermined amount of time.

Claims (36)

1. A data management system, comprising:

a storage appliance configured to store a snapshot of a virtual machine; and

one or more processors in communication with the storage appliance, the one or more processors configured to perform operations including:

receiving, at the storage appliance from a server hosting the virtual machine, a write made to the virtual machine;

computing, at the storage appliance, a fingerprint of the received write;

comparing, at the storage appliance, the computed fingerprint to malware fingerprints in a malware catalog while the virtual machine continues to receive writes;

repeating the computing and comparing for the continued received writes; and

disabling the virtual machine if a number of matches from the comparing breaches a predetermined threshold over a predetermined amount of time, the predetermined threshold greater than one.

2. The system of claim 1 , wherein the operations further include restoring the virtual machine using the snapshot stored in the storage appliance to a state before the predetermined threshold was breached.

3. The system of claim 1 , wherein the operations further include blocking writes from a source of the matches.

4. The system of claim 1 , wherein the operations further include generating the malware catalog including generating fingerprints of binaries and compressed binaries of known malware.

5. The system of claim 4 , wherein the fingerprints are computed at 4 kilobytes aligned offsets generated using SHA256.

6. The system of claim 1 , wherein the operations further include repeatedly generating snapshots of the virtual machine over time.

7. A computer-implemented method at a data management system, the method comprising:

receiving, at a storage appliance from a server hosting a virtual machine, a write made to the virtual machine;

computing, at the storage appliance, a fingerprint of the received write;

comparing, at the storage appliance, the computed fingerprint to malware fingerprints in a malware catalog while the virtual machine continues to receive writes;

repeating the computing and comparing for the continued received writes;

maintaining a log of the continued received writes; and

reversing the writes to revert the virtual machine per the maintained log if a number of matches from the comparing breaches a predetermined threshold over a predetermined amount of time.

8. The method of claim 7 , further comprising restoring the virtual machine using a snapshot stored in the storage appliance to a state before the predetermined threshold was breached.

9. The method of claim 7 , further comprising blocking writes from a source of the matches.

10. The method of claim 7 , further comprising generating the malware catalog including generating fingerprints of binaries and compressed binaries of known malware.

11. The method of claim 10 , wherein the fingerprints are computed at 4 kilobytes aligned offsets generated using SHA256.

12. The method of claim 7 , further comprising repeatedly generating snapshots of the virtual machine over time.

13. A non-transitory, machine-readable medium storing instructions which, when read by a storage appliance, cause the storage appliance to perform operations comprising, at least:

receiving, at the storage appliance from a server hosting a virtual machine, a write made to the virtual machine;

computing, at the storage appliance, a fingerprint of the received write;

comparing, at the storage appliance, the computed fingerprint to malware fingerprints in a malware catalog while the virtual machine continues to receive writes;

repeating the computing and comparing for the continued received writes; and

disabling the virtual machine if a number of matches from the comparing breaches a predetermined threshold over a predetermined amount of time, the predetermined threshold greater than one.

14. The machine-readable medium of claim 13 , wherein the operations further include restoring the virtual machine using a snapshot stored in the storage appliance to a state before the predetermined threshold was breached.

15. The machine-readable medium of claim 13 , wherein the operations further include blocking writes from a source of the matches.

16. The machine-readable medium of claim 13 , wherein the operations further include generating the malware catalog including generating fingerprints of binaries and compressed binaries of known malware.

17. The machine-readable medium of claim 16 , wherein the fingerprints are computed 4 kilobytes aligned offsets generated using SHA256.

18. The machine-readable medium of claim 13 , wherein the operations further include repeatedly generating snapshots of the virtual machine over time.

Assignments (3)
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 60333/0323 Recorded Jun 13, 2025
From: GOLDMAN SACHS BDC, INC., AS COLLATERAL AGENT
To: RUBRIK, INC.
Reel/Frame 071565/0602 →
GRANT OF SECURITY INTEREST IN PATENT RIGHTS Recorded Jun 10, 2022
From: RUBRIK, INC.
To: GOLDMAN SACHS BDC, INC., AS COLLATERAL AGENT
Reel/Frame 060333/0323 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jan 29, 2020
From: MITRA, ABHAY; KARTHIK, VIJAY; JAIN, VIVEK SANJAY; GANGULI, AVISHEK; KUMAR, AROHI; GOYAL, KUSHAAGRA; WONG, CHRISTOPHER
To: RUBRIK, INC.
Reel/Frame 051658/0913 →
Cited By (1)
US 12,406,061