IP Library Patent Application 16879387
Patent Application
App. No. 16/879,387

OPERATING A SECURITY ZONE ON AN AIR-GAPPED ENDPOINT

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
16/879,387
Abstract

A method for operating an air-gapped endpoint is provided. The method includes initializing, on the endpoint, a hypervisor for execution over a primitive operating system (OS) of the endpoint; creating an isolated security zone by instantiating a virtual machine using the hypervisor, wherein the security zone includes a plurality of applications executed over a guest OS; and auditing, by the hypervisor, any action performed by any application executed in the security zone.

Claims (41)

1 . A method for operating an air-gapped endpoint, comprising:

initializing, on the endpoint, a hypervisor for execution over a primitive operating system (OS) of the endpoint;

creating an isolated security zone by instantiating a virtual machine using the hypervisor, wherein the security zone includes a plurality of applications executed over a guest OS; and

auditing, by the hypervisor, any action performed by any application executed in the security zone.

2 . The method of claim 1 , wherein auditing any action performed by each of the plurality of applications executed in the security zone further comprises:

determining if execution of the guest OS and each application in the security zone maintain compliance with a security policy defined for the security zone.

3 . The method of claim 1 , wherein each security policy defines at least one of: a network policy, a user interface (UX) policy, a browsing policy, and a connectivity policy.

4 . The method of claim 3 , wherein the UX policy defines user interface actions allowed to be performed by the user in the security zone.

5 . The method of claim 3 , wherein the browsing policy defines a whitelist of uniform resource locators (URLs) or domain names that can be accessed from a browser executed in the security zone.

6 . The method of claim 3 , wherein the connectivity policy defines a set of allowed peripheral devices through any one of: a wired connection, and a wireless connection.

7 . The method of claim 3 , wherein the network policy defines, for each application in the corresponding activated security zone, at least one external network resource that is permitted to be accessed and an access type for the at least one external network resource.

8 . The method of claim 1 , further comprising:

enforcing the security policy of a corresponding security zone of the plurality of security zone.

9 . The method of claim 1 , wherein enforcing the security policy further comprises at least one of: disabling any change settings in the guest OS, hiding the file system of the operating system running in the virtual machine, disabling any system configurations, and applying a network access control.

10 . The method of claim 1 , further comprising:

generating a report indicating the auditing activity.

11 . A non-transitory computer readable medium having stored thereon instructions for causing a processing circuitry to execute a process for operating an air-gapped endpoint, the process comprising:

method for operating an air-gapped endpoint, comprising:

initializing, on the endpoint, a hypervisor for execution over a primitive operating system (OS) of the endpoint;

creating an isolated security zone by instantiating a virtual machine using the hypervisor, wherein the security zone includes a plurality of applications executed over a guest OS; and

auditing, by the hypervisor, any action performed by any application executed in the security zone.

12 . An air-gapped computing system, comprising:

a network card interface;

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

initialize, on the endpoint, a hypervisor for execution over a primitive operating system (OS) of the endpoint;

create an isolated security zone by instantiating a virtual machine using the hypervisor, wherein the security zone includes a plurality of applications executed over a guest OS; and

audit, by the hypervisor, any action performed by any application executed in the security zone.

13 . The air-gapped computing system of claim 12 , wherein auditing any action performed by each of the plurality of applications executed in the security zone further comprises:

determine if execution of the guest OS and each application in the security zone maintain compliance with a security policy defined for the security zone.

14 . The air-gapped computing system of claim 12 , wherein each security policy defines at least one of: a network policy, a user interface (UX) policy, a browsing policy, and a connectivity policy.

15 . The air-gapped computing system of claim 14 , wherein the UX policy defines user interface actions allowed to be performed by the user in the security zone.

16 . The air-gapped computing system of claim 14 , wherein the browsing policy defines a whitelist of uniform resource locators (URLs) or domain names that can be accessed from a browser executed in the security zone.

17 . The air-gapped computing system of claim 14 , wherein the connectivity policy defines a set of allowed peripheral devices through any one of: a wired connection, and a wireless connection.

18 . The air-gapped computing system of claim 14 , wherein the network policy defines, for each application in the corresponding activated security zone, at least one external network resource that is permitted to be accessed and an access type for the at least one external network resource.

19 . The air-gapped computing system of claim 12 , wherein the system is further configured to:

enforce the security policy of a corresponding security zone of the plurality of security zone.

20 . The air-gapped computing system of claim 12 , wherein the system is further configured to perform any one of:

disable any change settings in the guest OS, hiding the file system of the operating system running in the virtual machine, disabling any system configurations, and applying a network access control.

21 . The air-gapped computing system of claim 12 , wherein the system is further configured to perform any one of:

generate a report indicating the auditing activity.

Assignments (3)
SECURITY INTEREST Recorded Mar 26, 2023
From: PERCEPTION POINT LTD
To: KREOS CAPITAL VII AGGREGATOR SCSP
Reel/Frame 063103/0450 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 28, 2022
From: HYSOLATE LTD.
To: PERCEPTION POINT LTD.
Reel/Frame 060958/0747 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 20, 2020
From: ZAMIR, TAL; ZLOTNIK, OLEG; FIGOVSKY, BORIS; ADLER, NIR
To: HYSOLATE LTD.
Reel/Frame 052716/0103 →