IP Library Patent Application 17571433
Patent Application
App. No. 17/571,433

DATA CRITICALITY-BASED NETWORK POLICY CREATION AND CONSUMPTION

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
17/571,433
Abstract

Some embodiments of the invention provide a method of performing services on a host computer on which a machine executes. At a service engine executing on the host computer separately than the machine, the method receives a data message from the machine. The method determines that the data message is associated with a file (1) that is stored on the machine and (2) that stores confidential information. The method performs a service operation on the data message based on said determination.

Claims (36)

1 . A method of performing services on a host computer on which a machine executes, the method comprising:

at a service engine executing on the host computer separately than the machine:

receiving a data message from the machine;

determining that the data message is associated with a file (i) that is stored on the machine and (ii) that stores confidential information; and

performing a service operation on the data message based on said determination.

2 . The method of claim 1 , wherein said determining comprises:

receiving a service rule that includes a flow identifier of the data message and an indication that the flow identifier is associated with confidential information;

matching header values of the data message with the flow identifier included in the service rule;

using the indication to determine that the data message is associated with confidential information.

3 . The method of claim 2 , wherein receiving the service rule comprises receiving the service rule from a context engine that detects that the file stores confidential information and detects a network connection for a process that executes on the machine and that has accessed or is accessing the file.

4 . The method of claim 3 , wherein the context engine detects that the file stores confidential information and detects a network connection for a process that executes on the machine based on a set of data received by the context engine from a guest introspection (GI) agent that executes on the machine.

5 . The method of claim 1 , wherein the service engine is a firewall engine and the service operation comprises blocking the data message.

6 . The method of claim 5 , wherein the service operation is specified by a default service rule that instructs the firewall engine to allow data messages that are not associated with the file and to block data messages that are associated with the file.

7 . The method of claim 1 , wherein the service engine is a firewall engine and the service operation comprises a redirect operation that instructs the firewall engine to redirect data messages associated with the file to a deep packet inspector that performs deep packet inspection on data messages.

8 . The method of claim 7 , wherein the deep packet inspector performs deep packet inspection on data messages associated with files that store confidential data and does not perform deep packet inspection on data messages that are not associated with files that store confidential data.

9 . The method of claim 1 , wherein the service engine is an intrusion detection system (IDS) engine and the service operation comprises analyzing a payload of the data message to determine whether there is an attack, wherein when the IDS engine determines that there is an attack, the IDS engine sends an alert to an administrator identifying the attack.

10 . The method of claim 1 , wherein the service engine is an intrusion prevention system (IPS) engine and the service operation comprises one of logging the data message and dropping the data message.

11 . The method of claim 1 , wherein determining that the data message is associated with a file that is stored on the machine and that stores confidential information further comprises determining a confidentiality level specified for the confidential information, the confidentiality level comprising one of (i) high, (ii) medium, and (iii) low, wherein the service operation performed on the data message is based in part on the confidentiality level specified for the confidential information.

12 . A non-transitory machine readable medium storing a program for execution by one or more processing units of a host computer, the host computer executing at least one service engine and at least one machine that is separate from the service engine, the program for enabling the service engine to perform services on data messages sent by the machine, the program comprising sets of instructions for:

receiving a data message from the machine;

determining that the data message is associated with a file (i) that is stored on the machine and (ii) that stores confidential information; and

performing a service operation on the data message based on said determination.

13 . The non-transitory machine readable medium of claim 12 , wherein said determining comprises:

receiving a service rule that includes a flow identifier of the data message and an indication that the flow identifier is associated with confidential information;

matching header values of the data message with the flow identifier included in the service rule;

using the indication to determine that the data message is associated with confidential information.

14 . The non-transitory machine readable medium of claim 13 , wherein the set of instructions for receiving the service rule comprises a set of instructions for receiving the service rule from a context engine that detects that the file stores confidential information and detects a network connection for a process that executes on the machine and that has accessed or is accessing the file, said detections based on a set of data received by the context engine from a guest introspection (GI) agent that executes on the machine.

15 . The non-transitory machine readable medium of claim 12 , wherein the service engine is a firewall engine and the service operation comprises blocking the data message.

16 . The non-transitory machine readable medium of claim 15 , wherein the service operation is specified by a default service rule that instructs the firewall engine to allow data messages that are not associated with the file and to block data messages that are associated with the file.

17 . The non-transitory machine readable medium of claim 12 , wherein:

the service engine is a firewall engine;

the service operation comprises a redirect operation that instructs the firewall engine to redirect data messages associated with the file to a deep packet inspector that performs deep packet inspection on data messages; and

the deep packet inspector performs deep packet inspection on data messages associated with files that store confidential data and does not perform deep packet inspection on data messages that are not associated with files that store confidential data.

18 . The non-transitory machine readable medium of claim 12 , wherein the service engine is an intrusion detection system (IDS) engine and the service operation comprises analyzing a payload of the data message to determine whether there is an attack, wherein when the IDS engine determines that there is an attack, the IDS engine sends an alert to an administrator identifying the attack.

19 . The non-transitory machine readable medium of claim 12 , wherein the service engine is an intrusion prevention system (IPS) engine and the service operation comprises one of logging the data message and dropping the data message.

20 . The non-transitory machine readable medium of claim 12 , wherein the set of instructions for determining that the data message is associated with a file that is stored on the machine and that stores confidential information further comprises a set of instructions for determining a confidentiality level specified for the confidential information, the confidentiality level comprising one of (i) high, (ii) medium, and (iii) low, wherein the service operation performed on the data message is based in part on the confidentiality level specified for the confidential information.

Assignments (2)
CHANGE OF NAME Recorded Feb 27, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 066692/0103 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 7, 2022
From: GOPALAKRISHNAN, SRIRAM; GHATNEKAR, HRISHIKESH
To: VMWARE, INC.
Reel/Frame 060127/0758 →