IP Library Patent Application 17966807
Patent Application
App. No. 17/966,807

PREVENT NETWORK SPREAD OF MALWARE BY RESTRICTING IT TO ONE PATIENT ONLY

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
17/966,807
Abstract

Some embodiments provide a method of preventing network spread of malware files. At a first host computer, the method detects an attempt to establish a file-transfer connection between a first compute machine executing on the first host computer and a second compute machine executing on a second host computer, the file transfer connection for transferring a particular file stored by the first compute machine. The method delays establishment of the file-transfer connection in order to perform an analysis of the particular file to determine whether the particular file contains malware. When the file is determined to contain malware, the method prevents the file-transfer connection from being established between the first and the second compute machines to prevent the file from being transferred.

Claims (40)

1 . A method of preventing network spread of malware files, the method comprising:

at a first host computer:

detecting an attempt to establish a file-transfer connection between a first compute machine executing on the first host computer and a second compute machine executing on a second host computer, the file transfer connection for transferring a particular file stored by the first compute machine;

delaying establishment of the file-transfer connection in order to perform an analysis of the particular file to determine whether the particular file contains malware; and

when the file is determined to contain malware, preventing the file-transfer connection from being established between the first and the second compute machines to prevent the file from being transferred.

2 . The method of claim 1 , wherein detecting the attempt to establish the file-transfer connection comprises receiving, from a guest introspection (GI) agent executing on the first compute machine, a notification indicating the attempt to establish the file-transfer connection.

3 . The method of claim 1 , wherein the analysis comprises a sandboxing operation to open, monitor, and analyze the particular file in a secure, isolated environment.

4 . The method of claim 3 , wherein the sandboxing operation is a first sandboxing operation performed by a static analysis module executing within a container on the host computer, the method further comprising:

determining that the static analysis module is unable to identify whether the particular file contains malware; and

redirecting the particular file through a cloud connector proxy to a centralized cloud service that performs a second sandboxing operation to determine whether the file contain malware.

5 . The method of claim 4 , wherein:

the centralized cloud service includes a recordation service that stores a first plurality of profiles associated with a first plurality of files that contain malware and a second plurality of profiles associated with a second plurality of files that do not contain malware; and

upon determining whether the particular file contains malware, the centralized cloud service (i) creates a record for the particular file to be stored by the recordation service and (ii) distributes the determination to at least the first and second host computers.

6 . The method of claim 1 , wherein during the analysis of the particular file, the particular file cannot be (i) copied, (ii) moved, (iii) uploaded, or (iv) transferred across systems.

7 . The method of claim 1 , wherein the first and second host computers are a same host computer.

8 . The method of claim 1 , wherein the first host computer executes in a first datacenter and the second host computer executes in a second datacenter.

9 . The method of claim 1 , wherein the first and second host computers execute in a same datacenter.

10 . The method of claim 1 , wherein:

the first compute machine comprises one of a virtual machine, a container, and a pod; and

the second compute machine comprises one of a virtual machine, a container, and a pod.

11 . A non-transitory machine readable medium of a first host computer storing a program for execution by a set of processing units of the first host computer, the program for preventing network spread of malware files, the program comprising sets of instructions for:

detecting an attempt to establish a file-transfer connection between a first compute machine executing on the first host computer and a second compute machine executing on a second host computer, the file transfer connection for transferring a particular file stored by the first compute machine;

delaying establishment of the file-transfer connection in order to perform an analysis of the particular file to determine whether the particular file contains malware;

when the file is determined to contain malware, preventing the file-transfer connection from being established between the first and the second compute machines to prevent the file from being transferred; and

when the file is determined not to contain malware, allowing the file-transfer connection to be established between the first and second compute machines to transfer the file.

12 . The non-transitory machine readable medium of claim 11 , wherein the set of instructions for detecting the attempt to establish the file-transfer connection comprises a set of instruction for receiving, from a guest introspection (GI) agent executing on the first compute machine, a notification indicating the attempt to establish the file-transfer connection.

13 . The non-transitory machine readable medium of claim 11 , wherein the analysis comprises a sandboxing operation to open, monitor, and analyze the particular file in a secure, isolated environment.

14 . The non-transitory machine readable medium of claim 13 , wherein the sandboxing operation is a first sandboxing operation performed by a static analysis module executing within a container on the host computer, the program further comprising sets of instructions for:

determining that the static analysis module is unable to identify whether the particular file contains malware; and

redirecting the particular file through a cloud connector proxy to a centralized cloud service that performs a second sandboxing operation to determine whether the file contain malware.

15 . The non-transitory machine readable medium of claim 14 , wherein:

the centralized cloud service includes a recordation service that stores a first plurality of profiles associated with a first plurality of files that contain malware and a second plurality of profiles associated with a second plurality of files that do not contain malware; and

upon determining whether the particular file contains malware, the centralized cloud service (i) creates a record for the particular file to be stored by the recordation service and (ii) distributes the determination to at least the first and second host computers.

16 . The non-transitory machine readable medium of claim 11 , wherein during the analysis of the particular file, the particular file cannot be (i) copied, (ii) moved, (iii) uploaded, or (iv) transferred across systems.

17 . The non-transitory machine readable medium of claim 11 , wherein the first and second host computers are a same host computer.

18 . The non-transitory machine readable medium of claim 11 , wherein the first host computer executes in a first datacenter and the second host computer executes in a second datacenter.

19 . The non-transitory machine readable medium of claim 11 , wherein the first and second host computers execute in a same datacenter.

20 . The non-transitory machine readable medium of claim 11 , wherein:

the first compute machine comprises one of a virtual machine, a container, and a pod; and

the second compute machine comprises one of a virtual machine, a container, and a pod.

Assignments (2)
CHANGE OF NAME Recorded Feb 27, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 066692/0103 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Mar 24, 2023
From: GAMBHIR PAREKH, MANISHA SAMEER; GOKHALE, PRANAV NARAYAN; GOKHALE, ADITYA ANIL
To: VMWARE, INC.
Reel/Frame 063094/0305 →