IP Library Granted Patent US 12,346,455
Granted Patent B2
US 12,346,455 · App. 18/082,569 · Granted Jul 1, 2025

Security risk assessment system for a data management platform

Inventors: Argin Wong (San Francisco, CA); Brian Gyorkos (Fremont, CA)
Assignee: Rubrik, Inc.
G06F21/577G06F9/45558G06F2009/45587
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,346,455
App. No.
18/082,569
Granted
Jul 1, 2025
Kind
B2
Abstract

A virtual machine management system may support backup and recovery for virtual machines that support various applications. The virtual machine management system may process a backup snapshot of the virtual machine to identify security risks in the virtual machine. A cloud platform may communicate with the virtual machine management system to support backup processing. The cloud platform may identify security configuration information and transmit such information and transmit indications of the information to the virtual machine management system. The cloud platform may receive an indication of one or more security risks and generate notifications that indicate the security risks.

Claims (61)

1. A method for data management comprising:

identifying, at a cloud platform that is configured to manage a plurality of virtual machine management systems, security configuration information associated with virtual machines;

transmitting, to a virtual machine management system, an indication of the security configuration information that is configured for ingestion by the virtual machine management system, wherein the virtual machine management system uses the security configuration information in processing backup snapshots generated by virtual machines to identify security vulnerabilities;

receiving, from the virtual machine management system, an indication of one or more first security risks of a virtual machine managed by the virtual machine management system, wherein the one or more first security risks are identified by the virtual machine management system based on processing of one or more backup snapshots generated by the virtual machines and using the security configuration information;

receiving, from one or more additional virtual machine management systems, an indication of one or more second security risks of virtual machines managed by the one or more additional virtual machine management systems;

aggregating information associated with the one or more second security risks of virtual machines managed by the one or more additional virtual machine management systems with the one or more first security risks of the virtual machines managed by the virtual machine management system;

generating a notification that indicates the one or more first security risks and an identifier of the virtual machine; and

causing to display a user interface that includes the aggregated information.

2. The method of claim 1 , wherein the user interface indicates a number of virtual machines that are in compliance or out of compliance based at least in part on the one or more first security risks, a number of total security risks across virtual machines managed by the plurality of virtual machine management systems, or a combination thereof.

3. The method of claim 1 , further comprising:

receiving, from one or more of the plurality of virtual machine management systems, an indication of configuration information of corresponding virtual machines;

determining, using the configuration information, a set of common configurations that are supported by a plurality of virtual machines;

comparing the set of common configurations to configuration information associated with the virtual machine managed by the virtual machine management system; and

generating a notification that indicates a result of the comparing.

4. The method of claim 1 , wherein identifying the security configuration information comprises:

receiving one or more indications of current software versions of a set of software packages installed on a set of virtual machines supported by the plurality of virtual machine management systems.

5. The method of claim 1 , wherein identifying the security configuration information comprises:

receiving one or more indications of security vulnerabilities associated with a set of software packages installed on a set of virtual machines supported by the plurality of virtual machine management systems.

6. The method of claim 1 , wherein identifying the security configuration information comprises:

receiving one or more indications of recommended configuration parameters associated with a set of software packages installed on a set of virtual machines supported by the plurality of virtual machine management systems.

7. The method of claim 1 , wherein identifying the security configuration information comprises:

receiving, via the user interface, an indication of one or more target files of the virtual machines, an indication of one or more target configurations of the virtual machines, or both.

8. The method of claim 1 , wherein generating a notification comprises:

generating the notification that includes information about the one or more first security risks, a link to remediation of the one or more first security risks, or both.

9. An apparatus, comprising:

a processor;

memory coupled with the processor; and

instructions stored in the memory and executable by the processor to cause the apparatus to:

identify, at a cloud platform that is configured to manage a plurality of virtual machine management systems, security configuration information associated with virtual machines;

transmit, to a virtual machine management system, an indication of the security configuration information that is configured for ingestion by the virtual machine management system, wherein the virtual machine management system uses the security configuration information in processing backup snapshots generated by virtual machines to identify security vulnerabilities;

receive, from the virtual machine management system, an indication of one or more first security risks of a virtual machine managed by the virtual machine management system, wherein the one or more first security risks are identified by the virtual machine management system based on processing of one or more backup snapshots generated by the virtual machines and using the security configuration information;

receive, from one or more additional virtual machine management systems, an indication of one or more second security risks of virtual machines managed by the one or more additional virtual machine management systems;

aggregate information associated with the one or more second security risks of virtual machines managed by the one or more additional virtual machine management systems with the one or more first security risks of the virtual machines managed by the virtual machine management system;

generate a notification that indicates the one or more first security risks and an identifier of the virtual machine; and

cause to display a user interface that includes the aggregated information.

10. The apparatus of claim 9 , wherein the user interface indicates a number of virtual machines that are in compliance or out of compliance based at least in part on the one or more first security risks, a number of total security risks across virtual machines managed by the plurality of virtual machine management systems, or a combination thereof.

11. The apparatus of claim 9 , wherein the instructions are further executable by the processor to cause the apparatus to:

receive, from one or more of the plurality of virtual machine management systems, an indication of configuration information of corresponding virtual machines;

determine, using the configuration information, a set of common configurations that are supported by a plurality of virtual machines;

compare the set of common configurations to configuration information associated with the virtual machine managed by the virtual machine management system; and

generate a notification that indicates a result of the comparing.

12. The apparatus of claim 9 , wherein the instructions to identify the security configuration information are executable by the processor to cause the apparatus to:

receive one or more indications of current software versions of a set of software packages installed on a set of virtual machines supported by the plurality of virtual machine management systems.

13. The apparatus of claim 9 , wherein the instructions to identify the security configuration information are executable by the processor to cause the apparatus to:

receive one or more indications of security vulnerabilities associated with a set of software packages installed on a set of virtual machines supported by the plurality of virtual machine management systems.

14. A non-transitory computer-readable medium storing code, the code comprising instructions executable by a processor to:

identify, at a cloud platform that is configured to manage a plurality of virtual machine management systems, security configuration information associated with virtual machines;

transmit, to a virtual machine management system, an indication of the security configuration information that is configured for ingestion by the virtual machine management system, wherein the virtual machine management system uses the security configuration information in processing backup snapshots generated by virtual machines to identify security vulnerabilities;

receive, from the virtual machine management system, an indication of one or more first security risks of a virtual machine managed by the virtual machine management system, wherein the one or more first security risks are identified by the virtual machine management system based on processing of one or more backup snapshots generated by the virtual machines and using the security configuration information;

receive, from one or more additional virtual machine management systems, an indication of one or more second security risks of virtual machines managed by the one or more additional virtual machine management systems;

aggregate information associated with the one or more second security risks of virtual machines managed by the one or more additional virtual machine management systems with the one or more first security risks of the virtual machines managed by the virtual machine management system;

generate a notification that indicates the one or more first security risks and an identifier of the virtual machine; and

cause to display a user interface that includes the aggregated information.

15. The non-transitory computer-readable medium of claim 14 , wherein the user interface indicates a number of virtual machines that are in compliance or out of compliance based at least in part on the one or more first security risks, a number of total security risks across virtual machines managed by the plurality of virtual machine management systems, or a combination thereof.

16. The non-transitory computer-readable medium of claim 14 , wherein the instructions are further executable by the processor to:

receive, from one or more of the plurality of virtual machine management systems, an indication of configuration information of corresponding virtual machines;

determine, using the configuration information, a set of common configurations that are supported by a plurality of virtual machines;

compare the set of common configurations to configuration information associated with the virtual machine managed by the virtual machine management system; and

generate a notification that indicates a result of the comparing.

17. The non-transitory computer-readable medium of claim 14 , wherein the instructions to identify the security configuration information are executable by the processor to:

receive one or more indications of current software versions of a set of software packages installed on a set of virtual machines supported by the plurality of virtual machine management systems.

Assignments (3)
RELEASE OF SECURITY INTEREST IN PATENT COLLATERAL AT REEL/FRAME NO. 64659/0236 Recorded Jun 13, 2025
From: GOLDMAN SACHS BDC, INC., AS COLLATERAL AGENT
To: RUBRIK, INC.
Reel/Frame 071566/0187 →
GRANT OF SECURITY INTEREST IN PATENT RIGHTS Recorded Aug 21, 2023
From: RUBRIK, INC.
To: GOLDMAN SACHS BDC, INC., AS COLLATERAL AGENT
Reel/Frame 064659/0236 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 15, 2023
From: WONG, ARGIN; GYORKOS, BRIAN
To: RUBRIK, INC.
Reel/Frame 062713/0319 →
Continuity (2)
Provisional Application 63343875 · May 19, 2022
Related Publication 20230376608A1 · Nov 23, 2023
References Cited (4)
US 7437764B1 · Sobel · 2008 [cited by examiner]
US 20150256621A1 · Noda · 2015 [cited by examiner]
US 20170034023A1 · Nickolov · 2017 [cited by examiner]
US 20210136117A1 · Kuppannan · 2021 [cited by examiner]