IP Library Granted Patent US 8,418,173
Granted Patent B2
US 8,418,173 · App. 11/945,549 · Granted Apr 9, 2013

Locating an unauthorized virtual machine and bypassing locator code by adjusting a boot pointer of a managed virtual machine in authorized environment

Inventors: Joseph Fitzgerald (Franklin Lakes, NJ); Oleg Barenboim (Fort Lee, NJ); Richard Oliveri (Warren, NJ)
Assignee: ManageIQ, Inc.
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,418,173
App. No.
11/945,549
Granted
Apr 9, 2013
Kind
B2
Abstract

Methods and apparatus of locating an unauthorized virtual machine are disclosed. A virtual machine is registered with a management system. When the virtual machine is requested to start, the system determines whether the virtual machine is in an authorized environment. In an authorized environment, the virtual machine is enabled to operate normally. In an unauthorized environment, the virtual machine is disabled. The disabled virtual machine gathers information about the unauthorized environment and transmits the information to the virtual machine owner.

Claims (30)

1. A method for detecting an unauthorized use of a virtual machine, the method comprising:

storing a virtual machine on a physical machine at a first time, the virtual machine including a boot pointer, the boot pointer pointing to a locator code;

booting the virtual machine at a second time after the first time;

bypassing the locator code, at a third time after the second time, by adjusting the boot pointer to point from the locator code to a boot code of the virtual machine if the virtual machine is in an authorized environment, which exists when the physical machine and the virtual machine are both registered with a management system and associated with each other by the management system, which manages at least one physical machine and at least one virtual machine; and

executing the locator code, at a fourth time after the second time, if the virtual machine is in an unauthorized environment, which exists when the virtual machine is not in an authorized environment, wherein the locator code gathers information indicative of a location of the unauthorized environment, and transmits a message including the information indicative of the location.

2. The method of claim 1 , wherein the physical machine includes a management layer, wherein the management layer determines whether to enable the virtual machine in response to a request to start the virtual machine.

3. The method of claim 1 , wherein the physical machine includes a virtualization subsystem, the virtualization subsystem supporting a plurality of virtual machines.

4. The method of claim 1 , wherein the physical machine includes a management agent, wherein the management agent adjusts the boot pointer of the virtual machine.

5. The method of claim 1 , wherein the authorized environment includes a first managed physical machine, which is registered with the management system, and a first managed virtual machine, which is registered with the management system.

6. The method of claim 5 , wherein the first managed physical machine and the first managed virtual machine are associated with each other to create the authorized environment.

7. The method of claim 1 , wherein the unauthorized environment includes a first managed physical machine, which is registered with the management system, and first unmanaged virtual machine, which is not registered with the management system.

8. The method of claim 1 , wherein the unauthorized environment includes a first unmanaged physical machine, which is not registered with the management system, and a managed virtual machine, which is registered with the management system.

9. The method of claim 1 , wherein the unauthorized environment includes a first managed physical machine, which is registered with the management system, and a first managed virtual machine, which is registered with the management system, wherein the first managed physical machine and the first managed virtual machine are not associated with each other to create the authorized environment.

10. The method of claim 1 , wherein the information indicative of the location of the unauthorized environment includes an IP address associated with the physical machine.

11. The method of claim 1 , wherein the message including the information indicative of the location is transmitted via an internet.

12. The method of claim 1 , wherein the virtual machine shuts down after the message including the information indicative of the location has been transmitted.

13. An apparatus for detecting an unauthorized use of a virtual machine, the apparatus comprising:

a physical machine;

the physical machine storing a virtual machine;

at least one of the physical machine and the virtual machine storing a software program to cause the virtual machine to:

point a boot pointer of the virtual machine to a locator code at a first time;

boot the virtual machine at a second time after the first time;

bypass the locator code, at a third time after the second time, by adjusting the boot pointer from pointing to the locator code to point to a boot code of the virtual machine if the virtual machine is in an authorized environment, which exists when the physical machine and the virtual machine are both registered with a management system and associated with each other by the management system, which manages at least one physical machine and at least one virtual machine; and

execute the locator code, at a fourth time after the second time, if the virtual machine is in an unauthorized environment, which exists when the virtual machine is not in an authorized environment, wherein the locator code gathers information indicative of a location of the unauthorized environment, and transmits a message including the information indicative of the location.

14. A non-transitory computer readable media storing software instructions to detect an unauthorized use of a virtual machine, the software instructions causing a computing device to:

store a virtual machine on a physical machine at a first time, the virtual machine including a boot pointer;

point the boot pointer to a locator code;

boot the virtual machine at a second time after the first time;

bypass the locator code, at a third time after the second time, by adjusting the boot pointer from pointing to the locator code to point to a boot code of the virtual machine if the virtual machine is in an authorized environment, which exists when the physical machine and the virtual machine are both registered with a management system and associated with each other by the management system, which manages at least one physical machine and at least one virtual machine; and

execute the locator code, at a fourth time after the second time, if the virtual machine is in an unauthorized environment, which exists when the virtual machine is not in an authorized environment, wherein the locator code gathers information indicative of a location of the unauthorized environment, and transmits a message including the information indicative of the location.

Assignments (2)
MERGER Recorded Apr 5, 2018
From: MANAGEIQ, INC.
To: RED HAT, INC.
Reel/Frame 045445/0665 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 18, 2008
From: FITZGERALD, JOSEPH J.; BARENBOIM, OLEG; OLIVERI, RICHARD
To: MANAGEIQ, INC.
Reel/Frame 020522/0387 →
Continuity (1)
Related Publication 20090138877A1 · May 28, 2009