IP Library Granted Patent US 9,912,783
Granted Patent B2
US 9,912,783 · App. 15/010,487 · Granted Mar 6, 2018

Securing internal services in a distributed environment

Inventor: Vikas Goel (Sunnyvale, CA)
Assignee: Veritas Technologies LLC
H04L67/42G06F21/54G06F21/629H04L63/0227H04L67/32
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,912,783
App. No.
15/010,487
Granted
Mar 6, 2018
Kind
B2
Abstract

Disclosed herein are methods, systems, and processes to secure internal services in a distributed environment. A service call initiated by a client process of a client is intercepted. In this example, the service call is a request for an internal service provided by a server deployed in a target appliance. The client is deployed in a source appliance. The service call includes an identifier, and the identifier identifies the internal service. If one or more rules are specified for the identifier, a service packet is generated by multiplexing client information associated with the client process as well as information in the service call. The service packet is forwarded to the target appliance.

Claims (95)

1. A method comprising:

intercepting a service call initiated by a client process of a client, wherein

the client is deployed in a source appliance,

the service call is a request for provision of an internal service by a server deployed in a target appliance,

the service call comprises an identifier, and

the identifier identifies the internal service;

determining whether one or more rules of a plurality of rules are specified for the identifier; and

in response to a determination that the one or more rules are specified for the identifier,

generating a service packet by multiplexing client information and information specified in the service call, and

forwarding the service packet to the target appliance.

2. The method of claim 1 , further comprising:

accessing source kernel memory of the source appliance; and

retrieving the client information from source kernel memory, wherein

the client information comprises one or more client process properties of a plurality of client process properties associated with the client process.

3. The method of claim 2 , further comprising:

intercepting the service packet forwarded to the target appliance;

demultiplexing the service packet to retrieve the client information;

processing one or more attributes of at least one rule using the client information; and

forwarding the service call to the server, if the processing indicates that the forwarding the service call is allowable.

4. The method of claim 3 , wherein

the plurality of client process properties comprise a user context, a user group context, a client program name, a parent process name, or a terminal type.

5. The method of claim 4 , wherein

each rule of the one or more rules comprises one or more attributes, and

each attribute of the one or more attributes corresponds to a client process property of the plurality of client process properties.

6. The method of claim 4 , further comprising:

forwarding the service call to the server if no rule is specified for the identifier.

7. The method of claim 4 , wherein

the processing comprises

determining whether each attribute of at least one rule matches a corresponding client process property.

8. The method of claim 7 , wherein

the one or more rules are part of a rule set,

the rule set is part of

a source service call filter module, and

a target service call filter module,

the source kernel comprises a multiplexing module that performs the multiplexing, and

the target kernel comprises a demultiplexing module that performs the demultiplexing.

9. The method of claim 8 , further comprising:

accessing the rule set to determine whether the internal service identified by the identifier is unprotected or protected.

10. The method of claim 9 , wherein

the internal service is protected if the rule set comprises at least one rule of the plurality of rules for the identifier specified in the service call, and

the internal service is unprotected if the rule set does not comprise at least one rule of the plurality of rules for the identifier specified in the service call.

11. A non-transitory computer readable storage medium storing program instructions executable to:

intercept a service call initiated by a client process of a client, wherein

the client is deployed in a source appliance,

the service call is a request for provision of an internal service by a server deployed in a target appliance,

the service call comprises an identifier, and

the identifier identifies the internal service;

determine whether one or more rules of a plurality of rules are specified for the identifier; and

in response to a determination that the one or more rules are specified for the identifier,

generate a service packet by multiplexing client information and information specified in the service call, and

forward the service packet to the target appliance.

12. The non-transitory computer readable storage medium of claim 11 , further comprising:

accessing source kernel memory of the source appliance; and

retrieving the client information from source kernel memory, wherein

the client information comprises one or more client process properties of a plurality of client process properties associated with the client process, and

the plurality of client process properties comprise a user context, a user group context, a client program name, a parent process name, or a terminal type.

13. The non-transitory computer readable storage medium of claim of claim 12 , further comprising:

intercepting the service packet forwarded to the target appliance;

demultiplexing the service packet to retrieve the client information;

processing one or more attributes of at least one rule using the client information; and

forwarding the service call to the server, if the processing indicates that the forwarding the service call is allowable.

14. The non-transitory computer readable storage medium of claim of claim 13 , wherein

each rule of the one or more rules comprises one or more attributes, and

each attribute of the one or more attributes corresponds to a client process property of the plurality of client process properties.

15. The non-transitory computer readable storage medium of claim of claim 14 , wherein

the processing comprises

determining whether each attribute of at least one rule matches a corresponding client process property.

16. A system comprising:

one or more processors; and

a memory coupled to the one or more processors, wherein the memory stores program instructions executable by the one or more processors to:

intercept a service call initiated by a client process of a client, wherein

the client is deployed in a source appliance,

the service call is a request for provision of an internal service by a server deployed in a target appliance,

the service call comprises an identifier, and

the identifier identifies the internal service;

determine whether one or more rules of a plurality of rules are specified for the identifier; and

in response to a determination that the one or more rules are specified for the identifier,

generate a service packet by multiplexing client information and information specified in the service call, and

forward the service packet to the target appliance.

17. The system of claim 16 , further comprising:

accessing source kernel memory of the source appliance; and

retrieving the client information from source kernel memory, wherein

the client information comprises one or more client process properties of a plurality of client process properties associated with the client process, and

the plurality of client process properties comprise a user context, a user group context, a client program name, a parent process name, or a terminal type.

18. The system of claim 17 , further comprising:

intercepting the service packet forwarded to the target appliance;

demultiplexing the service packet to retrieve the client information;

processing one or more attributes of at least one rule using the client information; and

forwarding the service call to the server, if the processing indicates that the forwarding the service call is allowable.

19. The system of claim of claim 18 , wherein

each rule of the one or more rules comprises one or more attributes, and

each attribute of the one or more attributes corresponds to a client process property of the plurality of client process properties.

20. The system of claim of claim 19 , wherein

the processing comprises

determining whether each attribute of at least one rule matches a corresponding client process property.

Assignments (11)
AMENDMENT NO. 1 TO PATENT SECURITY AGREEMENT Recorded Apr 8, 2025
From: VERITAS TECHNOLOGIES LLC; COHESITY, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 070779/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 26, 2025
From: VERITAS TECHNOLOGIES LLC
To: COHESITY, INC.
Reel/Frame 070335/0013 →
RELEASE OF SECURITY INTEREST Recorded Dec 13, 2024
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: VERITAS TECHNOLOGIES LLC
Reel/Frame 069634/0584 →
RELEASE OF SECURITY INTEREST Recorded Dec 13, 2024
From: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
To: VERITAS TECHNOLOGIES LLC
Reel/Frame 069632/0613 →
SECURITY INTEREST Recorded Dec 9, 2024
From: VERITAS TECHNOLOGIES LLC; COHESITY, INC.
To: JPMORGAN CHASE BANK. N.A.
Reel/Frame 069890/0001 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS AT R/F 052426/0001 Recorded Nov 30, 2020
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
To: VERITAS TECHNOLOGIES LLC
Reel/Frame 054535/0565 →
SECURITY INTEREST Recorded Aug 20, 2020
From: VERITAS TECHNOLOGIES LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 054370/0134 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Apr 16, 2020
From: VERITAS TECHNOLOGIES, LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 052426/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 12, 2017
From: SYMANTEC CORPORATION
To: VERITAS TECHNOLOGIES LLC
Reel/Frame 044362/0859 →
PATENT SECURITY AGREEMENT Recorded Nov 23, 2016
From: VERITAS TECHNOLOGIES LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 040679/0466 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 16, 2016
From: GOEL, VIKAS
To: SYMANTEC CORPORATION
Reel/Frame 037744/0435 →
Continuity (1)
Related Publication 20170223142A1 · Aug 3, 2017