IP Library Granted Patent US 10,425,504
Granted Patent B1
US 10,425,504 · App. 15/911,519 · Granted Sep 24, 2019

Securing internal services in a distributed environment

Inventor: Vikas Goel (Sunnyvale, CA)
Assignee: Veritas Technologies LLC
H04L67/42G06F21/54G06F21/629H04L63/0227H04L67/32
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,425,504
App. No.
15/911,519
Granted
Sep 24, 2019
Kind
B1
Abstract

Disclosed herein are methods, systems, and processes to secure internal services in a distributed computing environment. A service packet that includes a service call from a source appliance is intercepted at a server. A determination is made that the service call is for an internal service provided by the source appliance and includes client information with client process properties. The service packet is demultiplexed. A determination is made that rule attributes associated with the internal service match the client process properties. The client information is removed from the service packet and the service call is forwarded to the server.

Claims (69)

1. A computer-implemented method comprising:

intercepting a service packet comprising a service call from a source appliance at a server;

determining that the service call is for an internal service provided by the source appliance;

determining that the service packet comprises client information with one or more client process properties;

demultiplexing the service packet;

determining that one or more rule attributes associated with the internal service match the one or more client process properties;

removing the client information from the service packet; and

forwarding the service call to the server.

2. The computer-implemented method of claim 1 , wherein

the client information is retrieved from source kernel memory of the source appliance.

3. The computer-implemented method of claim 2 , wherein

the one or more client process properties comprise a user context, a user group context, a client program name, a parent process name, or a terminal type.

4. The computer-implemented method of claim 1 , wherein

determining that the service packet comprises the client information with the one or more client process properties comprises determining whether at least one rule of one or more rules for the internal service is defined or specified in a rule set.

5. The computer-implemented method of claim 4 , wherein

each rule of the one or more rules comprises the one or more rule attributes, and

each rule attribute of the one or more rule attributes corresponds to a client process property of the one or more client process properties.

6. The computer-implemented method of claim 1 , wherein

the service call comprises an identifier, and

the identifier identifies the internal service.

7. The computer-implemented method of claim 4 , wherein

the internal service is protected if the rule set comprises at least one rule of the one or more rules for an identifier specified in the service call, and

the internal service is unprotected if the rule set does not comprise at least one rule of the one or more rules for the identifier specified in the service call.

8. A non-transitory computer readable storage medium storing program instructions executable to:

intercept a service packet comprising a service call from a source appliance at a server;

determine that the service call is for an internal service provided by the source appliance;

determine that the service packet comprises client information with one or more client process properties;

demultiplex the service packet;

determine that one or more rule attributes associated with the internal service match the one or more client process properties;

remove the client information from the service packet; and

forward the service call to the server.

9. The non-transitory computer readable storage medium of claim 8 , wherein the client information is retrieved from source kernel memory of the source appliance.

10. The non-transitory computer readable storage medium of claim 8 , wherein

the one or more client process properties comprise a user context, a user group context, a client program name, a parent process name, or a terminal type.

11. The non-transitory computer readable storage medium of claim 8 , wherein

determining that the service packet comprises the client information with the one or more client process properties comprises determining whether at least one rule of one or more rules for the internal service is defined or specified in a rule set.

12. The non-transitory computer readable storage medium of claim 11 , wherein

each rule of the one or more rules comprises the one or more rule attributes, and

each rule attribute of the one or more rule attributes corresponds to a client process property of the one or more client process properties.

13. The non-transitory computer readable storage medium of claim 8 , wherein

the service call comprises an identifier, and

the identifier identifies the internal service.

14. The non-transitory computer readable storage medium of claim 11 , wherein

the internal service is protected if the rule set comprises at least one rule of the one or more rules for an identifier specified in the service call, and

the internal service is unprotected if the rule set does not comprise at least one rule of the one or more rules for the identifier specified in the service call.

15. A system comprising:

one or more processors; and

a memory coupled to the one or more processors, wherein the memory stores program instructions executable by the one or more processors to:

intercept a service packet comprising a service call from a source appliance at a server;

determine that the service call is for an internal service provided by the source appliance;

determine that the service packet comprises client information with one or more client process properties;

demultiplex the service packet;

determine that one or more rule attributes associated with the internal service match the one or more client process properties;

remove the client information from the service packet; and

forward the service call to the server.

16. The system of claim 15 , wherein

the client information is retrieved from source kernel memory of the source appliance, and

the one or more client process properties comprise a user context, a user group context, a client program name, a parent process name, or a terminal type.

17. The system of claim 15 , wherein

determining that the service packet comprises the client information with the one or more client process properties comprises determining whether at least one rule of one or more rules for the internal service is defined or specified in a rule set.

18. The system of claim 17 , wherein

each rule of the one or more rules comprises the one or more rule attributes, and

each rule attribute of the one or more rule attributes corresponds to a client process property of the one or more client process properties.

19. The system of claim 15 , wherein

the service call comprises an identifier, and

the identifier identifies the internal service.

20. The system of claim 17 , wherein

the internal service is protected if the rule set comprises at least one rule of the one or more rules for an identifier specified in the service call, and

the internal service is unprotected if the rule set does not comprise at least one rule of the one or more rules for the identifier specified in the service call.

Assignments (10)
AMENDMENT NO. 1 TO PATENT SECURITY AGREEMENT Recorded Apr 8, 2025
From: VERITAS TECHNOLOGIES LLC; COHESITY, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 070779/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 26, 2025
From: VERITAS TECHNOLOGIES LLC
To: COHESITY, INC.
Reel/Frame 070335/0013 →
RELEASE OF SECURITY INTEREST Recorded Dec 16, 2024
From: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
To: VERITAS TECHNOLOGIES LLC
Reel/Frame 069697/0238 →
RELEASE OF SECURITY INTEREST Recorded Dec 13, 2024
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
To: VERITAS TECHNOLOGIES LLC
Reel/Frame 069634/0584 →
SECURITY INTEREST Recorded Dec 9, 2024
From: VERITAS TECHNOLOGIES LLC; COHESITY, INC.
To: JPMORGAN CHASE BANK. N.A.
Reel/Frame 069890/0001 →
ASSIGNMENT OF SECURITY INTEREST IN PATENT COLLATERAL Recorded Nov 25, 2024
From: BANK OF AMERICA, N.A., AS ASSIGNOR
To: ACQUIOM AGENCY SERVICES LLC, AS ASSIGNEE
Reel/Frame 069440/0084 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS AT R/F 052426/0001 Recorded Nov 30, 2020
From: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
To: VERITAS TECHNOLOGIES LLC
Reel/Frame 054535/0565 →
SECURITY INTEREST Recorded Aug 20, 2020
From: VERITAS TECHNOLOGIES LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 054370/0134 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Apr 16, 2020
From: VERITAS TECHNOLOGIES, LLC
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS COLLATERAL AGENT
Reel/Frame 052426/0001 →
PATENT SECURITY AGREEMENT SUPPLEMENT Recorded Mar 18, 2020
From: VERITAS TECHNOLOGIES LLC
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 052189/0311 →