System for virtual machine risk monitoring
US-2015067143-A1 · Mar 5, 2015 · US
US2016359847A1 · US · A1
| Field | Value |
|---|---|
| Publication number | US-2016359847-A1 |
| Application number | US-201615238682-A |
| Country | US |
| Kind code | A1 |
| Filing date | Aug 16, 2016 |
| Priority date | Dec 13, 2014 |
| Publication date | Dec 8, 2016 |
| Grant date | — |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A discovery bundle component is applied in a virtual image deployed within a virtual environment, wherein the discovery bundle automatically discovers asset information about one or more application bundles applied to the virtual image. The discovery bundle component sends, to a discovery product service, the asset information wrapped with a trusted signed certificate for the discovery product service, wherein the discovery product service is located outside the virtual environment.
Opening claim text (preview).
1 . A method, comprising: applying, using one or more processors, a discovery bundle component in a virtual image deployed within a virtual environment, wherein the discovery bundle component automatically discovers asset information about one or more application bundles applied to the virtual image, wherein the asset information comprises an application infrastructure the one or more application bundles applied to the virtual image that is secured and only discoverable within the virtual environment by providing a credential provided to the discovery bundle component by an authorized user; and sending, using the one or more processors, by the discovery bundle component, to a discovery product service, the asset information wrapped with a trusted signed certificate for the discovery product service, without sending the credential used to access the asset information to the discovery product service, wherein the discovery product service is located outside the virtual environment. 2 . The method according to claim 1 , further comprising: preconfiguring, using the one or more processors, the discovery bundle component with the trusted signed certificate of the discovery product service prior to applying the discovery bundle component in the virtual image deployed within the virtual environment, wherein the trusted signed certificate specifies a hostname and an internet protocol address of a host for the discovery product service. 3 . The method according to claim 1 , further comprising: prompting, using the one or more processors, a user to provide an access control list specifying the credential for accessing one or more assets of the virtual image on a deployed system hosting the virtual environment; in response to the user providing the access control list, storing, using the one or more processors, the access control list in a secured credential vault of the discovery bundle component; discovering, using the one or more processors, by the discovery bundle component, the asset information for a selection of at least one of the one or more application bundles applied to the virtual image, wherein the access control list comprises the credential required for accessing the selection of at least one of the one or more application bundles to discover the asset information; and sending, using the one or more processors, by the discovery bundle component, to a discovery product service, the asset information wrapped with a trusted signed certificate for the discovery product service, without sending the credential used to access the asset information to the discovery product service. 4 . The method according to claim 1 , wherein applying, using one or more processors, a discovery bundle component in a virtual image deployed within a virtual environment, wherein the discovery bundle component automatically discovers asset information about one or more application bundles applied to the virtual image further comprises: applying, using the one or more processors, the discovery bundle component in the virtual image deployed within the virtual environment, wherein the virtual environment comprises one of a virtual machine, a logical partition, and a workload partition. 5 . The method according to claim 1 , wherein applying, using one or more processors, a discovery bundle component in a virtual image deployed within a virtual environment, wherein the discovery bundle component automatically discovers asset information about one or more application bundles applied to the virtual image further comprises: configuring, using the one or more processors, within the discovery bundle component, the asset information that is discoverable by the discovery bundle component about a selection of the one or more application bundles wherein the discoverable asset information comprises at least one of operating system information, database information, and application server information, wherein the operating system information comprises at least one of file system information, device information, security settings, and operating system limits, wherein the database information comprises at least one of containers, log devices, cluster information, and tablespaces, wherein the application server information comprises at least one of message queues, cluster members, heap size, and connection pools. 6 . The method according to claim 1 , wherein sending, using the one or more processors, by the discovery bundle component, to a discovery product service, the asset information wrapped with a trusted signed certificate for the discovery product service, wherein the discovery product service is located outside the virtual environment further comprises: sending, using the one or more processors, by the discovery bundle component, the asset information in an initial discovery report to the discovery product within a first time period after the discovery bundle component is applied to the virtual image deployed in the virtual environment, wherein the discovery product verifies the trusted signed certificate and registers the virtual image based on the initial discovery report. 7 . The method according to claim 1 , wherein sending, using the one or more processors, by the discovery bundle component, to a discovery product service, the asset information wrapped with a trusted signed certificate for the discovery product service, wherein the discovery product service is located outside the virtual environment further comprises: in response to sending the asset information to the discovery product service, resetting and starting a delta timer using the one or more processors; in response to the delta timer expiring, discovering, using the one or more processors, whether there is at least one update to the asset information for the virtual image since the delta timer was reset; and sending, using the one or more processors, an updated discovery report indicating the virtual image is active and comprising the at least one update to the asset information. 8 . The method according to claim 1 , wherein applying, using one or more processors, a discovery bundle component in a virtual image deployed within a virtual environment, wherein the discovery bundle automatically discovers asset information about one or more application bundles applied to the virtual image further comprises: applying, using the one or more processors, the discovery bundle component in the virtual image deployed within the virtual environment on a deployed system connected within a cloud environment. 9 . A system, comprising: a processor, coupled with a memory, and configured to perform the actions of: applying a discovery bundle component in a virtual image deployed within a virtual environment, wherein the discovery bundle component automatically discovers asset information about one or more application bundles applied to the virtual image, wherein the asset information comprises an application infrastructure the one or more application bundles applied to the virtual image that is secured and only discoverable within the virtual environment by providing a credential provided to the discovery bundle component by an authorized user; and sending, by the discovery bundle component, to a discovery product service, the asset information wrapped with a trusted signed certificate for the discovery product service, without sending the credential used to access the asset information to the discovery product service, wherein the discovery product service is located outside the virtual environment. 10 . The system according to claim 9 , wherein the processor is further configured to perform the actions of: preconfiguring the discovery bundle component with the trusted signed certificate
Access control lists [ACL] · CPC title
when the policy decisions are valid for a limited amount of time · CPC title
using certificates (cryptographic mechanisms or cryptographic arrangements for entity authentication involving certificates H04L9/3263) · CPC title
Entity profiles · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.