System and method for critical virtual machine protection

US2020012572A1 · US · A1

Patent metadata
FieldValue
Publication numberUS-2020012572-A1
Application numberUS-201816028679-A
CountryUS
Kind codeA1
Filing dateJul 6, 2018
Priority dateJul 6, 2018
Publication dateJan 9, 2020
Grant date

How to read this patent

A practical reading order for non-experts. Skip the full description unless you need deep technical detail.

  1. Title

    What the patent document calls the invention.

  2. Abstract

    A short plain-language summary of the technical disclosure.

  3. Assignees and inventors

    Who owns or filed the patent and who is credited as inventor.

  4. Key dates

    Filing, priority, publication, and grant dates set the timeline.

  5. First independent claim

    The legal scope of protection — read this for what is actually claimed.

  6. CPC / IPC classifications

    Technology tags used to group this patent with similar filings.

  7. Citations and related patents

    Prior art links and similar publications in this corpus.

Abstract

Official abstract text for this publication.

A backup agent for facilitating restorations of virtual machines includes a persistent storage and a backup/restoration policy updater. The persistent storage stores backup/restoration policies. The backup/restoration policy updater identifies a change of a label associated with data of a production host and, in response to identifying change in the label, identifies a virtual machine of the virtual machines associated with the data; performs a threat analysis of the identified virtual machine to determine a new security policy for the identified virtual machine; and updates a policy of the backup/restoration policies associated with the identified virtual machine based on the identified new security policy.

First claim

Opening claim text (preview).

What is claimed is: 1 . A backup agent for facilitating restorations of virtual machines, comprising: a persistent storage that stores backup/restoration policies; and a backup/restoration policy updater programmed to: identify a change of a label associated with data of a production host; in response to identifying change in the label: identify a virtual machine of the virtual machines associated with the data; perform a threat analysis of the identified virtual machine to determine a new security policy for the identified virtual machine; and update a policy of the backup/restoration policies associated with the identified virtual machine based on the identified new security policy. 2 . The backup agent of claim 1 , wherein the backup/restoration policy updater is further programmed to: perform a backup of the identified virtual machine using the updated policy to store a backup of the identified virtual machine in a backup storage of a plurality of backup storages. 3 . The backup agent of claim 2 , wherein the updated policy specifies a first number of users that are credentialed to initiate performance of the backup, the policy specifies a second number of users that are credentialed to initiate performance of the backup, and the first number is smaller than the second number. 4 . The backup agent of claim 2 , wherein the updated policy specifies a first number of target storage locations for storage of the backup, the policy specifies a second number of storage locations for storage of the backup, and the first number is smaller than the second number. 5 . The backup agent of claim 1 , wherein the backup/restoration policy updater is further programmed to: perform a restoration of the identified virtual machine using the updated policy to restore the identified virtual machine. 6 . The backup agent of claim 5 , wherein performing the restoration of the identified virtual machine returns the identified virtual machine to a prior state. 7 . The backup agent of claim 1 , wherein performing the threat analysis of the identified virtual machine to determine the new security policy for the identified virtual machine comprises: obtaining a new virtual machine tag for the identified virtual machine based on the change of the label associated with the data of the production host. 8 . The backup agent of claim 7 , wherein the label associated with the data of the production host is set by a user of the identified virtual machine. 9 . The backup agent of claim 7 , wherein the label associated with the data of the production host is based on an importance of the data to a user of the identified virtual machine. 10 . The backup agent of claim 7 , wherein performing the threat analysis of the identified virtual machine to determine the new security policy for the identified virtual machine further comprises: obtaining a new security classification for the identified virtual machine based on the obtained new virtual machine tag. 11 . The backup agent of claim 10 , wherein performing the threat analysis of the identified virtual machine to determine the new security policy for the identified virtual machine further comprises: identifying a security policy corresponding to the obtained new security classification. 12 . The backup agent of claim 11 , wherein the identified security policy specifies a limited set of users authorized to initiate performance of a restoration of the identified virtual machine. 13 . The backup agent of claim 11 , wherein the identified security policy specifies a limited set of users authorized to initiate performance of a backup to obtain a backup of the identified virtual machine. 14 . The backup agent of claim 13 , wherein the identified security policy further specifies a second limited set of storage locations where the backup of the identified virtual machine may be stored. 15 . The backup agent of claim 13 , wherein the identified security policy further specifies a third limited set of backup types of the backup of the identified virtual machine. 16 . The backup agent of claim 1 , wherein each policy of the backup/restoration policies comprises a respective security policy for performing a backup or restoration workflow. 17 . A method for facilitating restorations of virtual machines, comprising: identifying a change of a label associated with data of a production host that hosts at least one virtual machine of the virtual machines; in response to identifying change in the label: identifying a virtual machine of the virtual machines associated with the data; performing a threat analysis of the identified virtual machine to determine a new security policy for the identified virtual machine, wherein performing the threat analysis comprises applying a second tag to a virtual machine based on the change of the label associated with the data of the production host; and updating a policy of backup/restoration policies associated with the identified virtual machine based on the identified new security policy. 18 . The method of claim 17 , wherein each policy of the backup/restoration policies comprises a respective security policy for performing a backup or restoration workflow. 19 . A non-transitory computer readable medium comprising computer readable program code, which when executed by a computer processor enables the computer processor to perform a method for facilitating restorations of virtual machines, the method comprising: identifying a change of a label associated with data of a production host that hosts at least one virtual machine of the virtual machines; in response to identifying change in the label: identifying a virtual machine of the virtual machines associated with the data; performing a threat analysis of the identified virtual machine to determine a new security policy for the identified virtual machine; and updating a policy of backup/restoration policies associated with the identified virtual machine based on the identified new security policy. 20 . The non-transitory computer readable medium of claim 19 , wherein each policy of the backup/restoration policies comprises a respective security policy for performing a backup or restoration workflow.

Assignees

Inventors

Classifications

  • Program or device authentication · CPC title

  • Protecting data · CPC title

  • for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title

  • Vulnerability analysis · CPC title

  • Backup restoration techniques · CPC title

Patent family

Related publications grouped by family.

External sources

Frequently asked questions

Answers are generated from the same data shown on this page.

What does patent US2020012572A1 cover?
A backup agent for facilitating restorations of virtual machines includes a persistent storage and a backup/restoration policy updater. The persistent storage stores backup/restoration policies. The backup/restoration policy updater identifies a change of a label associated with data of a production host and, in response to identifying change in the label, identifies a virtual machine of the vi…
Who is the assignee on this patent?
Emc Ip Holding Co Llc
What technology area does this patent fall under?
Primary CPC classification G06F11/1464. Mapped technology areas include Physics.
When was this patent published?
Publication date Thu Jan 09 2020 00:00:00 GMT+0000 (Coordinated Universal Time) (A1). Legal status and post-grant events are not shown on this page.
What related patents are in patentsdb?
We list 2 related publications on this page (citations in our corpus or others sharing the same primary CPC).