SECURELY ONBOARDING VIRTUAL MACHINES USING A CENTRALIZED POLICY SERVER
First Claim
1. A method comprising:
- determining a virtual machine (VM) inventory baseline of a system, including identifying VMs in a baseline configuration and generating a VM fingerprint for each VM in the inventory baseline;
detecting a user onboarded VM;
moving the user onboarded VM to a quarantine operating area for a period of time;
assessing an operational posture of the user onboarded VM;
comparing the operational posture of the user onboarded VM to an operational posture policy of the system;
when the operational posture of the user onboarded VM meets the operational posture policy of the system, moving the user onboarded VM from the quarantine area to an operational area; and
when the operational posture of the user onboarded system does not meet the operational policy posture of the system and the period of time has expired, terminating the user onboarded VM.
9 Assignments
0 Petitions
Accused Products
Abstract
In some implementations, a method can include determining a virtual machine (VM) inventory baseline of a system, including identifying VMs in a baseline configuration and generating a VM fingerprint for each VM in the inventory baseline, and detecting a user onboarded VM and moving the user onboarded VM to a quarantine operating area for a period of time. The operational posture of the user onboarded VM can be compared to an operational posture policy of the system. When the operational posture of the user onboarded VM meets the operational posture policy of the system, the user onboarded VM is moved from the quarantine area to an operational area, and, when the operational posture of the user onboarded system does not meet the operational policy posture of the system and the period of time has expired, the user onboarded VM is terminated.
-
Citations
18 Claims
-
1. A method comprising:
-
determining a virtual machine (VM) inventory baseline of a system, including identifying VMs in a baseline configuration and generating a VM fingerprint for each VM in the inventory baseline; detecting a user onboarded VM; moving the user onboarded VM to a quarantine operating area for a period of time; assessing an operational posture of the user onboarded VM; comparing the operational posture of the user onboarded VM to an operational posture policy of the system; when the operational posture of the user onboarded VM meets the operational posture policy of the system, moving the user onboarded VM from the quarantine area to an operational area; and when the operational posture of the user onboarded system does not meet the operational policy posture of the system and the period of time has expired, terminating the user onboarded VM. - View Dependent Claims (2, 3, 4, 5, 6)
-
-
7. A system comprising:
one or more processors coupled to a nontransitory computer readable medium having stored thereon on software instructions that, when executed by the one or more processors, cause to perform operations including; determining a virtual machine (VM) inventory baseline of a system, including identifying VMs in a baseline configuration and generating a VM fingerprint for each VM in the inventory baseline; detecting a user onboarded VM; moving the user onboarded VM to a quarantine operating area for a period of time; assessing an operational posture of the user onboarded VM; comparing the operational posture of the user onboarded VM to an operational posture policy of the system; when the operational posture of the user onboarded VM meets the operational posture policy of the system, moving the user onboarded VM from the quarantine area to an operational area; and when the operational posture of the user onboarded system does not meet the operational policy posture of the system and the period of time has expired, terminating the user onboarded VM. - View Dependent Claims (8, 9, 10, 11, 12)
-
13. A nontransitory computer readable medium having stored thereon software instructions that, when executed by one or more processors, cause the one or more processors to:
-
determining a virtual machine (VM) inventory baseline of a system, including identifying VMs in a baseline configuration and generating a VM fingerprint for each VM in the inventory baseline; detecting a user onboarded VM; moving the user onboarded VM to a quarantine operating area for a period of time; assessing an operational posture of the user onboarded VM; comparing the operational posture of the user onboarded VM to an operational posture policy of the system; when the operational posture of the user onboarded VM meets the operational posture policy of the system, moving the user onboarded VM from the quarantine area to an operational area; and when the operational posture of the user onboarded system does not meet the operational policy posture of the system and the period of time has expired, terminating the user onboarded VM. - View Dependent Claims (14, 15, 16, 17, 18)
-
Specification