Introspection method and apparatus for network access filtering
Abstract
Some embodiments of the invention provide a method for performing network access filtering and/or categorization through guest introspection (GI) on a device. In some embodiments, this GI method intercepts directly on a device a data message that device is preparing to send, and uses a service appliance to determine whether the data message can be sent. The device in some embodiments is a guest virtual machine (VM) that executes on a multi-VM host computing device along with a service VM (SVM) that is the service appliance that determines whether the data message can be sent based on a set of filtering rules. In some embodiments, the method uses one or more introspectors (e.g., network introspector and/or file introspector) to capture introspection data from the guest VM (GVM) about the data message that the GVM is preparing to send. To perform the network access filtering, the GI method in some embodiments captures contextual information, such as user and application information (e.g., application associated with a particular URL request). Hence, in some embodiments, this method seamlessly processes granular user-aware URL filtering rules (e.g., members of the sales organization can access social networking sites but not other members). This approach requires no additional configuration on networking infrastructure.
Claims
exact text as granted — not AI-modified1 - 19 . (canceled)
20 . A method of controlling network access on a host computer on which a machine executes, the method comprising:
at a service engine executing on the host computer separately from the machine,
receiving, through a guest introspection (GI) agent installed on the machine, captured contextual data that includes a uniform resource identifier identifying a resource that the machine is attempting to access through a network;
using the uniform resource identifier to identify a policy applicable to the attempted network access;
based on the identified policy, directing the GI agent to allow or reject the network access.
21 . The method of claim 20 , wherein the GI agent is a network introspection agent that captures data through a set of filters that is defined in a network stack of the data compute node.
22 . The method of claim 21 , wherein the set of filters include a transport layer library filter.
23 . The method of claim 21 , wherein the set of filters includes a filter that is defined in a library that handles communication protocol operations higher than layer 4.
24 . The method of claim 21 , wherein the set of filters capture the data before the data is encrypted, wherein the capturing of the unencrypted data allows the captured data to be used to examine network access policies without decrypting the data.
25 . The method of claim 20 , wherein
the data compute node is a guest virtual machine, and the service engine is a service virtual machine executing on the host computer.
26 . The method of claim 20 , wherein the uniform resource identifier identifies a website that is intended for access, the method further comprising evaluating the identified policy to determine whether the machine is allowed to access the website.
27 . The method of claim 26 , wherein evaluating the identified policy comprises evaluating the identified policy to determine whether the website is accessible by an application that executes on the machine and that is attempting the network access.
28 . The method of claim 26 , wherein evaluating the identified policy comprises evaluating the identified policy to determine whether the website is accessible by a user that is using the machine while the network access is being attempted.
29 . The method of claim 26 , wherein the website access is for accessing a file, and evaluating the identified policy determines comprises evaluating the identified policy to determine whether the file is available for the network access.
30 . The method of claim 20 further comprising:
identifying a category associated with the uniform resource identifier;
evaluating the identified policy to determine whether the identified category is one category of resources that the machine has a right to access.
31 . A non-transitory machine readable medium for storing a service engine to control network access on a host computer on which a machine executes, the service engine to execute on the host computer, the service engine comprising sets of instructions for:
receiving, through a guest introspection (GI) agent installed on the machine, captured contextual data that includes a uniform resource identifier identifying a resource that the machine is attempting to access through a network; using the uniform resource identifier to identify a policy applicable to the attempted network access; when the identified policy allows the network access, directing the GI agent to allow the network access; when the identified policy does not allow the network access, directing the GI agent to reject the network access.
32 . The non-transitory machine readable medium of claim 31 , wherein the GI agent is a network introspection agent that captures data through a set of filters that is defined in a network stack of the data compute node.
33 . The non-transitory machine readable medium of claim 32 , wherein the set of filters include a transport layer library filter.
34 . The non-transitory machine readable medium of claim 32 , wherein the set of filters includes a filter that is defined in a library that handles communication protocol operations higher than layer 4.
35 . The non-transitory machine readable medium of claim 32 , wherein the set of filters capture the data before the data is encrypted, wherein the capturing of the unencrypted data allows the captured data to be used to examine network access policies without decrypting the data.
36 . The non-transitory machine readable medium of claim 31 , wherein
the data compute node is a guest virtual machine, and the service engine is a service virtual machine executing on the host computer.
37 . The non-transitory machine readable medium of claim 31 , wherein the uniform resource identifier identifies a website that is intended for access, the service engine further comprising a set of instructions for evaluating the identified policy to determine whether the machine is allowed to access the website.
38 . The non-transitory machine readable medium of claim 37 , wherein the set of instructions for evaluating the identified policy comprises a set of instructions for evaluating the identified policy to determine whether the website is accessible by an application that executes on the machine and that is attempting the network access.
39 . The non-transitory machine readable medium of claim 37 , wherein the set of instructions for evaluating the identified policy comprises a set of instructions for evaluating the identified policy to determine whether the website is accessible by a user that is using the machine while the network access is being attempted.
40 . The non-transitory machine readable medium of claim 37 , wherein the website access is for accessing a file, and evaluating the identified policy comprises evaluating the identified policy to determine whether the file is available for the network access.Join the waitlist — get patent alerts
Track US2020225978A1 — get alerts on status changes and closely related new filings.
We store only your email — no account needed. See our privacy policy.