JP2017194979A - 仮想クラウドインフラストラクチャへの仮想セキュリティ装置アーキテクチャの提供 - Google Patents
仮想クラウドインフラストラクチャへの仮想セキュリティ装置アーキテクチャの提供 Download PDFInfo
- Publication number
- JP2017194979A JP2017194979A JP2017104683A JP2017104683A JP2017194979A JP 2017194979 A JP2017194979 A JP 2017194979A JP 2017104683 A JP2017104683 A JP 2017104683A JP 2017104683 A JP2017104683 A JP 2017104683A JP 2017194979 A JP2017194979 A JP 2017194979A
- Authority
- JP
- Japan
- Prior art keywords
- virtual
- security
- server
- virtual machine
- guest
- Prior art date
- Legal status (The legal status is an assumption and is not a legal conclusion. Google has not performed a legal analysis and makes no representation as to the accuracy of the status listed.)
- Granted
Links
Images
Classifications
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/60—Protecting data
- G06F21/606—Protecting data by securing the transmission between two devices or processes
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/14—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic
- H04L63/1408—Network architectures or network communication protocols for network security for detecting or protecting against malicious traffic by monitoring network traffic
- H04L63/1416—Event detection, e.g. attack signature detection
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/20—Network architectures or network communication protocols for network security for managing network security; network security policies in general
- H04L63/205—Network architectures or network communication protocols for network security for managing network security; network security policies in general involving negotiation or determination of the one or more network security mechanisms to be used, e.g. by negotiation between the client and the server or between peers or by selection according to the capabilities of the entities involved
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F9/00—Arrangements for program control, e.g. control units
- G06F9/06—Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
- G06F9/44—Arrangements for executing specific programs
- G06F9/455—Emulation; Interpretation; Software simulation, e.g. virtualisation or emulation of application or operating system execution engines
- G06F9/45533—Hypervisors; Virtual machine monitors
- G06F9/45558—Hypervisor-specific management and integration aspects
- G06F2009/45587—Isolation or security of virtual machine instances
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F9/00—Arrangements for program control, e.g. control units
- G06F9/06—Arrangements for program control, e.g. control units using stored programs, i.e. using an internal store of processing equipment to receive or retain programs
- G06F9/44—Arrangements for executing specific programs
- G06F9/455—Emulation; Interpretation; Software simulation, e.g. virtualisation or emulation of application or operating system execution engines
- G06F9/45533—Hypervisors; Virtual machine monitors
- G06F9/45558—Hypervisor-specific management and integration aspects
- G06F2009/45595—Network integration; Enabling network access in virtual machine instances
-
- G—PHYSICS
- G06—COMPUTING OR CALCULATING; COUNTING
- G06F—ELECTRIC DIGITAL DATA PROCESSING
- G06F21/00—Security arrangements for protecting computers, components thereof, programs or data against unauthorised activity
- G06F21/50—Monitoring users, programs or devices to maintain the integrity of platforms, e.g. of processors, firmware or operating systems
-
- H—ELECTRICITY
- H04—ELECTRIC COMMUNICATION TECHNIQUE
- H04L—TRANSMISSION OF DIGITAL INFORMATION, e.g. TELEGRAPHIC COMMUNICATION
- H04L63/00—Network architectures or network communication protocols for network security
- H04L63/10—Network architectures or network communication protocols for network security for controlling access to devices or network resources
- H04L63/105—Multiple levels of security
Landscapes
- Engineering & Computer Science (AREA)
- Computer Security & Cryptography (AREA)
- Computer Hardware Design (AREA)
- General Engineering & Computer Science (AREA)
- Theoretical Computer Science (AREA)
- Signal Processing (AREA)
- Computer Networks & Wireless Communication (AREA)
- Computing Systems (AREA)
- Health & Medical Sciences (AREA)
- Bioethics (AREA)
- General Health & Medical Sciences (AREA)
- Software Systems (AREA)
- Physics & Mathematics (AREA)
- General Physics & Mathematics (AREA)
- Data Exchanges In Wide-Area Networks (AREA)
Abstract
【解決手段】仮想ネットワークインフラストラクチャの仮想サーバ内の仮想マシンについての変化を検出するステップと、仮想セキュリティ装置が仮想サーバ内で構成されるかどうかを判断するステップと、仮想セキュリティ装置を仮想サーバ内で作成するよう要求を送信するステップと、仮想セキュリティ装置が仮想マシン内で作成されるときに、仮想マシンが開始するのを許可するステップと、仮想セキュリティ装置は、仮想マシンから送信されるネットワークパケットに対してセキュリティ検査を実行し、仮想マシンからのネットワークパケットをインターセプトするインターセプト機構を仮想サーバ内に作成するステップと、を含む。1つ又は複数のセキュリティポリシーが、1つ又は複数の仮想セキュリティ装置を識別し、仮想マシンからのネットワークパケットを処理する。
【選択図】図15
Description
例示の実施形態における方法は、仮想ネットワークインフラストラクチャの仮想サーバ内の仮想マシンについての変化を検出するステップと、仮想セキュリティ装置が仮想サーバ内で構成されるかどうかを判断するステップと、仮想セキュリティ装置を仮想サーバ内で作成するよう要求を送信するステップとを含む。当該方法は更に、仮想セキュリティ装置が仮想マシン内で作成されるときに、仮想マシンが開始するのを許可するステップを含む。仮想セキュリティ装置は、仮想マシンから送信されるネットワークパケットに対してセキュリティ検査を実行する。より具体的な実施形態では、当該方法は更に、仮想マシンからのネットワークパケットをインターセプトするインターセプト機構を仮想サーバ内に作成するステップを含む。更なる実施形態では、1つ又は複数のセキュリティポリシーが、1つ又は複数の仮想セキュリティ装置を識別し、仮想マシンからのネットワークパケットを処理する。
図1は、本開示の一実施形態に従って、仮想クラウドインフラストラクチャにおいて仮想セキュリティ装置を提供するための通信システム100の例示的な図である。通信システム100は、ハードウェアレイヤ110、(仮想マシンマネージャ(VMM)120によって一般的に表される)仮想化レイヤ、コアリソース135のセット、仮想化されたデスクトップインフラストラクチャ(VDI)130及びクラウドマネージャ150を備える仮想クラウドインフラストラクチャを表す。ハードウェアレイヤ110は、サーバ112、他のネットワークデバイス116及びストレージ114を含むことができる。コアリソース135は、ネットワークプロトコルを含み、例えば内部ネットワークや無線ネットワーク、インターネット等を含め様々なネットワークへのアクセスを可能にし、管理することができる。1つの例示の実装では、コアリソース135は、動的ホスト構成プロトコル(DHCP)ネットワーキングプロトコルサーバ136、ドメイン名サービス(DNS)137、認証許可アカウンティング(AAA:Authentication, Authorization, and Accounting)ネットワーキングプロトコルサーバ138を含むことができる。仮想セキュリティシステム160は、通信システム100における仮想セキュリティ装置のアーキテクチャを提供及び管理するのを可能にするのに提供される。仮想セキュリティシステムは、ポリシーレイヤ170、セキュリティマネージャ175、分散レイヤ180及びインターセプトレイヤ190を含むことができる。
typedef unsigned char mac_addr[6];
typedef struct{
mac addr dst; //Ethernet header, destination
mac_addr src; //Ethernet header, source
U16 etherType; //Ethernet header, type
U8 num_src_route; //number of elements in the source route array
mac addr src route[this.num_src_type]; //the source route
}mac_src_route_header;
上記のタイプはバイトに関してパケット化されることを想定している。上記において、ヘッダの最初の部分は、EthernetII MACヘッダのように見える。この構成は、MACヘッダに関連して説明されるが、IEEE802.3ヘッダを使用するネットワークのように、他のタイプのヘッダに適合するよう、適切な変更を行ってもよい。元のパケットは、mac_src_route_headerの後で始まる。このためのオフセットは、各VSAについて元のパケットを回復するよう、num_src_route*6+14として計算され得る。処理中に、mac_src_route_headerは保存される必要がある。一例において、フローテーブル582は、ドライバレベルで構築され、パケットストリーム内の各パケットについて同じヘッダを使用してよい。出力において、src_route_next_headerがインクリメントされ、src_routeアレイ内の次のMACアドレスがdstフィールドにコピーされる。
Claims (23)
- 少なくとも1つのプロセッサによって実行されると、該少なくとも1つのプロセッサに:
仮想ネットワークインフラストラクチャの仮想サーバ内において、仮想マシンの変化を検出し;
前記仮想サーバ内で仮想セキュリティ装置が構成されているかどうかを判断し;
前記仮想サーバ内で前記仮想セキュリティ装置を作成するよう要求を送信し;
前記仮想サーバ内で前記仮想セキュリティ装置が構成されていない場合、前記仮想マシンをブロックし;
前記仮想サーバ内で前記仮想セキュリティ装置が作成されるとき、前記仮想マシンが開始することを許可する;
動作を実行させ、
前記仮想セキュリティ装置が、前記仮想マシンから送信されるネットワークパケットに対してセキュリティ検査を実行する、
コンピュータプログラム。 - 当該コンピュータプログラムは、前記少なくとも1つのプロセッサによって実行されると、該少なくとも1つのプロセッサに更に、
前記仮想サーバ内に、前記仮想マシンからの前記ネットワークパケットをインターセプトするインターセプト機構を作成する、
動作を実行させる、請求項1に記載コンピュータプログラム。 - 当該コンピュータプログラムは、前記少なくとも1つのプロセッサによって実行されると、該少なくとも1つのプロセッサに更に、
前記仮想マシンからの前記ネットワークパケットを物理ネットワークインタフェースカードに向けるよう、前記仮想マシンに接続される仮想スイッチのロジックを再構成し、
前記ネットワークパケットが仮想ネットワークインタフェースカード(vNIC)を通過するのを防ぐよう、前記vNICのロジックを再構成する、
動作を実行させる、請求項2に記載のコンピュータプログラム。 - 前記インターセプト機構は、単一ルート入出力仮想化(SR−IOV)仕様に基づく前記ネットワークパケットのハードウェアインターセプトを含む、
請求項2又は3に記載のコンピュータプログラム。 - 前記変化は、前記仮想マシンを、第2の仮想サーバから前記仮想サーバに移動させることを含み、当該コンピュータプログラムは、前記少なくとも1つのプロセッサによって実行されると、該少なくとも1つのプロセッサに更に、
前記第2の仮想サーバから第2の仮想セキュリティ装置を削除し、
仮想ネットワークインタフェースカードを介して通信するよう前記第2の仮想サーバ内の仮想スイッチのロジックを再構成する、
動作を実行させ、
前記第2の仮想セキュリティ装置は、前記仮想マシンが前記第2の仮想サーバ内で実行していたときに前記仮想マシンからインターセプトされたネットワークパケットを処理するように構成されている、
請求項1乃至4のいずれかに記載のコンピュータプログラム。 - 1つ又は複数のセキュリティポリシーは、前記仮想マシンからの前記ネットワークパケットを処理するよう1つ又は複数の仮想セキュリティ装置を識別する、
請求項1乃至5のいずれかに記載のコンピュータプログラム。 - 前記1つ又は複数のセキュリティポリシーは、前記1つ又は複数の仮想セキュリティ装置について、前記仮想マシンからの前記ネットワークパケットを処理する順序を識別する、
請求項6に記載のコンピュータプログラム。 - 前記仮想マシンについて検出される前記変化は、前記仮想マシンを前記仮想サーバに追加すること又は前記仮想マシンを別の仮想サーバから前記仮想サーバに移動させることの一方を含む、
請求項1乃至4、6及び7のいずれかに記載のコンピュータプログラム。 - 前記変化は、前記仮想マシンが前記仮想サーバに追加されるとき又は前記仮想マシンが異なるサーバに移動されるときに、アプリケーションプログラミングインタフェース(API)を通して検出される、
請求項1乃至8のいずれかに記載のコンピュータプログラム。 - 前記仮想マシンからのパケットフローの最初の出力ネットワークパケットは、前記仮想マシンが前記仮想サーバ内で開始することを許可された後、前記仮想サーバ内のOpenFlowスイッチによってインターセプトされ、当該コンピュータプログラムは、前記少なくとも1つのプロセッサによって実行されると、該少なくとも1つのプロセッサに更に、
前記出力ネットワークパケットのためのフロールートを、セキュリティポリシーに基づいて生成する、
動作を実行させ、前記OpenFlowスイッチは、前記出力ネットワークパケットを前記フロールートに従ってルーティングする、
請求項1乃至9のいずれかに記載のコンピュータプログラム。 - プロセッサ上で動作するポリシーマネージャの仮想マシンであって:
仮想ネットワークインフラストラクチャの仮想サーバ内において、ゲスト仮想マシンの変化を検出し、
前記仮想サーバ内で仮想セキュリティ装置が構成されているかどうかを判断し、
前記仮想サーバ内で前記仮想セキュリティ装置が構成されていない場合、前記ゲスト仮想マシンをブロックし、
前記仮想サーバ内で前記仮想セキュリティ装置が作成されるとき、前記ゲスト仮想マシンが開始することを許可する、
ように構成されるポリシーマネージャの仮想マシンと;
プロセッサ上で動作する分散マネージャの仮想マシンであって、前記仮想サーバ内で前記仮想セキュリティ装置を作成するよう要求を送信するように構成される、分散マネージャの仮想マシンと;
を備え、前記仮想セキュリティ装置は、前記ゲスト仮想マシンから送信されるネットワークパケットに対してセキュリティ検査を実行する、
装置。 - 分散マネージャは、
前記仮想サーバ内に、前記ゲスト仮想マシンからの前記ネットワークパケットをインターセプトするインターセプト機構を作成する、
ように構成される、請求項11に記載の装置。 - 分散マネージャは、
前記ゲスト仮想マシンからの前記ネットワークパケットを物理ネットワークインタフェースカードに向けるよう、前記ゲスト仮想マシンに接続される仮想スイッチのロジックを再構成し、
前記ネットワークパケットが仮想ネットワークインタフェースカード(vNIC)を通過するのを防ぐよう、前記vNICのロジックを再構成する、
ように更に構成される、請求項12に記載の装置。 - 前記インターセプト機構は、単一ルート入出力仮想化(SR−IOV)仕様に基づく前記ネットワークパケットのハードウェアインターセプトを含む、
請求項12又は13に記載の装置。 - 前記変化は、前記ゲスト仮想マシンを、第2の仮想サーバから前記仮想サーバに移動させることを含み、前記第2の仮想サーバから第2の仮想セキュリティ装置が削除される、
請求項11乃至14のいずれかに記載の装置。 - 1つ又は複数のセキュリティポリシーは、前記ゲスト仮想マシンからの前記ネットワークパケットを処理するよう1つ又は複数の仮想セキュリティ装置を識別し、前記1つ又は複数のセキュリティポリシーは、前記1つ又は複数の仮想セキュリティ装置について、前記ゲスト仮想マシンからの前記ネットワークパケットを処理する順序を識別する、
請求項11乃至15のいずれかに記載の装置。 - 仮想ネットワークインフラストラクチャの仮想サーバ内において、仮想マシンの変化を検出するステップと、
前記仮想サーバ内で仮想セキュリティ装置が構成されているかどうかを判断するステップと、
前記仮想サーバ内で前記仮想セキュリティ装置を作成するよう要求を送信するステップと、
前記仮想サーバ内で前記仮想セキュリティ装置が構成されていない場合、前記仮想マシンをブロックするステップと、
前記仮想サーバ内で前記仮想セキュリティ装置が作成されるとき、前記仮想マシンが開始することを許可するステップであって、前記仮想セキュリティ装置が、前記仮想マシンから送信されるネットワークパケットに対してセキュリティ検査を実行する、ステップと、
を含む方法。 - 前記仮想サーバ内に、前記仮想マシンからの前記ネットワークパケットをインターセプトするインターセプト機構を作成するステップを更に含み、前記インターセプト機構は、単一ルート入出力仮想化(SR−IOV)仕様に基づいて前記仮想サーバのハードウェアで前記ネットワークパケットをインターセプトすることを含む、
請求項17に記載の方法。 - 1つ又は複数のセキュリティポリシーは、前記仮想マシンからの前記ネットワークパケットを処理するよう1つ又は複数の仮想セキュリティ装置を識別し、前記1つ又は複数のセキュリティポリシーは、前記1つ又は複数の仮想セキュリティ装置について、前記仮想マシンからの前記ネットワークパケットを処理する順序を識別する、
請求項17又は18に記載の方法。 - 前記仮想マシンからのパケットフローの最初の出力ネットワークパケットは、前記仮想マシンが前記仮想サーバ内で開始することを許可された後、前記仮想サーバ内のOpenFlowスイッチによってインターセプトされ、当該方法は、
前記出力ネットワークパケットのためのフロールートを、セキュリティポリシーに基づいて生成するステップ、
を更に含み、前記OpenFlowスイッチは、前記出力ネットワークパケットを前記フロールートに従ってルーティングする、
請求項17乃至19のいずれかに記載の方法。 - 少なくとも1つのプロセッサによって実行されると、該少なくとも1つのプロセッサに:
仮想ネットワークインフラストラクチャの第1の仮想サーバ内において、ゲスト仮想マシンの変化を検出させ;
前記第1の仮想サーバ内で仮想セキュリティ装置が構成されているかどうかを判断させ;
前記第1の仮想サーバ内で前記仮想セキュリティ装置が構成されていないと判断すると、
前記第1の仮想サーバ内で前記ゲスト仮想マシンを開始し、前記第1の仮想サーバ内で1つ以上の必要なセキュリティ検査を適用することができる新たな仮想セキュリティ装置を作成するよう要求を送信する、
ように処理を実行させ;
前記の開始が、前記第1の仮想サーバ内で前記ゲスト仮想マシンを実行することと、前記仮想ネットワークインフラストラクチャの第2の仮想サーバ上で実行する前記1つ以上の必要なセキュリティ検査を適用することができる既存の仮想セキュリティ装置を通して、前記ゲスト仮想マシンに関連付けられるパケットストリームをルーティングすることを含む、
コンピュータプログラム。 - 当該コンピュータプログラムは、前記少なくとも1つのプロセッサによって実行されると、該少なくとも1つのプロセッサに更に:
前記第1の仮想サーバ上に前記新たな仮想セキュリティ装置を作成して、前記新たな仮想セキュリティ装置を実行させ、前記の作成は、前記第1の仮想サーバ上における前記ゲスト仮想マシンの実行と少なくとも部分的に同時に実行される、
請求項21に記載のコンピュータプログラム。 - 当該コンピュータプログラムは、前記少なくとも1つのプロセッサによって実行されると、該少なくとも1つのプロセッサに更に:
前記新たな仮想セキュリティ装置が前記第1の仮想サーバ上で実行しているとき、前記既存の仮想セキュリティ装置の代わりに前記新たな仮想セキュリティ装置を通して後続のパケットストリームをルーティングさせる、
請求項21又は22に記載のコンピュータプログラム。
Applications Claiming Priority (2)
| Application Number | Priority Date | Filing Date | Title |
|---|---|---|---|
| US13/656,730 | 2012-10-21 | ||
| US13/656,730 US9571507B2 (en) | 2012-10-21 | 2012-10-21 | Providing a virtual security appliance architecture to a virtual cloud infrastructure |
Related Parent Applications (1)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| JP2016029265A Division JP6151394B2 (ja) | 2012-10-21 | 2016-02-18 | 仮想クラウドインフラストラクチャへの仮想セキュリティ装置アーキテクチャの提供 |
Publications (2)
| Publication Number | Publication Date |
|---|---|
| JP2017194979A true JP2017194979A (ja) | 2017-10-26 |
| JP6335363B2 JP6335363B2 (ja) | 2018-05-30 |
Family
ID=50486583
Family Applications (3)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| JP2015534834A Active JP5890595B2 (ja) | 2012-10-21 | 2013-10-20 | 仮想クラウドインフラストラクチャへの仮想セキュリティ装置アーキテクチャの提供 |
| JP2016029265A Active JP6151394B2 (ja) | 2012-10-21 | 2016-02-18 | 仮想クラウドインフラストラクチャへの仮想セキュリティ装置アーキテクチャの提供 |
| JP2017104683A Active JP6335363B2 (ja) | 2012-10-21 | 2017-05-26 | 仮想クラウドインフラストラクチャへの仮想セキュリティ装置アーキテクチャの提供 |
Family Applications Before (2)
| Application Number | Title | Priority Date | Filing Date |
|---|---|---|---|
| JP2015534834A Active JP5890595B2 (ja) | 2012-10-21 | 2013-10-20 | 仮想クラウドインフラストラクチャへの仮想セキュリティ装置アーキテクチャの提供 |
| JP2016029265A Active JP6151394B2 (ja) | 2012-10-21 | 2016-02-18 | 仮想クラウドインフラストラクチャへの仮想セキュリティ装置アーキテクチャの提供 |
Country Status (5)
| Country | Link |
|---|---|
| US (3) | US9571507B2 (ja) |
| EP (1) | EP2909780B1 (ja) |
| JP (3) | JP5890595B2 (ja) |
| CN (2) | CN104685507B (ja) |
| WO (1) | WO2014063129A1 (ja) |
Families Citing this family (312)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US7634584B2 (en) | 2005-04-27 | 2009-12-15 | Solarflare Communications, Inc. | Packet validation in virtual network interface architecture |
| WO2011162663A1 (en) | 2010-06-23 | 2011-12-29 | Telefonaktiebolaget L M Ericsson (Publ) | Reference signal interference management in heterogeneous network deployments |
| US9571507B2 (en) | 2012-10-21 | 2017-02-14 | Mcafee, Inc. | Providing a virtual security appliance architecture to a virtual cloud infrastructure |
| US9135051B2 (en) * | 2012-11-02 | 2015-09-15 | Red Hat Israel, Ltd. | Redirecting guest-generated events to an event aggregator in a networked virtualization environment |
| US10083065B2 (en) * | 2012-12-21 | 2018-09-25 | Red Hat Israel, Ltd. | Creating multiple rules for a device to allow concurrent access to the device by different virtual machines |
| US20140189127A1 (en) * | 2012-12-27 | 2014-07-03 | Anjaneya Reddy Chagam | Reservation and execution image writing of native computing devices |
| US9667527B2 (en) * | 2013-01-04 | 2017-05-30 | Nec Corporation | Control apparatus, communication system, tunnel endpoint control method, and program |
| US10671418B2 (en) * | 2013-01-09 | 2020-06-02 | Red Hat, Inc. | Sharing templates and multi-instance cloud deployable applications |
| JP2014142720A (ja) * | 2013-01-22 | 2014-08-07 | Fujitsu Ltd | 仮想マシン移動方法、情報処理装置及びプログラム |
| KR101558065B1 (ko) * | 2013-01-30 | 2015-10-06 | 지티이 (유에스에이) 인크. | 심리스 (분산된) 가상 네트워크 자원 관리를 위해 가상 네트워크 요소와 네트워크 하이퍼바이저 간의 인터페이스를 위한 요구 사항을 결정하기 위한 방법 및 시스템 |
| US9317310B2 (en) * | 2013-01-31 | 2016-04-19 | Broadcom Corporation | Systems and methods for handling virtual machine packets |
| US9485188B2 (en) * | 2013-02-01 | 2016-11-01 | International Business Machines Corporation | Virtual switching based flow control |
| US9930066B2 (en) | 2013-02-12 | 2018-03-27 | Nicira, Inc. | Infrastructure level LAN security |
| US9565202B1 (en) | 2013-03-13 | 2017-02-07 | Fireeye, Inc. | System and method for detecting exfiltration content |
| US9483286B2 (en) | 2013-03-15 | 2016-11-01 | Avi Networks | Distributed network services |
| US10742604B2 (en) | 2013-04-08 | 2020-08-11 | Xilinx, Inc. | Locked down network interface |
| US9426124B2 (en) | 2013-04-08 | 2016-08-23 | Solarflare Communications, Inc. | Locked down network interface |
| US9225638B2 (en) | 2013-05-09 | 2015-12-29 | Vmware, Inc. | Method and system for service switching using service tags |
| US9686192B2 (en) | 2013-06-28 | 2017-06-20 | Niciria, Inc. | Network service slotting |
| CN103491129B (zh) * | 2013-07-05 | 2017-07-14 | 华为技术有限公司 | 一种业务节点配置方法、业务节点池注册器及系统 |
| US9571386B2 (en) | 2013-07-08 | 2017-02-14 | Nicira, Inc. | Hybrid packet processing |
| US9282019B2 (en) | 2013-07-12 | 2016-03-08 | Nicira, Inc. | Tracing logical network packets through physical network |
| US9344349B2 (en) | 2013-07-12 | 2016-05-17 | Nicira, Inc. | Tracing network packets by a cluster of network controllers |
| US9407580B2 (en) | 2013-07-12 | 2016-08-02 | Nicira, Inc. | Maintaining data stored with a packet |
| US9456003B2 (en) | 2013-07-24 | 2016-09-27 | At&T Intellectual Property I, L.P. | Decoupling hardware and software components of network security devices to provide security software as a service in a distributed computing environment |
| US9952885B2 (en) | 2013-08-14 | 2018-04-24 | Nicira, Inc. | Generation of configuration files for a DHCP module executing within a virtualized container |
| US9626205B2 (en) * | 2013-08-14 | 2017-04-18 | Bank Of America Corporation | Hypervisor driven embedded endpoint security monitoring |
| US9887960B2 (en) | 2013-08-14 | 2018-02-06 | Nicira, Inc. | Providing services for logical networks |
| US10027605B2 (en) | 2013-08-26 | 2018-07-17 | Vmware, Inc. | Traffic and load aware dynamic queue management |
| US9548965B2 (en) | 2013-08-26 | 2017-01-17 | Nicira, Inc. | Proxy methods for suppressing broadcast traffic in a network |
| US9602398B2 (en) | 2013-09-15 | 2017-03-21 | Nicira, Inc. | Dynamically generating flows with wildcard fields |
| US9674087B2 (en) | 2013-09-15 | 2017-06-06 | Nicira, Inc. | Performing a multi-stage lookup to classify packets |
| CN105745886B (zh) * | 2013-09-23 | 2019-06-04 | 迈克菲有限公司 | 在两个实体之间提供快速路径 |
| US10033693B2 (en) | 2013-10-01 | 2018-07-24 | Nicira, Inc. | Distributed identity-based firewalls |
| US20150100670A1 (en) * | 2013-10-04 | 2015-04-09 | International Business Machines Corporation | Transporting multi-destination networking traffic by sending repetitive unicast |
| US9575782B2 (en) | 2013-10-13 | 2017-02-21 | Nicira, Inc. | ARP for logical router |
| US9998530B2 (en) | 2013-10-15 | 2018-06-12 | Nicira, Inc. | Distributed global load-balancing system for software-defined data centers |
| US9634948B2 (en) * | 2013-11-07 | 2017-04-25 | International Business Machines Corporation | Management of addresses in virtual machines |
| US9967199B2 (en) | 2013-12-09 | 2018-05-08 | Nicira, Inc. | Inspecting operations of a machine to detect elephant flows |
| US9548924B2 (en) | 2013-12-09 | 2017-01-17 | Nicira, Inc. | Detecting an elephant flow based on the size of a packet |
| US9996467B2 (en) | 2013-12-13 | 2018-06-12 | Nicira, Inc. | Dynamically adjusting the number of flows allowed in a flow table cache |
| US9569368B2 (en) | 2013-12-13 | 2017-02-14 | Nicira, Inc. | Installing and managing flows in a flow table cache |
| US11349806B2 (en) | 2013-12-19 | 2022-05-31 | Vmware, Inc. | Methods, apparatuses and systems for assigning IP addresses in a virtualized environment |
| US20150304343A1 (en) | 2014-04-18 | 2015-10-22 | Intuit Inc. | Method and system for providing self-monitoring, self-reporting, and self-repairing virtual assets in a cloud computing environment |
| US9215213B2 (en) | 2014-02-20 | 2015-12-15 | Nicira, Inc. | Method and apparatus for distributing firewall rules |
| US10757133B2 (en) | 2014-02-21 | 2020-08-25 | Intuit Inc. | Method and system for creating and deploying virtual assets |
| US9866581B2 (en) | 2014-06-30 | 2018-01-09 | Intuit Inc. | Method and system for secure delivery of information to computing environments |
| US9755981B2 (en) | 2014-03-11 | 2017-09-05 | Vmware, Inc. | Snooping forwarded packets by a virtual machine |
| US9742682B2 (en) | 2014-03-11 | 2017-08-22 | Vmware, Inc. | Large receive offload for virtual machines |
| US9384033B2 (en) | 2014-03-11 | 2016-07-05 | Vmware, Inc. | Large receive offload for virtual machines |
| US20150341377A1 (en) * | 2014-03-14 | 2015-11-26 | Avni Networks Inc. | Method and apparatus to provide real-time cloud security |
| US9680708B2 (en) | 2014-03-14 | 2017-06-13 | Veritas Technologies | Method and apparatus for cloud resource delivery |
| US9338091B2 (en) | 2014-03-27 | 2016-05-10 | Nicira, Inc. | Procedures for efficient cloud service access in a system with multiple tenant logical networks |
| US9893988B2 (en) | 2014-03-27 | 2018-02-13 | Nicira, Inc. | Address resolution using multiple designated instances of a logical router |
| US9825854B2 (en) | 2014-03-27 | 2017-11-21 | Nicira, Inc. | Host architecture for efficient cloud service access |
| US9794186B2 (en) | 2014-03-27 | 2017-10-17 | Nicira, Inc. | Distributed network address translation for efficient cloud service access |
| US9985896B2 (en) | 2014-03-31 | 2018-05-29 | Nicira, Inc. | Caching of service decisions |
| US9906494B2 (en) | 2014-03-31 | 2018-02-27 | Nicira, Inc. | Configuring interactions with a firewall service virtual machine |
| US10193806B2 (en) | 2014-03-31 | 2019-01-29 | Nicira, Inc. | Performing a finishing operation to improve the quality of a resulting hash |
| US9503427B2 (en) | 2014-03-31 | 2016-11-22 | Nicira, Inc. | Method and apparatus for integrating a service virtual machine |
| US9582308B2 (en) | 2014-03-31 | 2017-02-28 | Nicira, Inc. | Auto detecting legitimate IP addresses using spoofguard agents |
| US9215210B2 (en) | 2014-03-31 | 2015-12-15 | Nicira, Inc. | Migrating firewall connection state for a firewall service virtual machine |
| US9385954B2 (en) | 2014-03-31 | 2016-07-05 | Nicira, Inc. | Hashing techniques for use in a network environment |
| US11294700B2 (en) | 2014-04-18 | 2022-04-05 | Intuit Inc. | Method and system for enabling self-monitoring virtual assets to correlate external events with characteristic patterns associated with the virtual assets |
| US10469404B1 (en) | 2014-05-12 | 2019-11-05 | Google Llc | Network multi-level rate limiter |
| US9762502B1 (en) | 2014-05-12 | 2017-09-12 | Google Inc. | Method and system for validating rate-limiter determination made by untrusted software |
| US9755978B1 (en) * | 2014-05-12 | 2017-09-05 | Google Inc. | Method and system for enforcing multiple rate limits with limited on-chip buffering |
| US9729512B2 (en) | 2014-06-04 | 2017-08-08 | Nicira, Inc. | Use of stateless marking to speed up stateful firewall rule processing |
| US9825913B2 (en) | 2014-06-04 | 2017-11-21 | Nicira, Inc. | Use of stateless marking to speed up stateful firewall rule processing |
| US10110712B2 (en) | 2014-06-04 | 2018-10-23 | Nicira, Inc. | Efficient packet classification for dynamic containers |
| US9774707B2 (en) | 2014-06-04 | 2017-09-26 | Nicira, Inc. | Efficient packet classification for dynamic containers |
| US10261814B2 (en) * | 2014-06-23 | 2019-04-16 | Intel Corporation | Local service chaining with virtual machines and virtualized containers in software defined networking |
| US10666689B2 (en) | 2014-06-30 | 2020-05-26 | Alcatel Lucent | Security in software defined network |
| US10747888B2 (en) | 2014-06-30 | 2020-08-18 | Nicira, Inc. | Method and apparatus for differently encrypting data messages for different logical networks |
| US9692698B2 (en) | 2014-06-30 | 2017-06-27 | Nicira, Inc. | Methods and systems to offload overlay network packet encapsulation to hardware |
| WO2016003489A1 (en) * | 2014-06-30 | 2016-01-07 | Nicira, Inc. | Methods and systems to offload overlay network packet encapsulation to hardware |
| US9419897B2 (en) | 2014-06-30 | 2016-08-16 | Nicira, Inc. | Methods and systems for providing multi-tenancy support for Single Root I/O Virtualization |
| US9356945B2 (en) | 2014-07-17 | 2016-05-31 | Check Point Advanced Threat Prevention Ltd | Automatic content inspection system for exploit detection |
| US10102082B2 (en) | 2014-07-31 | 2018-10-16 | Intuit Inc. | Method and system for providing automated self-healing virtual assets |
| US9749242B2 (en) | 2014-08-20 | 2017-08-29 | At&T Intellectual Property I, L.P. | Network platform as a service layer for open systems interconnection communication model layer 4 through layer 7 services |
| US10291689B2 (en) | 2014-08-20 | 2019-05-14 | At&T Intellectual Property I, L.P. | Service centric virtual network function architecture for development and deployment of open systems interconnection communication model layer 4 through layer 7 services in a cloud computing system |
| US9800673B2 (en) | 2014-08-20 | 2017-10-24 | At&T Intellectual Property I, L.P. | Service compiler component and service controller for open systems interconnection layer 4 through layer 7 services in a cloud computing system |
| US9742690B2 (en) | 2014-08-20 | 2017-08-22 | At&T Intellectual Property I, L.P. | Load adaptation architecture framework for orchestrating and managing services in a cloud computing system |
| EP2988214A1 (en) * | 2014-08-20 | 2016-02-24 | Alcatel Lucent | Method for balancing a load, a system, an elasticity manager and a computer program product |
| US9473567B2 (en) | 2014-08-20 | 2016-10-18 | At&T Intellectual Property I, L.P. | Virtual zones for open systems interconnection layer 4 through layer 7 services in a cloud computing system |
| US9864864B2 (en) * | 2014-09-23 | 2018-01-09 | Accenture Global Services Limited | Industrial security agent platform |
| US9300693B1 (en) * | 2014-09-24 | 2016-03-29 | Symantec Corporation | Systems and methods for preventing data loss over virtualized networks |
| US9755898B2 (en) | 2014-09-30 | 2017-09-05 | Nicira, Inc. | Elastically managing a service node group |
| US10511458B2 (en) | 2014-09-30 | 2019-12-17 | Nicira, Inc. | Virtual distributed bridging |
| US10225137B2 (en) | 2014-09-30 | 2019-03-05 | Nicira, Inc. | Service node selection by an inline service switch |
| US11178051B2 (en) | 2014-09-30 | 2021-11-16 | Vmware, Inc. | Packet key parser for flow-based forwarding elements |
| US10135737B2 (en) | 2014-09-30 | 2018-11-20 | Nicira, Inc. | Distributed load balancing systems |
| US10250443B2 (en) | 2014-09-30 | 2019-04-02 | Nicira, Inc. | Using physical location to modify behavior of a distributed virtual network element |
| US10469342B2 (en) | 2014-10-10 | 2019-11-05 | Nicira, Inc. | Logical network traffic analysis |
| US9876714B2 (en) | 2014-11-14 | 2018-01-23 | Nicira, Inc. | Stateful services on stateless clustered edge |
| US9866473B2 (en) | 2014-11-14 | 2018-01-09 | Nicira, Inc. | Stateful services on stateless clustered edge |
| US10044617B2 (en) | 2014-11-14 | 2018-08-07 | Nicira, Inc. | Stateful services on stateless clustered edge |
| US11533255B2 (en) | 2014-11-14 | 2022-12-20 | Nicira, Inc. | Stateful services on stateless clustered edge |
| US9622019B2 (en) * | 2014-11-28 | 2017-04-11 | Huawei Technologies Co., Ltd. | Systems and methods for generating a virtual network topology for M2M communications |
| US9692727B2 (en) | 2014-12-02 | 2017-06-27 | Nicira, Inc. | Context-aware distributed firewall |
| US9699060B2 (en) | 2014-12-17 | 2017-07-04 | Vmware, Inc. | Specializing virtual network device processing to avoid interrupt processing for high packet rate applications |
| US10320921B2 (en) * | 2014-12-17 | 2019-06-11 | Vmware, Inc. | Specializing virtual network device processing to bypass forwarding elements for high packet rate applications |
| US9891940B2 (en) | 2014-12-29 | 2018-02-13 | Nicira, Inc. | Introspection method and apparatus for network access filtering |
| TW201624277A (zh) | 2014-12-31 | 2016-07-01 | 萬國商業機器公司 | 協助虛擬機器即時遷移的方法 |
| EP3251320A1 (en) * | 2015-01-28 | 2017-12-06 | Nokia Solutions and Networks Oy | Software-defined networking controller |
| US10439984B2 (en) * | 2015-02-16 | 2019-10-08 | Telefonaktiebolaget Lm Ericsson (Publ) | Multi-stage defense-aware security modules placement in the cloud |
| JP6272258B2 (ja) * | 2015-03-04 | 2018-01-31 | 日本電信電話株式会社 | 最適化装置、最適化方法および最適化プログラム |
| US9807117B2 (en) * | 2015-03-17 | 2017-10-31 | Solarflare Communications, Inc. | System and apparatus for providing network security |
| US10609091B2 (en) | 2015-04-03 | 2020-03-31 | Nicira, Inc. | Method, apparatus, and system for implementing a content switch |
| IL238690B (en) | 2015-05-07 | 2019-07-31 | Mellanox Technologies Ltd | Network-based computational accelerator |
| US10567395B2 (en) | 2015-05-10 | 2020-02-18 | Check Point Advanced Threat Prevention Ltd | Detection of potentially malicious web content by emulating user behavior and user environment |
| US10078465B1 (en) * | 2015-05-20 | 2018-09-18 | VCE IP Holding Company LLC | Systems and methods for policy driven storage in a hyper-convergence data center |
| US10212589B2 (en) * | 2015-06-02 | 2019-02-19 | Huawei Technologies Co., Ltd. | Method and apparatus to use infra-structure or network connectivity services provided by 3rd parties |
| US10700936B2 (en) | 2015-06-02 | 2020-06-30 | Huawei Technologies Co., Ltd. | System and methods for virtual infrastructure management between operator networks |
| KR20160144688A (ko) * | 2015-06-09 | 2016-12-19 | 한국전자통신연구원 | 큐를 이용한 smp 가상 머신 이벤트 라우터 및 방법 |
| US10642753B1 (en) | 2015-06-30 | 2020-05-05 | Fireeye, Inc. | System and method for protecting a software component running in virtual machine using a virtualization layer |
| US9680706B2 (en) | 2015-06-30 | 2017-06-13 | Nicira, Inc. | Federated firewall management for moving workload across data centers |
| US10395029B1 (en) | 2015-06-30 | 2019-08-27 | Fireeye, Inc. | Virtual system and method with threat protection |
| US10726127B1 (en) | 2015-06-30 | 2020-07-28 | Fireeye, Inc. | System and method for protecting a software component running in a virtual machine through virtual interrupts by the virtualization layer |
| US11113086B1 (en) | 2015-06-30 | 2021-09-07 | Fireeye, Inc. | Virtual system and method for securing external network connectivity |
| US10361952B2 (en) | 2015-06-30 | 2019-07-23 | Nicira, Inc. | Intermediate logical interfaces in a virtual distributed router environment |
| US10216927B1 (en) | 2015-06-30 | 2019-02-26 | Fireeye, Inc. | System and method for protecting memory pages associated with a process using a virtualization layer |
| JP6512990B2 (ja) * | 2015-08-05 | 2019-05-15 | アラクサラネットワークス株式会社 | 転送装置及び転送システム |
| US10356012B2 (en) * | 2015-08-20 | 2019-07-16 | Intel Corporation | Techniques for routing packets among virtual machines |
| CN105099789B (zh) | 2015-09-02 | 2018-03-16 | 华为技术有限公司 | 一种网元升级方法及设备 |
| US10862818B2 (en) | 2015-09-23 | 2020-12-08 | Huawei Technologies Co., Ltd. | Systems and methods for distributing network resources to network service providers |
| US10033759B1 (en) | 2015-09-28 | 2018-07-24 | Fireeye, Inc. | System and method of threat detection under hypervisor control |
| US10353726B2 (en) * | 2015-09-29 | 2019-07-16 | NeuVector, Inc. | Transparent network security for application containers |
| US10204122B2 (en) | 2015-09-30 | 2019-02-12 | Nicira, Inc. | Implementing an interface between tuple and message-driven control entities |
| US10324746B2 (en) | 2015-11-03 | 2019-06-18 | Nicira, Inc. | Extended context delivery for context-based authorization |
| US11159486B2 (en) | 2015-11-17 | 2021-10-26 | Zscaler, Inc. | Stream scanner for identifying signature matches |
| US11277383B2 (en) | 2015-11-17 | 2022-03-15 | Zscaler, Inc. | Cloud-based intrusion prevention system |
| US10594656B2 (en) * | 2015-11-17 | 2020-03-17 | Zscaler, Inc. | Multi-tenant cloud-based firewall systems and methods |
| US10237239B2 (en) * | 2015-12-03 | 2019-03-19 | International Business Machines Corporation | Policy-based load distribution between host-based packet processing units |
| US10298720B1 (en) * | 2015-12-07 | 2019-05-21 | Amazon Technologies, Inc. | Client-defined rules in provider network environments |
| JP6657910B2 (ja) * | 2015-12-16 | 2020-03-04 | 富士通株式会社 | 帯域設定方法、帯域設定プログラム、情報処理装置及び情報処理システム |
| US11050562B2 (en) * | 2016-01-29 | 2021-06-29 | Hewlett Packard Enterprise Development Lp | Target device attestation using a trusted platform module |
| US10873566B2 (en) * | 2016-02-23 | 2020-12-22 | Nicira, Inc. | Distributed firewall in a virtualized computing environment |
| US11038845B2 (en) | 2016-02-23 | 2021-06-15 | Nicira, Inc. | Firewall in a virtualized computing environment using physical network interface controller (PNIC) level firewall rules |
| US10474589B1 (en) * | 2016-03-02 | 2019-11-12 | Janus Technologies, Inc. | Method and apparatus for side-band management of security for a server computer |
| WO2017158407A1 (en) * | 2016-03-18 | 2017-09-21 | Telefonaktiebolaget Lm Ericsson (Publ) | Using nano-services to secure multi-tenant networking in datacenters |
| US20170279826A1 (en) * | 2016-03-22 | 2017-09-28 | Symantec Corporation | Protecting dynamic and short-lived virtual machine instances in cloud environments |
| US20200401432A1 (en) * | 2016-03-31 | 2020-12-24 | Nec Corporation | Management method and management apparatus in network system |
| CN107291525B (zh) * | 2016-04-01 | 2021-06-01 | 华为技术有限公司 | 一种部署虚拟机的方法、宿主机及系统 |
| US10116630B2 (en) * | 2016-04-04 | 2018-10-30 | Bitdefender IPR Management Ltd. | Systems and methods for decrypting network traffic in a virtualized environment |
| WO2017187520A1 (ja) * | 2016-04-26 | 2017-11-02 | 三菱電機株式会社 | 侵入検知装置、侵入検知方法及び侵入検知プログラム |
| US10135727B2 (en) | 2016-04-29 | 2018-11-20 | Nicira, Inc. | Address grouping for distributed service rules |
| US10841273B2 (en) | 2016-04-29 | 2020-11-17 | Nicira, Inc. | Implementing logical DHCP servers in logical networks |
| US10348685B2 (en) | 2016-04-29 | 2019-07-09 | Nicira, Inc. | Priority allocation for distributed service rules |
| US11019167B2 (en) * | 2016-04-29 | 2021-05-25 | Nicira, Inc. | Management of update queues for network controller |
| US10484515B2 (en) | 2016-04-29 | 2019-11-19 | Nicira, Inc. | Implementing logical metadata proxy servers in logical networks |
| US11425095B2 (en) | 2016-05-01 | 2022-08-23 | Nicira, Inc. | Fast ordering of firewall sections and rules |
| US11171920B2 (en) | 2016-05-01 | 2021-11-09 | Nicira, Inc. | Publication of firewall configuration |
| RU2628923C1 (ru) * | 2016-05-20 | 2017-08-22 | Акционерное общество "Лаборатория Касперского" | Система и способ распределения файлов между виртуальными машинами, входящими в распределённую систему виртуальных машин, для выполнения антивирусной проверки |
| US10079919B2 (en) | 2016-05-27 | 2018-09-18 | Solarflare Communications, Inc. | Method, apparatus and computer program product for processing data |
| CN107547480A (zh) * | 2016-06-28 | 2018-01-05 | 华为技术有限公司 | 一种虚拟桌面安全控制的方法、装置和虚拟桌面管理系统 |
| US11082400B2 (en) | 2016-06-29 | 2021-08-03 | Nicira, Inc. | Firewall configuration versioning |
| US11258761B2 (en) | 2016-06-29 | 2022-02-22 | Nicira, Inc. | Self-service firewall configuration |
| US10356182B2 (en) | 2016-07-19 | 2019-07-16 | Telefonaktiebolaget Lm Ericsson (Publ) | Communication stack optimized per application without virtual machine overhead |
| US10798073B2 (en) | 2016-08-26 | 2020-10-06 | Nicira, Inc. | Secure key management protocol for distributed network encryption |
| US10567281B2 (en) * | 2016-08-29 | 2020-02-18 | Vmware, Inc. | Stateful connection optimization over stretched networks using packet introspection |
| US10938837B2 (en) | 2016-08-30 | 2021-03-02 | Nicira, Inc. | Isolated network stack to manage security for virtual machines |
| US9762619B1 (en) | 2016-08-30 | 2017-09-12 | Nicira, Inc. | Multi-layer policy definition and enforcement framework for network virtualization |
| US10608881B2 (en) * | 2016-09-22 | 2020-03-31 | Nicira, Inc. | Application-based network segmentation in a virtualized computing environment |
| US10193862B2 (en) | 2016-11-29 | 2019-01-29 | Vmware, Inc. | Security policy analysis based on detecting new network port connections |
| US10609160B2 (en) | 2016-12-06 | 2020-03-31 | Nicira, Inc. | Performing context-rich attribute-based services on a host |
| US10812451B2 (en) | 2016-12-22 | 2020-10-20 | Nicira, Inc. | Performing appID based firewall services on a host |
| US11032246B2 (en) | 2016-12-22 | 2021-06-08 | Nicira, Inc. | Context based firewall services for data message flows for multiple concurrent users on one machine |
| US10803173B2 (en) | 2016-12-22 | 2020-10-13 | Nicira, Inc. | Performing context-rich attribute-based process control services on a host |
| US10802858B2 (en) | 2016-12-22 | 2020-10-13 | Nicira, Inc. | Collecting and processing contextual attributes on a host |
| US10805332B2 (en) | 2017-07-25 | 2020-10-13 | Nicira, Inc. | Context engine model |
| US10581960B2 (en) | 2016-12-22 | 2020-03-03 | Nicira, Inc. | Performing context-rich attribute-based load balancing on a host |
| US10666617B2 (en) * | 2016-12-31 | 2020-05-26 | ShieldX Networks, Inc. | Intercepting network traffic routed by virtual switches for selective security processing |
| WO2018133035A1 (zh) | 2017-01-20 | 2018-07-26 | 华为技术有限公司 | 用于转发数据包的方法、网卡、主机设备和计算机系统 |
| US10417033B2 (en) * | 2017-01-23 | 2019-09-17 | ShieldX Networks, Inc. | Generating efficient computer security threat signature libraries |
| US10798179B2 (en) * | 2017-02-01 | 2020-10-06 | Amazon Technologies, Inc. | Service endpoint interconnect in a virtual private gateway |
| US10200306B2 (en) | 2017-03-07 | 2019-02-05 | Nicira, Inc. | Visualization of packet tracing operation results |
| US10313926B2 (en) | 2017-05-31 | 2019-06-04 | Nicira, Inc. | Large receive offload (LRO) processing in virtualized computing environments |
| US10868836B1 (en) | 2017-06-07 | 2020-12-15 | Amazon Technologies, Inc. | Dynamic security policy management |
| US10599856B2 (en) * | 2017-06-07 | 2020-03-24 | International Business Machines Corporation | Network security for data storage systems |
| US10735259B2 (en) * | 2017-07-10 | 2020-08-04 | Nicira, Inc. | Virtual switch updates via temporary virtual switch |
| US10951584B2 (en) | 2017-07-31 | 2021-03-16 | Nicira, Inc. | Methods for active-active stateful network service cluster |
| US11296984B2 (en) | 2017-07-31 | 2022-04-05 | Nicira, Inc. | Use of hypervisor for active-active stateful network service cluster |
| US11570092B2 (en) | 2017-07-31 | 2023-01-31 | Nicira, Inc. | Methods for active-active stateful network service cluster |
| US11469953B2 (en) | 2017-09-27 | 2022-10-11 | Intel Corporation | Interworking of legacy appliances in virtualized networks |
| US10116671B1 (en) | 2017-09-28 | 2018-10-30 | International Business Machines Corporation | Distributed denial-of-service attack detection based on shared network flow information |
| US10608887B2 (en) | 2017-10-06 | 2020-03-31 | Nicira, Inc. | Using packet tracing tool to automatically execute packet capture operations |
| US11005771B2 (en) | 2017-10-16 | 2021-05-11 | Mellanox Technologies, Ltd. | Computational accelerator for packet payload operations |
| US11502948B2 (en) | 2017-10-16 | 2022-11-15 | Mellanox Technologies, Ltd. | Computational accelerator for storage operations |
| US12307274B2 (en) * | 2018-06-04 | 2025-05-20 | Srinivas Vegesna | Methods and systems for virtual top-of-rack implementation |
| CN111133417B (zh) * | 2017-10-24 | 2024-08-06 | 英特尔公司 | 硬件辅助的虚拟交换机 |
| US10805181B2 (en) | 2017-10-29 | 2020-10-13 | Nicira, Inc. | Service operation chaining |
| US10841243B2 (en) | 2017-11-08 | 2020-11-17 | Mellanox Technologies, Ltd. | NIC with programmable pipeline |
| US10374827B2 (en) | 2017-11-14 | 2019-08-06 | Nicira, Inc. | Identifier that maps to different networks at different datacenters |
| US10511459B2 (en) | 2017-11-14 | 2019-12-17 | Nicira, Inc. | Selection of managed forwarding element for bridge spanning multiple datacenters |
| US11012420B2 (en) | 2017-11-15 | 2021-05-18 | Nicira, Inc. | Third-party service chaining using packet encapsulation in a flow-based forwarding element |
| US10778651B2 (en) | 2017-11-15 | 2020-09-15 | Nicira, Inc. | Performing context-rich attribute-based encryption on a host |
| TWI648637B (zh) * | 2017-11-30 | 2019-01-21 | 財團法人工業技術研究院 | 於平台部署與操作行動作業系統的系統及其方法 |
| US10938784B2 (en) * | 2017-12-05 | 2021-03-02 | Assured Information Security, Inc. | Dedicating hardware devices to virtual machines in a computer system |
| US10708240B2 (en) * | 2017-12-14 | 2020-07-07 | Mellanox Technologies, Ltd. | Offloading communication security operations to a network interface controller |
| JP7041506B2 (ja) * | 2017-12-20 | 2022-03-24 | 積水ハウス株式会社 | 通信装置保護プログラム |
| US10797910B2 (en) | 2018-01-26 | 2020-10-06 | Nicira, Inc. | Specifying and utilizing paths through a network |
| US10862773B2 (en) * | 2018-01-26 | 2020-12-08 | Nicira, Inc. | Performing services on data messages associated with endpoint machines |
| US10659252B2 (en) | 2018-01-26 | 2020-05-19 | Nicira, Inc | Specifying and utilizing paths through a network |
| US10802893B2 (en) | 2018-01-26 | 2020-10-13 | Nicira, Inc. | Performing process control services on endpoint machines |
| US11153122B2 (en) | 2018-02-19 | 2021-10-19 | Nicira, Inc. | Providing stateful services deployed in redundant gateways connected to asymmetric network |
| US10805192B2 (en) | 2018-03-27 | 2020-10-13 | Nicira, Inc. | Detecting failure of layer 2 service using broadcast messages |
| US10728174B2 (en) | 2018-03-27 | 2020-07-28 | Nicira, Inc. | Incorporating layer 2 service between two interfaces of gateway device |
| US11057385B2 (en) * | 2018-05-24 | 2021-07-06 | Nicira, Inc. | Methods to restrict network file access in guest virtual machines using in-guest agents |
| US11258760B1 (en) | 2018-06-22 | 2022-02-22 | Vmware, Inc. | Stateful distributed web application firewall |
| US10826943B2 (en) | 2018-08-21 | 2020-11-03 | At&T Intellectual Property I, L.P. | Security controller |
| US11595250B2 (en) | 2018-09-02 | 2023-02-28 | Vmware, Inc. | Service insertion at logical network gateway |
| US10944673B2 (en) | 2018-09-02 | 2021-03-09 | Vmware, Inc. | Redirection of data messages at logical network gateway |
| US12608218B2 (en) * | 2018-09-26 | 2026-04-21 | Telefonaktiebolaget Lm Ericsson (Publ) | Methods and apparatus for modifying an allocation of virtualized processing resources for a digital unit based on timing feedback from a radio unit |
| WO2020076302A1 (en) * | 2018-10-09 | 2020-04-16 | Hewlett Packard Enterprise Development Lp | Virtualized network functions |
| US10771318B1 (en) | 2018-10-24 | 2020-09-08 | Vmware, Inc | High availability on a distributed networking platform |
| US11163873B2 (en) | 2018-11-16 | 2021-11-02 | Salesforce.Com, Inc. | Distributed security introspection |
| US11138311B2 (en) | 2018-11-16 | 2021-10-05 | Salesforce.Com, Inc. | Distributed security introspection |
| US10824469B2 (en) | 2018-11-28 | 2020-11-03 | Mellanox Technologies, Ltd. | Reordering avoidance for flows during transition between slow-path handling and fast-path handling |
| CN109802999B (zh) * | 2018-12-28 | 2021-07-13 | 北京指掌易科技有限公司 | 一种通过vsa技术在pc端实现移动应用功能的方法 |
| US11086654B2 (en) | 2019-02-22 | 2021-08-10 | Vmware, Inc. | Providing services by using multiple service planes |
| US11347529B2 (en) * | 2019-03-08 | 2022-05-31 | International Business Machines Corporation | Inject interrupts and exceptions into secure virtual machine |
| US11310202B2 (en) | 2019-03-13 | 2022-04-19 | Vmware, Inc. | Sharing of firewall rules among multiple workloads in a hypervisor |
| CN111865801B (zh) * | 2019-04-24 | 2021-10-22 | 厦门网宿有限公司 | 一种基于Virtio端口传输数据的方法和系统 |
| JP7396615B2 (ja) * | 2019-06-27 | 2023-12-12 | 株式会社エヴリカ | 情報処理装置、方法およびプログラム |
| FR3098615B1 (fr) * | 2019-07-08 | 2021-07-02 | Secnap Network Security Corp | Protection contre les intrusions avant routage pour environnements informatiques virtuels en nuage |
| US11297106B2 (en) | 2019-07-08 | 2022-04-05 | Secnap Network Security Corp. | Pre-routing intrusion protection for cloud based virtual computing environments |
| US20210037061A1 (en) * | 2019-07-31 | 2021-02-04 | At&T Intellectual Property I, L.P. | Managing machine learned security for computer program products |
| US11283717B2 (en) | 2019-10-30 | 2022-03-22 | Vmware, Inc. | Distributed fault tolerant service chain |
| US11140218B2 (en) | 2019-10-30 | 2021-10-05 | Vmware, Inc. | Distributed service chain across multiple clouds |
| JP7411895B2 (ja) * | 2019-12-05 | 2024-01-12 | パナソニックIpマネジメント株式会社 | 情報処理装置、異常検知方法およびコンピュータプログラム |
| US11539718B2 (en) | 2020-01-10 | 2022-12-27 | Vmware, Inc. | Efficiently performing intrusion detection |
| US11223494B2 (en) | 2020-01-13 | 2022-01-11 | Vmware, Inc. | Service insertion for multicast traffic at boundary |
| US11283699B2 (en) | 2020-01-17 | 2022-03-22 | Vmware, Inc. | Practical overlay network latency measurement in datacenter |
| US11659061B2 (en) | 2020-01-20 | 2023-05-23 | Vmware, Inc. | Method of adjusting service function chains to improve network performance |
| US11153406B2 (en) | 2020-01-20 | 2021-10-19 | Vmware, Inc. | Method of network performance visualization of service function chains |
| US11016799B1 (en) | 2020-01-30 | 2021-05-25 | Coupang Corp. | Systems and methods for centralization of server initialization information |
| CN113467988B (zh) * | 2020-03-30 | 2025-03-14 | 阿里巴巴集团控股有限公司 | 容灾系统的处理方法、装置和系统 |
| US11438257B2 (en) | 2020-04-06 | 2022-09-06 | Vmware, Inc. | Generating forward and reverse direction connection-tracking records for service paths at a network edge |
| US11496437B2 (en) | 2020-04-06 | 2022-11-08 | Vmware, Inc. | Selective ARP proxy |
| US11635970B2 (en) | 2020-04-17 | 2023-04-25 | Nutanix, Inc. | Integrated network boot operating system installation leveraging hyperconverged storage |
| US11962518B2 (en) | 2020-06-02 | 2024-04-16 | VMware LLC | Hardware acceleration techniques using flow selection |
| US11108728B1 (en) | 2020-07-24 | 2021-08-31 | Vmware, Inc. | Fast distribution of port identifiers for rule processing |
| US11196628B1 (en) | 2020-07-29 | 2021-12-07 | Vmware, Inc. | Monitoring container clusters |
| US11570090B2 (en) | 2020-07-29 | 2023-01-31 | Vmware, Inc. | Flow tracing operation in container cluster |
| US11558426B2 (en) | 2020-07-29 | 2023-01-17 | Vmware, Inc. | Connection tracking for container cluster |
| CN114095153B (zh) | 2020-08-05 | 2024-12-17 | 迈络思科技有限公司 | 密码数据通信装置 |
| IL276538B2 (en) | 2020-08-05 | 2023-08-01 | Mellanox Technologies Ltd | A cryptographic device for data communication |
| US11716383B2 (en) | 2020-09-28 | 2023-08-01 | Vmware, Inc. | Accessing multiple external storages to present an emulated local storage through a NIC |
| US11792134B2 (en) | 2020-09-28 | 2023-10-17 | Vmware, Inc. | Configuring PNIC to perform flow processing offload using virtual port identifiers |
| US11593278B2 (en) | 2020-09-28 | 2023-02-28 | Vmware, Inc. | Using machine executing on a NIC to access a third party storage not supported by a NIC or host |
| US11636053B2 (en) | 2020-09-28 | 2023-04-25 | Vmware, Inc. | Emulating a local storage by accessing an external storage through a shared port of a NIC |
| US11875172B2 (en) | 2020-09-28 | 2024-01-16 | VMware LLC | Bare metal computer for booting copies of VM images on multiple computing devices using a smart NIC |
| US12021759B2 (en) | 2020-09-28 | 2024-06-25 | VMware LLC | Packet processing with hardware offload units |
| US11677789B2 (en) * | 2020-12-11 | 2023-06-13 | Amazon Technologies, Inc. | Intent-based governance |
| US11734043B2 (en) | 2020-12-15 | 2023-08-22 | Vmware, Inc. | Providing stateful services in a scalable manner for machines executing on host computers |
| US11611625B2 (en) | 2020-12-15 | 2023-03-21 | Vmware, Inc. | Providing stateful services in a scalable manner for machines executing on host computers |
| US11736436B2 (en) | 2020-12-31 | 2023-08-22 | Vmware, Inc. | Identifying routes with indirect addressing in a datacenter |
| US11336533B1 (en) | 2021-01-08 | 2022-05-17 | Vmware, Inc. | Network visualization of correlations between logical elements and associated physical elements |
| US11700274B1 (en) | 2021-02-04 | 2023-07-11 | Cisco Technology, Inc. | Systems and methods for protecting pod deployment |
| US11934658B2 (en) | 2021-03-25 | 2024-03-19 | Mellanox Technologies, Ltd. | Enhanced storage protocol emulation in a peripheral device |
| US11934333B2 (en) | 2021-03-25 | 2024-03-19 | Mellanox Technologies, Ltd. | Storage protocol emulation in a peripheral device |
| US11805101B2 (en) | 2021-04-06 | 2023-10-31 | Vmware, Inc. | Secured suppression of address discovery messages |
| US11687210B2 (en) | 2021-07-05 | 2023-06-27 | Vmware, Inc. | Criteria-based expansion of group nodes in a network topology visualization |
| US12505200B2 (en) | 2022-05-23 | 2025-12-23 | Wiz, Inc. | Techniques for improved virtual instance inspection utilizing disk cloning |
| US12579251B2 (en) | 2021-11-24 | 2026-03-17 | Wiz, Inc. | System and method for detecting excessive permissions in identity and access management |
| US12278840B1 (en) | 2021-07-16 | 2025-04-15 | Wiz, Inc. | Efficient representation of multiple cloud computing environments through unified identity mapping |
| US12278819B1 (en) | 2021-07-16 | 2025-04-15 | Wiz, Inc. | Cybersecurity threat detection utilizing unified identity mapping and permission detection |
| US20240137382A1 (en) | 2021-07-16 | 2024-04-25 | Wiz, Inc. | Techniques for cybersecurity identity risk detection utilizing disk cloning and unified identity mapping |
| US11711278B2 (en) | 2021-07-24 | 2023-07-25 | Vmware, Inc. | Visualization of flow trace operation across multiple sites |
| US11855862B2 (en) | 2021-09-17 | 2023-12-26 | Vmware, Inc. | Tagging packets for monitoring and analysis |
| EP4427430A1 (en) * | 2021-11-01 | 2024-09-11 | Microsoft Technology Licensing, LLC | Transparent network service chaining |
| CN114024747A (zh) * | 2021-11-04 | 2022-02-08 | 全球能源互联网研究院有限公司 | 基于软件定义nfv的安全服务链编排部署方法及系统 |
| US12267366B2 (en) * | 2021-11-22 | 2025-04-01 | Nutanix, Inc. | System and method for scheduling virtual machines based on security policy |
| US12489781B2 (en) | 2021-11-24 | 2025-12-02 | Wiz, Inc. | Techniques for lateral movement detection in a cloud computing environment |
| CA3238579A1 (en) | 2021-11-24 | 2023-06-01 | Wiz, Inc. | Detecting vulnerabilities in configuration code of a cloud environment utilizing infrastructure as code |
| US11995024B2 (en) | 2021-12-22 | 2024-05-28 | VMware LLC | State sharing between smart NICs |
| US11863376B2 (en) | 2021-12-22 | 2024-01-02 | Vmware, Inc. | Smart NIC leader election |
| US12229578B2 (en) | 2021-12-22 | 2025-02-18 | VMware LLC | Teaming of smart NICs |
| US12081656B1 (en) | 2021-12-27 | 2024-09-03 | Wiz, Inc. | Techniques for circumventing provider-imposed limitations in snapshot inspection of disks for cybersecurity |
| US12219048B1 (en) | 2021-12-27 | 2025-02-04 | Wiz, Inc. | Techniques for encrypted disk cybersecurity inspection utilizing disk cloning |
| US11936785B1 (en) | 2021-12-27 | 2024-03-19 | Wiz, Inc. | System and method for encrypted disk inspection utilizing disk cloning techniques |
| US11799761B2 (en) | 2022-01-07 | 2023-10-24 | Vmware, Inc. | Scaling edge services with minimal disruption |
| KR102779468B1 (ko) * | 2022-01-18 | 2025-03-12 | 주식회사 카카오엔터프라이즈 | 클라우드 컴퓨팅 환경에서의 스마트닉 기반 패킷 처리 가속화 및 그것의 운영 자동화 시스템 |
| US12531881B2 (en) | 2022-01-31 | 2026-01-20 | Wiz, Inc. | Detection of cybersecurity threats utilizing established baselines |
| US11841945B1 (en) | 2022-01-31 | 2023-12-12 | Wiz, Inc. | System and method for cybersecurity threat detection utilizing static and runtime data |
| US12218976B2 (en) * | 2022-02-02 | 2025-02-04 | Fortinet, Inc. | Systems and methods for container server protection |
| US11962564B2 (en) | 2022-02-15 | 2024-04-16 | VMware LLC | Anycast address for network address translation at edge |
| US11936693B2 (en) | 2022-04-13 | 2024-03-19 | Wiz, Inc. | System and method for applying a policy on a network path |
| US12443720B2 (en) | 2022-08-10 | 2025-10-14 | Wiz, Inc. | Techniques for detecting applications paths utilizing exposure analysis |
| US12395488B2 (en) * | 2022-04-13 | 2025-08-19 | Wiz, Inc. | Techniques for analyzing external exposure in cloud environments |
| US12244627B2 (en) | 2022-04-13 | 2025-03-04 | Wiz, Inc. | Techniques for active inspection of vulnerability exploitation using exposure |
| US12267326B2 (en) | 2022-04-13 | 2025-04-01 | Wiz, Inc. | Techniques for detecting resources without authentication using exposure analysis |
| US12212586B2 (en) | 2022-05-23 | 2025-01-28 | Wiz, Inc. | Techniques for cybersecurity inspection based on runtime data and static analysis from cloned resources |
| US12506755B2 (en) | 2022-05-23 | 2025-12-23 | Wiz, Inc. | Technology discovery techniques in cloud computing environments utilizing disk cloning |
| US12287899B2 (en) | 2022-05-23 | 2025-04-29 | Wiz, Inc. | Techniques for detecting sensitive data in cloud computing environments utilizing cloning |
| US12217079B2 (en) | 2022-05-23 | 2025-02-04 | Wiz, Inc. | Detecting security exceptions across multiple compute environments |
| US12061719B2 (en) | 2022-09-28 | 2024-08-13 | Wiz, Inc. | System and method for agentless detection of sensitive data in computing environments |
| US12373237B2 (en) | 2022-05-27 | 2025-07-29 | VMware LLC | Logical memory addressing by smart NIC across multiple devices |
| US11928367B2 (en) | 2022-06-21 | 2024-03-12 | VMware LLC | Logical memory addressing for network devices |
| US11899594B2 (en) | 2022-06-21 | 2024-02-13 | VMware LLC | Maintenance of data message classification cache on smart NIC |
| US12481444B2 (en) | 2022-06-21 | 2025-11-25 | VMware LLC | Smart NIC responding to requests from client device |
| US11928062B2 (en) | 2022-06-21 | 2024-03-12 | VMware LLC | Accelerating data message classification with smart NICs |
| US12107832B2 (en) | 2022-07-14 | 2024-10-01 | Bank Of America Corporation | System for establishing secure communication channels for peripheral hardware devices |
| US12470621B2 (en) | 2022-07-22 | 2025-11-11 | VMware LLC | Transparent load balancing |
| US20240036898A1 (en) * | 2022-07-28 | 2024-02-01 | Vmware, Inc. | Offloading stateful services from guest machines to host resources |
| US20240039803A1 (en) * | 2022-07-28 | 2024-02-01 | Vmware, Inc. | Offloading stateful services from guest machines to host resources |
| US12117948B2 (en) | 2022-10-31 | 2024-10-15 | Mellanox Technologies, Ltd. | Data processing unit with transparent root complex |
| US12007921B2 (en) | 2022-11-02 | 2024-06-11 | Mellanox Technologies, Ltd. | Programmable user-defined peripheral-bus device implementation using data-plane accelerator (DPA) |
| US12452219B2 (en) | 2023-06-01 | 2025-10-21 | Mellanox Technologies, Ltd | Network device with datagram transport layer security selective software offload |
| US20250317477A1 (en) * | 2024-04-09 | 2025-10-09 | Cisco Technology, Inc. | Policy-based transparent packet inspection for last mile zero-trust workload protection |
| US12547543B2 (en) | 2024-07-31 | 2026-02-10 | Mellanox Technologies, Ltd. | Cache coherency |
Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20070266433A1 (en) * | 2006-03-03 | 2007-11-15 | Hezi Moore | System and Method for Securing Information in a Virtual Computing Environment |
| US20090158432A1 (en) * | 2007-12-12 | 2009-06-18 | Yufeng Zheng | On-Access Anti-Virus Mechanism for Virtual Machine Architecture |
| WO2012003048A1 (en) * | 2010-06-29 | 2012-01-05 | Symantec Corportation | Systems and methods for sharing the results of analyses among virtual machines |
| JP2012003367A (ja) * | 2010-06-15 | 2012-01-05 | Fuji Xerox Co Ltd | 監視ポータル、監視システム、端末、そのプログラム |
| WO2012078690A1 (en) * | 2010-12-07 | 2012-06-14 | Microsoft Corporation | Antimalware protection of virtual machines |
Family Cites Families (50)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US6073142A (en) | 1997-06-23 | 2000-06-06 | Park City Group | Automated post office based rule analysis of e-mail messages and other data objects for controlled distribution in network environments |
| US5987610A (en) | 1998-02-12 | 1999-11-16 | Ameritech Corporation | Computer virus screening methods and systems |
| US6460050B1 (en) | 1999-12-22 | 2002-10-01 | Mark Raymond Pace | Distributed content identification system |
| US6901519B1 (en) | 2000-06-22 | 2005-05-31 | Infobahn, Inc. | E-mail virus protection system and method |
| JP4018900B2 (ja) * | 2001-11-22 | 2007-12-05 | 株式会社日立製作所 | 仮想計算機システム及びプログラム |
| US20080022376A1 (en) * | 2006-06-23 | 2008-01-24 | Lenovo (Beijing) Limited | System and method for hardware access control |
| US8707383B2 (en) * | 2006-08-16 | 2014-04-22 | International Business Machines Corporation | Computer workload management with security policy enforcement |
| US8353031B1 (en) * | 2006-09-25 | 2013-01-08 | Symantec Corporation | Virtual security appliance |
| US9015703B2 (en) * | 2006-10-17 | 2015-04-21 | Manageiq, Inc. | Enforcement of compliance policies in managed virtual systems |
| US8185893B2 (en) * | 2006-10-27 | 2012-05-22 | Hewlett-Packard Development Company, L.P. | Starting up at least one virtual machine in a physical machine by a load balancer |
| US8381209B2 (en) * | 2007-01-03 | 2013-02-19 | International Business Machines Corporation | Moveable access control list (ACL) mechanisms for hypervisors and virtual machines and virtual port firewalls |
| WO2008108868A1 (en) | 2007-03-01 | 2008-09-12 | Reflex Security, Inc. | System and method for implementing a virtualized security platform |
| US20090328193A1 (en) * | 2007-07-20 | 2009-12-31 | Hezi Moore | System and Method for Implementing a Virtualized Security Platform |
| US8250641B2 (en) | 2007-09-17 | 2012-08-21 | Intel Corporation | Method and apparatus for dynamic switching and real time security control on virtualized systems |
| EP2597816B1 (en) * | 2007-09-26 | 2019-09-11 | Nicira Inc. | Network operating system for managing and securing networks |
| US8276208B2 (en) * | 2007-12-31 | 2012-09-25 | Intel Corporation | Security-level enforcement in virtual-machine fail-over |
| US8443440B2 (en) * | 2008-04-05 | 2013-05-14 | Trend Micro Incorporated | System and method for intelligent coordination of host and guest intrusion prevention in virtualized environment |
| US8195774B2 (en) * | 2008-05-23 | 2012-06-05 | Vmware, Inc. | Distributed virtual switch for virtualized computer systems |
| CN101309180B (zh) * | 2008-06-21 | 2010-12-08 | 华中科技大学 | 一种适用于虚拟机环境的安全网络入侵检测系统 |
| US7962647B2 (en) | 2008-11-24 | 2011-06-14 | Vmware, Inc. | Application delivery control module for virtual network switch |
| US8032660B2 (en) | 2008-12-30 | 2011-10-04 | Intel Corporation | Apparatus and method for managing subscription requests for a network interface component |
| EP2401683A4 (en) * | 2009-02-27 | 2015-07-29 | Broadcom Corp | METHOD AND SYSTEM FOR NETWORKING VIRTUAL MACHINES |
| US8359386B2 (en) * | 2009-04-16 | 2013-01-22 | Dell Products, Lp | System and method of migrating virtualized environments |
| CN102460393B (zh) | 2009-05-01 | 2014-05-07 | 思杰系统有限公司 | 用于在虚拟存储资源之间建立云桥的系统和方法 |
| US8341505B2 (en) * | 2009-05-08 | 2012-12-25 | Oracle America, Inc. | Enforcing network bandwidth partitioning for virtual execution environments with direct access to network hardware |
| CN101937357B (zh) * | 2009-07-01 | 2013-11-06 | 华为技术有限公司 | 一种虚拟机迁移决策方法、装置及系统 |
| US8726334B2 (en) * | 2009-12-09 | 2014-05-13 | Microsoft Corporation | Model based systems management in virtualized and non-virtualized environments |
| CN101841451B (zh) * | 2009-12-30 | 2013-01-02 | 北京世纪互联宽带数据中心有限公司 | 一种云主机基于虚拟局域网的限速方法和系统 |
| JP2011186701A (ja) * | 2010-03-08 | 2011-09-22 | Nec Corp | リソース割当装置、リソース割当方法、およびリソース割当プログラム |
| CN103038749B (zh) | 2010-07-01 | 2017-09-15 | 纽戴纳公司 | 为了优化群集特定配置的使用而按进程类型在群集之间分割进程 |
| JP5435133B2 (ja) * | 2010-07-13 | 2014-03-05 | 富士通株式会社 | 情報処理装置、情報処理装置の制御方法及びプログラム |
| WO2012101893A1 (ja) * | 2011-01-25 | 2012-08-02 | 日本電気株式会社 | セキュリティポリシ強制システム及びセキュリティポリシ強制方法 |
| US8566899B2 (en) * | 2011-03-16 | 2013-10-22 | Symantec Corporation | Techniques for securing a checked-out virtual machine in a virtual desktop infrastructure |
| US20120291024A1 (en) * | 2011-05-13 | 2012-11-15 | International Business Machines Corporation | Virtual Managed Network |
| US9110703B2 (en) * | 2011-06-07 | 2015-08-18 | Hewlett-Packard Development Company, L.P. | Virtual machine packet processing |
| US8923294B2 (en) * | 2011-06-28 | 2014-12-30 | Polytechnic Institute Of New York University | Dynamically provisioning middleboxes |
| US9139982B2 (en) | 2011-06-28 | 2015-09-22 | Caterpillar Inc. | Hydraulic control system having swing energy recovery |
| US8893274B2 (en) * | 2011-08-03 | 2014-11-18 | Trend Micro, Inc. | Cross-VM network filtering |
| US20130034094A1 (en) * | 2011-08-05 | 2013-02-07 | International Business Machines Corporation | Virtual Switch Data Control In A Distributed Overlay Network |
| US8797914B2 (en) * | 2011-09-12 | 2014-08-05 | Microsoft Corporation | Unified policy management for extensible virtual switches |
| US8631458B1 (en) * | 2011-09-29 | 2014-01-14 | Symantec Corporation | Method and apparatus for elastic (re)allocation of enterprise workloads on clouds while minimizing compliance costs |
| US20150135178A1 (en) * | 2012-03-08 | 2015-05-14 | Anna Fischer | Modifying virtual machine communications |
| US20130263208A1 (en) * | 2012-04-02 | 2013-10-03 | Narsimha Reddy Challa | Managing virtual machines in a cloud computing system |
| CN102739645B (zh) | 2012-04-23 | 2016-03-16 | 杭州华三通信技术有限公司 | 虚拟机安全策略的迁移方法及装置 |
| US9304801B2 (en) * | 2012-06-12 | 2016-04-05 | TELEFONAKTIEBOLAGET L M ERRICSSON (publ) | Elastic enforcement layer for cloud security using SDN |
| US9250884B2 (en) * | 2012-07-17 | 2016-02-02 | Oracle International Corporation | Automatic deployment of software applications to meet regulatory compliance requirements |
| US8966573B2 (en) * | 2012-07-20 | 2015-02-24 | Ca, Inc. | Self-generation of virtual machine security clusters |
| US9104492B2 (en) * | 2012-09-04 | 2015-08-11 | Wisconsin Alumni Research Foundation | Cloud-based middlebox management system |
| US20140101656A1 (en) * | 2012-10-10 | 2014-04-10 | Zhongwen Zhu | Virtual firewall mobility |
| US9571507B2 (en) | 2012-10-21 | 2017-02-14 | Mcafee, Inc. | Providing a virtual security appliance architecture to a virtual cloud infrastructure |
-
2012
- 2012-10-21 US US13/656,730 patent/US9571507B2/en active Active
-
2013
- 2013-10-20 CN CN201380050646.4A patent/CN104685507B/zh active Active
- 2013-10-20 CN CN201810021935.6A patent/CN108062482B/zh active Active
- 2013-10-20 JP JP2015534834A patent/JP5890595B2/ja active Active
- 2013-10-20 WO PCT/US2013/065806 patent/WO2014063129A1/en not_active Ceased
- 2013-10-20 EP EP13846316.1A patent/EP2909780B1/en active Active
-
2016
- 2016-02-18 JP JP2016029265A patent/JP6151394B2/ja active Active
-
2017
- 2017-01-06 US US15/400,101 patent/US11025647B2/en active Active
- 2017-05-26 JP JP2017104683A patent/JP6335363B2/ja active Active
-
2021
- 2021-05-13 US US17/320,129 patent/US12218956B2/en active Active
Patent Citations (5)
| Publication number | Priority date | Publication date | Assignee | Title |
|---|---|---|---|---|
| US20070266433A1 (en) * | 2006-03-03 | 2007-11-15 | Hezi Moore | System and Method for Securing Information in a Virtual Computing Environment |
| US20090158432A1 (en) * | 2007-12-12 | 2009-06-18 | Yufeng Zheng | On-Access Anti-Virus Mechanism for Virtual Machine Architecture |
| JP2012003367A (ja) * | 2010-06-15 | 2012-01-05 | Fuji Xerox Co Ltd | 監視ポータル、監視システム、端末、そのプログラム |
| WO2012003048A1 (en) * | 2010-06-29 | 2012-01-05 | Symantec Corportation | Systems and methods for sharing the results of analyses among virtual machines |
| WO2012078690A1 (en) * | 2010-12-07 | 2012-06-14 | Microsoft Corporation | Antimalware protection of virtual machines |
Also Published As
| Publication number | Publication date |
|---|---|
| CN104685507A (zh) | 2015-06-03 |
| JP6151394B2 (ja) | 2017-06-21 |
| US20210344692A1 (en) | 2021-11-04 |
| US11025647B2 (en) | 2021-06-01 |
| US20140115578A1 (en) | 2014-04-24 |
| CN108062482B (zh) | 2021-09-17 |
| JP2016129043A (ja) | 2016-07-14 |
| CN104685507B (zh) | 2018-02-09 |
| CN108062482A (zh) | 2018-05-22 |
| US20170264622A1 (en) | 2017-09-14 |
| US12218956B2 (en) | 2025-02-04 |
| JP6335363B2 (ja) | 2018-05-30 |
| US9571507B2 (en) | 2017-02-14 |
| EP2909780A4 (en) | 2016-06-01 |
| JP5890595B2 (ja) | 2016-03-22 |
| WO2014063129A1 (en) | 2014-04-24 |
| JP2015536003A (ja) | 2015-12-17 |
| EP2909780B1 (en) | 2019-11-27 |
| EP2909780A1 (en) | 2015-08-26 |
Similar Documents
| Publication | Publication Date | Title |
|---|---|---|
| JP6335363B2 (ja) | 仮想クラウドインフラストラクチャへの仮想セキュリティ装置アーキテクチャの提供 | |
| US11700236B2 (en) | Packet steering to a host-based firewall in virtualized environments | |
| CN111355666B (zh) | 促进针对计算机网络中的服务链的流对称的方法和网络控制器 | |
| US10437775B2 (en) | Remote direct memory access in computing systems | |
| JP5976942B2 (ja) | ポリシーベースのデータセンタネットワーク自動化を提供するシステムおよび方法 | |
| US10698714B2 (en) | Application/context-based management of virtual networks using customizable workflows | |
| US9596159B2 (en) | Finding latency through a physical network in a virtualized network | |
| JP2022522260A (ja) | マルチクラウド環境におけるオンデマンドフローに基づくポリシー実施のためのシステムおよび方法 | |
| CN112470436A (zh) | 使用srv6和bgp的多云连通性 | |
| US20170126559A1 (en) | Performing logical network functionality within data compute nodes | |
| US20150172183A1 (en) | Managing data flows in overlay networks | |
| US9292351B2 (en) | Distributed fabric architecture in a cloud computing environment | |
| US9716688B1 (en) | VPN for containers and virtual machines in local area networks | |
| US9374308B2 (en) | Openflow switch mode transition processing | |
| US20220210127A1 (en) | Attribute-based firewall rule enforcement |
Legal Events
| Date | Code | Title | Description |
|---|---|---|---|
| TRDD | Decision of grant or rejection written | ||
| A01 | Written decision to grant a patent or to grant a registration (utility model) |
Free format text: JAPANESE INTERMEDIATE CODE: A01 Effective date: 20180403 |
|
| A61 | First payment of annual fees (during grant procedure) |
Free format text: JAPANESE INTERMEDIATE CODE: A61 Effective date: 20180427 |
|
| R150 | Certificate of patent or registration of utility model |
Ref document number: 6335363 Country of ref document: JP Free format text: JAPANESE INTERMEDIATE CODE: R150 |
|
| R250 | Receipt of annual fees |
Free format text: JAPANESE INTERMEDIATE CODE: R250 |
|
| R250 | Receipt of annual fees |
Free format text: JAPANESE INTERMEDIATE CODE: R250 |
|
| S111 | Request for change of ownership or part of ownership |
Free format text: JAPANESE INTERMEDIATE CODE: R313113 |
|
| S531 | Written request for registration of change of domicile |
Free format text: JAPANESE INTERMEDIATE CODE: R313531 |
|
| R350 | Written notification of registration of transfer |
Free format text: JAPANESE INTERMEDIATE CODE: R350 |
|
| R250 | Receipt of annual fees |
Free format text: JAPANESE INTERMEDIATE CODE: R250 |
|
| R250 | Receipt of annual fees |
Free format text: JAPANESE INTERMEDIATE CODE: R250 |
|
| R250 | Receipt of annual fees |
Free format text: JAPANESE INTERMEDIATE CODE: R250 |