US2017134436A1PendingUtilityA1

System and method for preventing data loss using virtual machine wrapped applications

Assignee: MCAFEE INCPriority: Nov 10, 2009Filed: Jan 23, 2017Published: May 11, 2017
Est. expiryNov 10, 2029(~3.3 yrs left)· nominal 20-yr term from priority
G06F 21/6281H04L 63/0263G06F 21/53G06F 21/128H04L 63/20H04L 63/205
38
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

A method in one example implementation includes selecting at least one criterion for controlling data transmission from within a virtual machine. At least one application is included within the virtual machine, which includes a policy module. The selected criterion corresponds to at least one policy associated with the policy module. The method also includes evaluating the selected criterion of the policy to permit an attempt to transmit the data from within the virtual machine. In more specific embodiments, the policy may include a plurality of criteria with a first selected criterion permitting transmission of the data to a first application and a second selected criterion prohibiting transmission of the data to a second application. In another specific embodiment, the method may include updating the policy module through an administration module to modify the selected criterion.

Claims

exact text as granted — not AI-modified
1 - 20 . (canceled) 
     
     
         21 . A method implemented by a system including an operating system and a virtual machine monitor, the method comprising:
 downloading a browser wrapped in a virtual machine, based on a determination that the browser is not being used in an access to an institution;   updating the browser if the browser is determined to not be current; and   allowing a connection to the institution through the browser, the system including the browser, the operating system underlying the virtual machine.   
     
     
         22 . The method of  claim 21 , further comprising:
 determining whether the browser is allowed to share data, based on an evaluation of a firewall policy.   
     
     
         23 . The method of  claim 22 , wherein the browser shares the data using a copy buffer or a paste buffer, and the operating system cannot access the copy buffer or the paste buffer. 
     
     
         24 . The method of  claim 21 , further comprising:
 evaluating a criterion of a policy to determine whether to permit access to the virtual machine, based on a determination that a master image is not available, the master image corresponding to a version of the browser or a version of the virtual machine.   
     
     
         25 . The method of  claim 21 , further comprising:
 comparing the browser to a master image, the master image corresponding to a version of the browser or a version of the virtual machine.   
     
     
         26 . The method of  claim 21 , further comprising:
 performing a self-integrity check, wherein the allowing is performed if the self-integrity check passes.   
     
     
         27 . A system, comprising:
 a memory element that stores instructions; and   a processor configured to execute a browser wrapped in a virtual machine, an operating system underlying the virtual machine, wherein the browser is downloaded based on a determination that the browser is not being used in an access to an institution, the browser is updated if the browser is determined to not be current, and a connection to the institution is allowed through the browser.   
     
     
         28 . The system of  claim 27 , wherein the browser shares data, based on an evaluation of a firewall policy. 
     
     
         29 . The system of  claim 28 , wherein the browser shares the data using a copy buffer or a paste buffer, and the operating system cannot access the copy buffer or the paste buffer. 
     
     
         30 . The system of  claim 27 , wherein a criterion of a policy is evaluated to determine whether to permit access to the virtual machine, based on a determination that a master image is not available, the master image corresponding to a version of the browser or a version of the virtual machine. 
     
     
         31 . The system of  claim 27 , wherein the browser is compared to a master image, the master image corresponding to a version of the browser or a version of the virtual machine. 
     
     
         32 . The system of  claim 27 , wherein a self-integrity check is performed, and the connection is allowed if the self-integrity check passes. 
     
     
         33 . The system of  claim 27 , wherein a policy prohibits accessing the virtual machine if a client device requests access to the virtual machine from an unsecured network environment. 
     
     
         34 . A non-transitory computer readable storage medium, comprising:
 instructions to download a browser wrapped in a virtual machine, based on a determination that the browser is not being used in an access to an institution, an operating system underlying the virtual machine;   instructions to update the browser if the browser is determined to not be current; and   instructions to allow a connection to the institution through the browser.   
     
     
         35 . The medium of  claim 34 , further comprising:
 instructions to determine whether the browser is allowed to share data, based on an evaluation of a firewall policy.   
     
     
         36 . The medium of  claim 35 , wherein the browser shares the data using a copy buffer or a paste buffer, and the operating system cannot access the copy buffer or the paste buffer. 
     
     
         37 . The medium of  claim 34 , further comprising:
 instructions to evaluate a criterion of a policy to determine whether to permit access to the virtual machine, based on a determination that a master image is not available, the master image corresponding to a version of the browser or a version of the virtual machine.   
     
     
         38 . The medium of  claim 34 , further comprising:
 instructions to compare the browser to a master image, the master image corresponding to a version of the browser or a version of the virtual machine.   
     
     
         39 . The medium of  claim 34 , further comprising:
 instructions to perform a self-integrity check, wherein the connection is allowed if the self-integrity check passes.   
     
     
         40 . The medium of  claim 34 , wherein a policy prohibits accessing the virtual machine if a client device requests access to the virtual machine from an unsecured network environment.

Join the waitlist — get patent alerts

Track US2017134436A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.