发明名称 Method and apparatus to detect and block unauthorized MAC address by virtual machine aware network switches
摘要 The disclosure relates to a method and apparatus for detecting and blocking unauthorized MAC addresses used by virtual machines. In one embodiment, the disclosure provides automated and consistent verification of VM traffic against values assigned to each VM by network administrator. In another embodiment, the disclosure provides for validating a newly discovered VM by comparing its attributes with the corresponding description of the known VMs stored at a database. A re-validation check may also be implemented. If the VM is validated, the VM will be processed according to network policy to support features including VMReady. If the VM fails validation, other actions can be taken.
申请公布号 US9276953(B2) 申请公布日期 2016.03.01
申请号 US201313975310 申请日期 2013.08.24
申请人 International Business Machines Corporation 发明人 Abidi Vasmi Mohammad;David Marius-Cristian;Ghosh Nirapad;Sait Tamanna Zackaria;Udrea Eugen-Cristian
分类号 H04L29/06;H04L12/54 主分类号 H04L29/06
代理机构 代理人 Vallone Mark C.
主权项 1. A method for verifying identity of a virtual machine (VM), the method comprising: receiving, at a switch associated with a VM group, an initial message from a first VM of the VM group through a port, the first VM managed by a first hypervisor; the switch determining, based on configuration information associated with the switch, that the port is not a trusted port, the configuration information indicating that the first hypervisor is not connected to the switch through the port; in response to said determining that the port is not a trusted port, the switch: retrieving attribute data relating to the initial message from a database;determining, based on the attribute data, that the port the initial message arrived through is a trusted port;querying the attribute data; andascertaining whether the first VM is valid, wherein said ascertaining is affirmative if the attribute data matches with at least one attribute included in the initial message, and wherein said ascertaining is negative if the attribute data does not match with at least one attribute included in the initial message, the attribute data including at least one of a first VM media access control (MAC) Address, a VM universally unique identifier (UUID), a switch port address or a switch ID.
地址 Armonk NY US