US 11,989,298 B2
Methods and apparatus to validate and restore machine configurations
Nilesh Awate, Pune (IN); Goresh Musalay, Pune (IN); Sachin Shinde, Pune (IN); and V S V Vijay, Pune (IN)
Assigned to VMware LLC, Palo Alto, CA (US)
Filed by VMware LLC, Palo Alto, CA (US)
Filed on Aug. 2, 2021, as Appl. No. 17/392,127.
Application 17/392,127 is a continuation of application No. 16/215,612, filed on Dec. 10, 2018, granted, now 11,080,402.
Claims priority of application No. 201841022336 (IN), filed on Jun. 14, 2018.
Prior Publication US 2022/0027473 A1, Jan. 27, 2022
This patent is subject to a terminal disclaimer.
Int. Cl. G06F 21/57 (2013.01); G06F 21/53 (2013.01); G06F 21/60 (2013.01); H04L 41/0893 (2022.01); H04N 21/443 (2011.01)
CPC G06F 21/57 (2013.01) [G06F 21/53 (2013.01); G06F 21/602 (2013.01); H04L 41/0893 (2013.01); H04N 21/4437 (2013.01); G06F 2212/152 (2013.01); G06F 2221/00 (2013.01); G06F 2221/034 (2013.01)] 20 Claims
OG exemplary drawing
 
1. An apparatus comprising:
at least one memory;
instructions in the apparatus; and
processor circuitry to execute the instructions to:
obtain first context information of a set of configuration update events;
obtain second context information of a first subsequent configuration update event;
transmit the set of configuration update events to a security manager for generation of a policy including allowable configuration update events and responses to unallowable configuration update events;
determine whether the first subsequent configuration update event is an event covered by a rule of the policy:
in response to determining that the first subsequent configuration update event is not covered by the rule of the policy:
transmit the first subsequent configuration update event to the security manager for generation of an updated policy; and
enable, based on the updated policy, a comparison between third context information of a second subsequent configuration update event to the updated policy, the processor circuitry to determine, based on the comparison, whether to transmit the second subsequent configuration update event to the security manager for generation of a second updated policy.