The patent badge is an abbreviated version of the USPTO patent document. The patent badge does contain a link to the full patent document.

The patent badge is an abbreviated version of the USPTO patent document. The patent badge covers the following: Patent number, Date patent was issued, Date patent was filed, Title of the patent, Applicant, Inventor, Assignee, Attorney firm, Primary examiner, Assistant examiner, CPCs, and Abstract. The patent badge does contain a link to the full patent document (in Adobe Acrobat format, aka pdf). To download or print any patent click here.

Date of Patent:
Jun. 30, 2020

Filed:

Nov. 09, 2017
Applicant:

Hysolate Ltd., Tel Aviv-Jaffa, IL;

Inventors:

Tal Zamir, Tel Aviv, IL;

Oleg Zlotnik, Nesher, IL;

Boris Figovsky, Hadera, IL;

Assignee:

HYSOLATE LTD., Tel Aviv-Jaffa, IL;

Attorney:
Primary Examiner:
Int. Cl.
CPC ...
G06F 21/53 (2013.01); H04L 29/06 (2006.01); G06F 9/455 (2018.01); G06F 21/60 (2013.01); H04W 12/08 (2009.01); H04L 29/12 (2006.01);
U.S. Cl.
CPC ...
G06F 21/53 (2013.01); G06F 9/45537 (2013.01); G06F 9/45545 (2013.01); G06F 9/45558 (2013.01); G06F 21/606 (2013.01); H04L 61/2015 (2013.01); H04L 63/02 (2013.01); H04L 63/0209 (2013.01); H04L 63/0272 (2013.01); H04L 63/0815 (2013.01); H04L 63/10 (2013.01); H04L 63/1416 (2013.01); H04L 63/1491 (2013.01); H04L 63/20 (2013.01); H04W 12/0806 (2019.01); G06F 2009/4557 (2013.01); G06F 2009/45562 (2013.01); G06F 2009/45587 (2013.01); G06F 2009/45591 (2013.01); G06F 2009/45595 (2013.01); H04L 63/0263 (2013.01);
Abstract

An air-gapped computing system includes at least network card interface; a processing circuitry; and a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to: initialize a hypervisor for execution over a primitive OS; create a plurality of isolated security zones by instantiating a plurality of corresponding virtual machines using the hypervisor, wherein each of the plurality of security zones includes a plurality of applications executed over a guest OS; instantiate a networking virtual machine using the hypervisor; control, by the networking virtual machine, access of each application in each of the plurality of security zones to an external network resource; and monitor execution of the guest OS and each application in at least one activated security zone of the plurality of security zones, wherein the monitoring is performed to maintain compliance with a security policy corresponding to each activated security zone being monitored.


Find Patent Forward Citations

Loading…