Anti-malware Broker for Multi-tenant Cloud VM Protection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In multi-tenant cloud computing environments, existing solutions require tenants to install and maintain anti-malware on their virtual machines, which is cumbersome and lacks centralized management, as the anti-malware running on the virtualization layer cannot distinguish between virtual machines belonging to different tenants.
Innovation Solution
A system and method that utilize an anti-malware broker to manage and provide anti-malware services by translating cloud layer identifiers to virtualization layer identifiers, enabling selective anti-malware protection for virtual machines, allowing tenants to opt-in to the service and providing centralized management by the cloud service provider.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If anti-malware is installed on each virtual machine, then each virtual machine receives protection, but the system complexity and maintenance burden increase for tenants
Solution Approach 1:
The patent introduces an anti-malware broker as an intermediary component that runs on the virtualization layer. This broker receives anti-malware service requests from tenants, translates cloud layer virtual machine identifiers to virtualization layer identifiers, and coordinates with anti-malware agents. This intermediary eliminates the need for tenants to directly manage anti-malware installations on each virtual machine, reducing system complexity while maintaining protection reliability.
2Ease of operation
If anti-malware runs on the virtualization layer, then centralized management is achieved, but the anti-malware cannot distinguish between virtual machines of different tenants
Solution Approach 1:
The anti-malware broker acts as an intermediary that maintains the mapping between cloud layer virtual machine identifiers (which contain tenant information) and virtualization layer identifiers. When a tenant requests anti-malware service, the broker translates the cloud layer identifier to the corresponding virtualization layer identifier, ensuring that the anti-malware service can be provided to the correct virtual machine while preserving tenant identification information.
Solution Approach 2:
The patent segments the anti-malware service into distinct functional components: the anti-malware broker that handles identification and coordination, the anti-malware agents that run on specific virtual machines, and the virtualization layer that provides the underlying infrastructure. This segmentation allows each component to perform its specific function, with the broker managing tenant identification and the agents providing actual protection.
3Reliability
If tenants manually install and maintain anti-malware, then protection is provided, but the process is cumbersome and lacks centralized management
Solution Approach 1:
The system enables tenants to self-service by requesting anti-malware protection through a simple interface. The anti-malware broker automatically processes these requests, translates identifiers, and coordinates service delivery without requiring tenants to manually install or configure anti-malware on each virtual machine. This self-service approach maintains protection reliability while dramatically improving ease of operation.
Solution Approach 2:
The anti-malware broker serves as an intermediary that abstracts away the complexity of anti-malware deployment from tenants. Tenants simply request service, and the broker handles all the complex tasks of identifier translation, service coordination, and agent management, making the process easy to operate while maintaining centralized control.
4Ease of operation
If cloud providers manage anti-malware services, then centralized control is achieved, but the complexity of managing multi-tenant environments increases
Solution Approach 1:
The patent segments the anti-malware management system into distinct functional components with clear responsibilities. The anti-malware broker handles identifier translation and service coordination, anti-malware agents provide actual protection on virtual machines, and the virtualization layer provides infrastructure support. This segmentation reduces management complexity by assigning specific functions to each component while maintaining centralized control through the broker.
Solution Approach 2:
The anti-malware broker acts as an intermediary that simplifies cloud provider management of anti-malware services in multi-tenant environments. It automatically translates cloud layer virtual machine identifiers to virtualization layer identifiers, coordinates service delivery to the correct virtual machines, and maintains the mapping information. This intermediary function reduces management complexity while enabling centralized control over anti-malware service delivery.
Data Source
AI summary
A host machine hosts virtual machines on a first logical layer, and a multi-tenant cloud computing environment on a second logical layer running on top of the first logical layer. An anti-malware provides an anti-malware service to virtual machines on the first logical layer. A tenant of the multi-tenant cloud computing environment may lease a virtual machine, and select the virtual machine for subscription to the anti-malware service. A second identifier of the selected virtual machine on the second logical layer is used to determine a first identifier of the selected virtual machine on the first logical layer. The selected virtual machine is identified to the anti-malware using the first identifier. The anti-malware provides anti-malware service to the selected virtual machine. An anti-malware broker may be employed to facilitate selection of the selected virtual machine, and to allow the anti-malware to identify virtual machines subscribed to the anti-malware service.


