Bus Snooping Monitoring Device for Hypervisor Intrusion Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing hypervisor systems face challenges in securely managing virtual machine instances due to the risk of intrusions, as they require privileged access and complex security measures to prevent attacks, which can be difficult to implement effectively.

Innovation Solution

A monitoring device is introduced to detect and prevent intrusions by 'snooping' on computer system bus communications, applying a communications filter to identify protected memory ranges, and generating events for administrative systems to take corrective actions, such as halting the system or restarting it.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If privileged access is granted to hypervisor components for effective administration, then administrative functionality is improved, but security risk increases

Engineering Contradiction:
Improveadministrative functionalityVSAvoidsecurity risk
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

A monitoring device is introduced as an intermediary component that sits between the privileged hypervisor components and the physical host machine. This monitoring device captures and analyzes bus communications to detect intrusion attempts, allowing the hypervisor to maintain privileged access for administration while the monitoring device provides an additional security layer that reduces overall security risk by detecting and alerting on malicious activities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If complex security measures are implemented to prevent attacks, then security protection is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity protectionVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security function is segmented into a separate monitoring device that operates independently from the hypervisor system. This monitoring device is specifically dedicated to capturing bus communications and detecting intrusions, while the hypervisor itself remains focused on virtual machine management. This segmentation improves security protection by providing specialized monitoring capabilities while managing system complexity by isolating security functions from core hypervisor operations.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If real-time monitoring is implemented to detect intrusions, then intrusion detection capability is improved, but processing overhead increases

Engineering Contradiction:
Improveintrusion detection capabilityVSAvoidprocessing overhead
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The monitoring function is extracted from the main hypervisor processing path and implemented as a separate monitoring device that captures bus communications in parallel. This extraction allows real-time intrusion detection to occur without adding processing overhead to the critical hypervisor operations. The monitoring device independently analyzes bus traffic while the hypervisor continues its primary functions, thus improving intrusion detection capability without significantly increasing overall system processing overhead.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS9727726B1Intrusion detection using bus snooping
Publication Date: 2017.08.08 AMAZON TECH INC
  • US9727726B1 patent drawing
  • US9727726B1 patent drawing
  • US9727726B1 patent drawing

AI summary

Remote computing resource service providers allow customers to execute one or more applications in a virtual environment on computer systems provided by the computing resource service provider. The customer applications are generally executed by multiple virtual machine instances working together. The virtual machines may be managed by a hypervisor executing on computer systems operated by the service provider. These computer systems may be vulnerable to intrusions and other malicious attack, thereby exposing the virtual machines and corresponding customer applications executing on the computer systems. A monitoring device may be used in one or more of the computing systems, operated by the service provider, in order to monitor and prevent a variety of different attacks.