Centralized Security VM for Malware Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current virtual machine-based systems for detecting malware and exploits in datacenters face inefficiencies due to duplication of detection efforts across multiple virtual machines, leading to increased overhead and resource utilization.

Innovation Solution

A virtualized malware detection system that employs a centralized security virtual machine to perform dynamic analysis and further processing of potentially malicious objects, offloading duplicate analysis tasks from individual virtual machines and utilizing a hypervisor to manage communications and resource allocation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple virtual machines perform exploit detection independently, then detection coverage and reliability are improved, but system overhead and resource utilization increase due to duplication of detection efforts

Engineering Contradiction:
Improveexploit detection reliabilityVSAvoidsystem overhead
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent merges the exploit detection functionality from multiple independent virtual machines into a single centralized security virtual machine. This consolidation eliminates redundant detection efforts while maintaining comprehensive coverage through the coordinated action of the centralized VM with endpoint devices and the management system.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a management system as an intermediary that coordinates between endpoint devices and the centralized security virtual machine. This intermediary collects security events from endpoint devices and directs analysis to the appropriate virtual machine, enabling efficient resource utilization while maintaining detection reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If each virtual machine is configured with different software images to simulate various network devices, then detection versatility and adaptability are improved, but device complexity and configuration management difficulty increase

Engineering Contradiction:
Improvedetection versatilityVSAvoidconfiguration management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a universal software image template that can be deployed across multiple virtual machines. This template serves as a foundation that can be customized for different network device simulations, allowing a single base configuration to support multiple detection scenarios without requiring separate complex configurations for each device type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments the configuration management function into a centralized management system that handles software image deployment and virtual machine configuration. This segmentation separates the complexity of configuration management from the detection functionality, allowing versatile detection capabilities while simplifying administration through centralized control.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10666686B1Virtualized exploit detection system
Publication Date: 2020.05.26 MAGENTA SECURITY HOLDINGS LLC
  • US10666686B1 patent drawing
  • US10666686B1 patent drawing
  • US10666686B1 patent drawing

AI summary

According to one embodiment, a virtualized malware detection system is integrated with a virtual machine host including a plurality of virtual machines and a security virtual machine. Logic within the virtual machines are configured to perform a dynamic analysis of an object and monitor for the occurrence of a triggering event. Upon detection of a triggering event within a virtual machine, the logic within the virtual machine provides the security virtual machine with information associated with the triggering event for further analysis. Based on the further analysis, the object may then be classified as “non-malicious,” or “malicious.”