Cloud Chamber Firewall for Virtual Machine Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing environments, traditional firewall systems struggle to protect applications and virtual machines due to the lack of available network topology information, making it challenging to deploy and manage firewalls effectively, as they rely on physical network structures that are not applicable in virtualized environments.

Innovation Solution

A cloud chamber system is introduced, which is a virtual and logical firewall structure that generates and enforces firewall rules based on user-defined security policies and computing flows, allowing for dynamic reconfiguration and protection of virtual machines without relying on underlying TCP/IP network topology, enabling seamless integration with cloud orchestration systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a traditional centralized firewall is deployed at the network periphery, then physical network topology-based security protection is achieved, but the firewall cannot effectively protect virtual machines in cloud computing environments where network topology information is not available

Engineering Contradiction:
Improvefirewall protection effectivenessVSAvoidapplicability to virtualized environments
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent creates a virtual copy of the firewall functionality within the cloud computing environment. Instead of relying on physical network topology, the system generates virtual network topology information that mirrors the logical structure of virtual machines and their communication patterns. This virtual topology copy enables the firewall to function effectively in virtualized environments where physical topology is unavailable.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces a cloud management system as an intermediary between the firewall and the virtual machines. This intermediary layer translates security requirements into virtual topology-based rules, enabling the firewall to protect virtual machines without direct access to physical network infrastructure. The intermediary generates and enforces security policies based on virtual network relationships.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If brute force methods are used to obtain network topology information for firewall deployment, then firewall configuration data may be obtained, but the method is ineffective for most cloud management systems and violates business model and liability constraints

Engineering Contradiction:
Improvenetwork topology information availabilityVSAvoidfirewall deployment feasibility
Core Design Contradiction:
Loss of informationVSEase of manufacture

Solution Approach 1:

The patent enables the cloud management system to self-generate the required network topology information instead of requiring external extraction or brute force methods. The system automatically discovers virtual machine relationships and communication patterns, then uses this self-generated information to configure firewall rules. This eliminates the need for invasive information gathering while maintaining effective firewall protection.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If a centralized firewall architecture is used to protect distributed virtual machines, then security policy enforcement is simplified, but the firewall cannot keep sync with dynamic reconfiguration of computing resources controlled by cloud orchestration systems

Engineering Contradiction:
Improvesecurity policy managementVSAvoiddynamic adaptation to resource reconfiguration
Core Design Contradiction:
Ease of operationVSExtent of automation

Solution Approach 1:

The patent transforms the static centralized firewall architecture into a dynamic system that automatically adapts to changing cloud environments. The firewall continuously monitors virtual machine provisioning, deployment, and termination events through integration with cloud orchestration systems. When resources are dynamically reconfigured, the firewall automatically updates its security rules to maintain protection, eliminating the sync problems inherent in static architectures.

Inventive Principle:
Principle #15Dynamics

4Reliability

If conventional firewalls work in the physical network domain, then network-based security protection is effective, but applications and firewall protection become out of sync in virtualized cloud environments

Engineering Contradiction:
Improvenetwork security protectionVSAvoidalignment with virtual machine deployment
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent shifts the firewall operation from the physical network dimension to the virtual network dimension. Instead of enforcing security based on physical network topology, the system operates in the virtualization layer where it can directly correlate with virtual machine deployment, migration, and termination. This dimensional shift allows the firewall to remain synchronized with application lifecycles in cloud environments.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS9634990B2Distributed firewall security system for cloud computing environments
Publication Date: 2017.04.25 ZENTERA SYST
  • US9634990B2 patent drawing
  • US9634990B2 patent drawing
  • US9634990B2 patent drawing

AI summary

An application profile specifies server groups, components, and computing flows among the server groups and components. Each computing flow may be identified as malicious or not malicious. Firewall rules are generated based on the computing flows. The firewall rules are distributed to a server group. According to the firewall rules distributed to the server group, data that is malicious is directed to another server for quarantine.