Cloud Traffic Migration via VM Shells for Threat Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large-scale cloud infrastructure operations are susceptible to anomalies, attacks, and faults, making it difficult to identify and manage harmful traffic within virtual machines (VMs), which can lead to performance issues and security breaches.

Innovation Solution

A cloud traffic migration system that utilizes VM shells to segregate and analyze traffic, creating sub-VMs to isolate and evaluate suspicious traffic, implementing restrictive rules to mitigate harm and gather threat analytics.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If cloud infrastructure uses virtualized network functions on general-purpose hardware, then device complexity and scalability are improved, but susceptibility to anomalies, attacks, and faults increases

Engineering Contradiction:
Improvenetwork infrastructure complexityVSAvoidsystem reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent segments the cloud infrastructure into isolated virtual network function instances, each running on separate virtual machines with dedicated resource pools. This segmentation allows individual VNFs to be isolated from each other, preventing cascading failures while maintaining overall system scalability and complexity management.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary orchestration layer that manages communication and resource allocation between virtualized network functions. This intermediary layer provides abstraction and control mechanisms that enhance reliability by mediating interactions and preventing direct exposure of vulnerabilities between VNFs.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If multiple virtual machines are instantiated to provide cloud services, then service capability and flexibility are improved, but difficulty in identifying root causes of malfunctions increases

Engineering Contradiction:
Improveservice adaptabilityVSAvoidfault detection difficulty
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements comprehensive feedback mechanisms through logging and monitoring systems that track traffic patterns, performance metrics, and error states across all virtual machines. This feedback enables automated root cause analysis by correlating events across the distributed VM environment, making fault detection manageable despite system complexity.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent extracts and isolates logging and monitoring functions into separate dedicated components that systematically capture and analyze traffic data from multiple VMs. This extraction consolidates diagnostic capabilities, allowing centralized analysis of distributed system issues without requiring manual inspection of each VM.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If cloud infrastructure migrates from dedicated hardware to software-defined networks, then operational flexibility and scalability are improved, but susceptibility to harmful traffic increases

Engineering Contradiction:
Improvenetwork operational flexibilityVSAvoidharmful traffic impact
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary security actions by deploying intrusion detection and traffic filtering mechanisms at the virtual network boundary before harmful traffic can reach internal VNFs. This preliminary protection allows the flexible SDN architecture to maintain operational adaptability while preemptively blocking threats.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent employs nested security layers where virtualized network functions are contained within isolated virtual environments, each with its own security boundaries. This nesting creates multiple containment layers that protect against harmful traffic while preserving the flexibility benefits of software-defined networking.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS11422845B2Native cloud live traffic migration to counter suspected harmful traffic
Publication Date: 2022.08.23 AT&T INTELLECTUAL PROPERTY I L P
  • US11422845B2 patent drawing
  • US11422845B2 patent drawing
  • US11422845B2 patent drawing

AI summary

A cloud traffic migration system may be used to counter suspected harmful traffic. For example, a virtual machine (VM) may have a separate security and networking policy called a VM shell. The VM shell may be placed at the VM's interface as a layer of protection. When suspected harmful traffic is detected inside the VM, multiple mini VMs may be created that replicate some functions of the infected VM and the traffic may be grouped and segregated into categories. Each category of traffic may be routed to a mini VM for further analysis. Any traffic confirmed to be harmful may be kept inside the mini VM and subject to restrictive rules. Such restrictive rules may introduce delays to waste the attackers time or resources as well as obtain data for threat analytics.