Container-Based Management System for Cloud Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In cloud computing environments, existing virtualization technologies face challenges in detecting abnormal actions across multiple clients and controlling causative services effectively, leading to security and stability issues due to resource wastage and vulnerability to malicious attacks.
Innovation Solution
An integrated management system that monitors client activities, compares monitoring information with predefined policies, and controls affected clients to prevent abnormal behavior propagation, utilizing a computing device to detect system abnormalities and implement control measures such as device, file, and network controls.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If virtual machine-based server virtualization technology is used to provide multiple independently operable servers in one physical system, then resource sharing and efficient utilization of idle resources are improved, but resource waste increases when host OS and guest OS operate in the same operating system
Solution Approach 1:
The patent merges multiple client operating systems to share a single host operating system kernel. Instead of each client running a separate instance of the OS, the system combines them into one shared kernel that serves multiple clients simultaneously. This merging approach eliminates redundant OS instances while maintaining client independence through virtualization, directly resolving the resource waste problem described in the contradiction.
2Productivity
If container-based system is used to share operating system kernel among multiple clients, then resource efficiency and mobility are improved, but security vulnerability increases when malicious attack occurs
Solution Approach 1:
The patent segments the shared host operating system into isolated client environments using virtualization technology. Each client operates in its own isolated space with controlled access to shared resources, preventing malicious actions from spreading across the entire system. This segmentation maintains the resource efficiency of container-based systems while adding security boundaries to protect against malware propagation.
Solution Approach 2:
The patent introduces a management server as an intermediary between clients and the host operating system. This intermediary monitors client activities, detects abnormal behaviors, and controls resource access to prevent security threats. The management server acts as a mediator that enables secure sharing of the host OS while protecting against malicious attacks, resolving the security stability concern.
3Reliability
If monitoring and control operations are performed on multiple clients to detect abnormal actions, then security detection capability is improved, but system complexity increases
Solution Approach 1:
The patent implements a universal management server that handles multiple functions: monitoring client activities, detecting abnormal actions, analyzing threats, and controlling resource allocation. This single multi-functional component replaces what would otherwise require multiple separate systems, improving detection capability while minimizing the increase in system complexity through functional consolidation.
Data Source
AI summary
Disclosed is a computer program that is used for detecting a system abnormality and controlling a causative service in a computing device. In a computer program stored in a computer-readable storage medium, including encoded commands, which causes one or more processors to perform operations for detecting a system abnormality in the computing device when the computer program is executed by the one or more processors of a computer device, the operations may include: an operation of receiving monitoring information for each client from a plurality of clients of the computing device; an operation of comparing each monitoring information for each client with a system monitoring policy; an operation of determining whether the system abnormality occurs based on a comparison result with the system monitoring policy; and an operation of determining to control some clients among the plurality of clients based on the determination of whether the system abnormality occurs.


