Container-Based Management System for Cloud Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing environments, existing virtualization technologies face challenges in detecting abnormal actions across multiple clients and controlling causative services effectively, leading to security and stability issues due to resource wastage and vulnerability to malicious attacks.

Innovation Solution

An integrated management system that monitors client activities, compares monitoring information with predefined policies, and controls affected clients to prevent abnormal behavior propagation, utilizing a computing device to detect system abnormalities and implement control measures such as device, file, and network controls.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If virtual machine-based server virtualization technology is used to provide multiple independently operable servers in one physical system, then resource sharing and efficient utilization of idle resources are improved, but resource waste increases when host OS and guest OS operate in the same operating system

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidresource waste
Core Design Contradiction:
ProductivityVSLoss of energy

Solution Approach 1:

The patent merges multiple client operating systems to share a single host operating system kernel. Instead of each client running a separate instance of the OS, the system combines them into one shared kernel that serves multiple clients simultaneously. This merging approach eliminates redundant OS instances while maintaining client independence through virtualization, directly resolving the resource waste problem described in the contradiction.

Inventive Principle:
Principle #5Merging (Combining)

2Productivity

If container-based system is used to share operating system kernel among multiple clients, then resource efficiency and mobility are improved, but security vulnerability increases when malicious attack occurs

Engineering Contradiction:
Improveresource efficiencyVSAvoidsecurity stability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the shared host operating system into isolated client environments using virtualization technology. Each client operates in its own isolated space with controlled access to shared resources, preventing malicious actions from spreading across the entire system. This segmentation maintains the resource efficiency of container-based systems while adding security boundaries to protect against malware propagation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a management server as an intermediary between clients and the host operating system. This intermediary monitors client activities, detects abnormal behaviors, and controls resource access to prevent security threats. The management server acts as a mediator that enables secure sharing of the host OS while protecting against malicious attacks, resolving the security stability concern.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If monitoring and control operations are performed on multiple clients to detect abnormal actions, then security detection capability is improved, but system complexity increases

Engineering Contradiction:
Improveabnormal action detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal management server that handles multiple functions: monitoring client activities, detecting abnormal actions, analyzing threats, and controlling resource allocation. This single multi-functional component replaces what would otherwise require multiple separate systems, improving detection capability while minimizing the increase in system complexity through functional consolidation.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11003765B2Container-based integrated management system
Publication Date: 2021.05.11 TMAXTIBERO CO LTD
  • US11003765B2 patent drawing
  • US11003765B2 patent drawing
  • US11003765B2 patent drawing

AI summary

Disclosed is a computer program that is used for detecting a system abnormality and controlling a causative service in a computing device. In a computer program stored in a computer-readable storage medium, including encoded commands, which causes one or more processors to perform operations for detecting a system abnormality in the computing device when the computer program is executed by the one or more processors of a computer device, the operations may include: an operation of receiving monitoring information for each client from a plurality of clients of the computing device; an operation of comparing each monitoring information for each client with a system monitoring policy; an operation of determining whether the system abnormality occurs based on a comparison result with the system monitoring policy; and an operation of determining to control some clients among the plurality of clients based on the determination of whether the system abnormality occurs.