Disposable Virtual Machines for Cyber-Attack Rollback

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity measures are inadequate in ensuring the continuous operation of mission-critical systems during cyber-attacks, as they rely on manual intervention and are slow to react, leading to potential system compromise and service disruption.

Innovation Solution

Implementing Fight-Through Nodes (FTN-Ds) with disposable virtual machines that provide swift and efficient recovery from compromised states by isolating and destroying malware, using sandboxing, parallel processing, rapid checkpointing, and rapid restoration to maintain network resilience and critical service continuity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual intervention is used to respond to cyber-attacks, then system security can be maintained through human analysis and decision-making, but the response time is too slow compared to the speed of cyber-attacks which occur within milliseconds

Engineering Contradiction:
Improvedetection accuracyVSAvoidresponse time
Core Design Contradiction:
Measurement precisionVSSpeed

Solution Approach 1:

The system performs preliminary actions by pre-configuring disposable virtual machines and establishing rollback mechanisms before attacks occur. When an attack is detected, the system can immediately activate pre-prepared clean VM instances and execute pre-planned rollback procedures, eliminating the need for manual analysis and decision-making during the critical response window.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements self-service automation where the fight-through node automatically detects attacks, isolates compromised components, activates clean virtual machine instances, and executes rollback procedures without human intervention. This automated response capability enables the system to react within milliseconds, matching the speed of modern cyber-attacks while maintaining detection accuracy through embedded monitoring mechanisms.

Inventive Principle:
Principle #25Self-service

2Reliability

If nodes are isolated during cyber-attacks to maintain security, then system security is improved, but mission-critical services experience disruption and unavailability

Engineering Contradiction:
Improvesystem securityVSAvoidservice availability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system segments the node into isolated virtual machine instances that can be individually managed during attacks. When an attack is detected on one VM, only that specific instance is isolated or discarded, while other clean VM instances continue to provide critical services. This granular segmentation allows security isolation without complete service disruption.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements rapid discarding of compromised virtual machine instances and automatic recovery through activation of clean instances from the disposable pool. This process occurs automatically within milliseconds, maintaining service continuity by replacing only the affected components while preserving overall system functionality and availability.

Inventive Principle:
Principle #34Discarding and recovering

3Reliability

If traditional cybersecurity measures are used, then system security is maintained through conventional defense mechanisms, but the system cannot quickly react to and recover from compromised states

Engineering Contradiction:
Improvesecurity postureVSAvoidrecovery time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system prepares clean virtual machine instances and rollback mechanisms in advance, before attacks occur. This preliminary preparation enables immediate activation of clean instances and rapid rollback to known good states, reducing recovery time from hours or days to milliseconds while maintaining strong security posture through pre-configured defense mechanisms.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system employs disposable virtual machine instances that are designed to be temporarily used and then discarded after completing their function or being compromised. These inexpensive, short-lived VM instances can be rapidly created and destroyed without significant resource waste, enabling quick recovery by simply discarding compromised instances and activating fresh ones, thereby dramatically reducing recovery time while maintaining security.

Inventive Principle:
Principle #27Cheap short-living objects (Disposable)

Data Source

PatentUS9769250B2Fight-through nodes with disposable virtual machines and rollback of persistent state
Publication Date: 2017.09.19 ARCHITECTURE TECH CORP
  • US9769250B2 patent drawing
  • US9769250B2 patent drawing
  • US9769250B2 patent drawing

AI summary

A server system receives messages from client computing devices. Each of the messages corresponds to a transaction. The server system assigns each respective transaction to a respective fresh virtual machine. Furthermore, the server system performs, as part of a respective virtual machine processing a respective transaction, a modification associated with the respective transaction to a shared database. The shared database is persisted independently of the plurality of virtual machines. In response to determining that processing of the respective transaction is complete, the server system discards the respective virtual machine. In response to a trigger, such as determining that the respective transaction is associated with a cyber-attack, the server system uses checkpoint data associated with the respective transaction to roll back the modifications associated with the respective transaction to the shared database.