Centralized DLP Manager for Virtual Machine Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Ensuring every virtual machine in a virtualized environment has an up-to-date data loss prevention agent is inefficient and resource-intensive, as existing methods require agents to be installed on each VM individually.

Innovation Solution

Implementing a Data Loss Protection (DLP) manager running on a security virtual machine that identifies guest VM startups and installs a DLP component before other applications launch, communicating with DLP components to enforce policies and respond to file system events that violate DLP policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a DLP agent is installed on each virtual machine individually, then data loss prevention coverage is ensured, but system resource usage increases and deployment complexity increases

Engineering Contradiction:
Improvedata loss prevention coverageVSAvoiddeployment complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple DLP agent instances into a single centralized DLP manager running on one virtual machine. This manager coordinates DLP policies across all guest VMs without requiring individual agents on each VM, thereby reducing deployment complexity while maintaining comprehensive coverage through centralized monitoring and control.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The centralized DLP manager performs multiple functions that would otherwise require separate agents on each VM: policy enforcement, file system event monitoring, removable device monitoring, and network share monitoring. This multi-functional approach simplifies the system architecture while ensuring comprehensive data loss prevention across all VMs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If a DLP agent is installed on each virtual machine individually, then data loss prevention coverage is ensured, but system resource usage increases

Engineering Contradiction:
Improvedata loss prevention coverageVSAvoidsystem resource usage
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent consolidates resource-intensive DLP operations into a single centralized manager rather than distributing them across multiple VM agents. This reduces total system resource consumption by eliminating redundant processes while maintaining comprehensive monitoring through the manager's ability to observe file system events and device usage across all guest VMs.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The centralized DLP manager acts as an intermediary that receives notifications from virtualization infrastructure about file system events, removable device connections, and network share access across all VMs. This intermediary approach eliminates the need for resource-intensive local agents on each VM while maintaining comprehensive monitoring through centralized event reception and policy enforcement.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If DLP policies are enforced through individual agents on each VM, then policy compliance is achieved, but installation and maintenance time increases

Engineering Contradiction:
Improvepolicy complianceVSAvoidinstallation and maintenance time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary configuration by establishing the centralized DLP manager before guest VMs are deployed or activated. The manager pre-configures policy enforcement mechanisms and monitoring capabilities, so that when VMs are created or accessed, DLP protection is already in place without requiring time-consuming individual agent installations on each VM.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent combines installation and maintenance operations into a single centralized process. Policy updates, configuration changes, and maintenance tasks are performed once on the DLP manager rather than being propagated individually to agents on each VM, dramatically reducing the time required for installation and ongoing maintenance while ensuring consistent policy compliance across all VMs.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9230096B2System and method for data loss prevention in a virtualized environment
Publication Date: 2016.01.05 CA TECH INC
  • US9230096B2 patent drawing
  • US9230096B2 patent drawing
  • US9230096B2 patent drawing

AI summary

A data loss prevention (DLP) manager running on a security virtual machine manages DLP policies for a plurality of guest virtual machines. The DLP manager identifies a startup event of a guest virtual machine, and installs a DLP component in the guest virtual machine. The DLP component communicates with the DLP manager operating within the security virtual machine. The DLP manager also receives file system events from the DLP component, and enforces a response rule associated with the guest virtual machine if the file system event violates a DLP policy.