Emulation System for Isolating Software Flaws and Security Risks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current systems face challenges in effectively managing software flaws and security control practices during thread emulation, particularly in isolating software object types and determining appropriate execution environments based on performance norms and security considerations.

Innovation Solution

The method involves obtaining software flaw indications from thread emulation, signaling decisions on resource authorizations and security control practices, and determining execution environments through user interface inputs, allowing for the isolation of software object types and the application of appropriate security measures based on compliance with policies and performance norms.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If software objects are emulated in a controlled environment to detect flaws and enforce security policies, then security and compliance are improved, but execution speed and productivity deteriorate due to the overhead of emulation

Engineering Contradiction:
ImprovesecurityVSAvoidexecution speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary emulation in a controlled environment before actual execution to detect software flaws and verify compliance with security policies. By pre-evaluating software objects in an isolated emulation environment, the system identifies potential security issues and performance problems before they affect production systems, thereby improving security without sacrificing execution speed during actual operation

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system segments the execution process into distinct phases: emulation phase in a controlled environment for security verification, and execution phase in the target environment for actual operation. This segmentation allows security checks to be performed separately from production execution, maintaining both security requirements and execution efficiency through temporal and spatial separation of concerns

Inventive Principle:
Principle #1Segmentation

2Reliability

If software objects are isolated by type in the emulation environment to prevent harmful interactions, then security control is improved, but system complexity increases due to isolation policies and environment management

Engineering Contradiction:
Improvesecurity controlVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system introduces an intermediary controlled environment that mediates between software objects of different types. This intermediary environment enforces isolation policies by controlling interactions between software objects, allowing security verification without requiring complex modifications to the software objects themselves. The intermediary layer manages the complexity of isolation requirements while maintaining simple software object designs

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system applies different isolation policies locally to different types of software objects based on their specific security requirements. Rather than imposing a uniform complex isolation framework on all software, the system tailors isolation mechanisms to local needs, reducing overall system complexity while maintaining appropriate security controls for each software type

Inventive Principle:
Principle #3Local quality

3Reliability

If performance norms are enforced in the emulation environment to ensure compliant execution, then reliability is improved, but adaptability deteriorates as software must conform to specific emulation constraints

Engineering Contradiction:
ImprovecomplianceVSAvoidsoftware flexibility
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system applies performance norms partially during the emulation phase rather than requiring full compliance during all execution phases. By enforcing compliance requirements only during the preliminary emulation and verification stage, the system ensures that software meets necessary performance standards without imposing continuous constraints that would reduce adaptability during actual operation in the target environment

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9378108B2Implementing performance-dependent transfer or execution decisions from service emulation indications
Publication Date: 2016.06.28 MEC MANAGEMENT LLC
  • US9378108B2 patent drawing
  • US9378108B2 patent drawing
  • US9378108B2 patent drawing

AI summary

A system, method, computer program product, and carrier are described for obtaining data from a first emulator and from a first emulation environment hosting software and signaling a decision whether to transfer any of the data to a second emulator at least partly as a result of the first emulation environment hosting the software.