Guest Agent for Virtual Machine Configuration Validation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Monitoring and validating updates to critical configurations of numerous virtual machines is cumbersome and impractical for security administrators, posing a risk to the integrity of virtual machines and operating systems due to potential security threats like malware and ransomware.

Innovation Solution

A guest agent is installed on virtual machines to monitor and enforce policies by taking snapshots of critical components, collecting context information on configuration updates, and comparing it to a policy whitelist to allow or block updates, with the ability to restore the machine to a trusted configuration if necessary, utilizing a central manager and host agent to manage and protect the virtual machines.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual monitoring and validation of configuration updates is performed, then security control precision is improved, but administrator workload and time consumption increase significantly

Engineering Contradiction:
Improvesecurity control precisionVSAvoidadministrator time consumption
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system implements self-service through automated configuration monitoring and validation. The agent automatically detects configuration changes, validates them against security policies, and alerts administrators only when violations occur. This eliminates the need for continuous manual monitoring while maintaining high security control precision, resolving the contradiction between precise security control and administrator time consumption.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical monitoring processes with automated computational systems. The agent continuously monitors configuration parameters, compares them against security policies, and generates alerts automatically. This substitution of manual processes with automated systems maintains precise security control while dramatically reducing administrator time consumption.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If configuration updates are blocked to prevent security threats, then system security is improved, but system adaptability and functionality may deteriorate

Engineering Contradiction:
Improvesystem securityVSAvoidsystem adaptability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system implements feedback mechanisms where configuration changes are monitored, validated against security policies, and only blocked when violations are detected. Legitimate configuration updates are allowed to proceed, maintaining system adaptability. The feedback loop ensures that security threats are blocked while valid operational changes are permitted, resolving the contradiction between security and adaptability.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary validation of configuration changes against security policies before allowing them to take effect. This preliminary action ensures that only secure configurations are applied, preventing security threats while allowing legitimate operational changes. The pre-validation approach maintains both security and system adaptability by blocking only malicious changes.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If comprehensive monitoring of all virtual machines is implemented, then security coverage is improved, but system complexity and resource consumption increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system implements segmentation by deploying lightweight agent components on individual virtual machines rather than centralized monitoring of all machines. Each agent independently monitors its local configuration, reducing the complexity burden on any single system component. This segmented approach provides comprehensive security coverage across all virtual machines while keeping individual agent complexity low.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces intermediary agent components that mediate between the virtual machine configurations and the security policy enforcement mechanism. These intermediaries simplify the overall system architecture by handling local monitoring and validation tasks, reducing the complexity of direct comprehensive monitoring while maintaining complete security coverage across all virtual machines.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11989298B2Methods and apparatus to validate and restore machine configurations
Publication Date: 2024.05.21 VMWARE INC
  • US11989298B2 patent drawing
  • US11989298B2 patent drawing
  • US11989298B2 patent drawing

AI summary

Methods and apparatus to validate and restore machine configurations are disclosed herein. An example apparatus includes a context identifier to obtain first context information for a first set of configuration update events occurring on a computing device, a guest agent interface to transmit the first set of configuration update events to a security manager for generation of a policy, the policy including allowable configuration update events and responses to unallowable configuration update events, an event comparator to compare second context information of a subsequent configuration update event obtained by the context identifier to the policy received from the security manager, and an event handler to determine, when the subsequent configuration update event is not included in the policy, that the subsequent configuration update event is to be transmitted to the security manager for generation of an updated policy.