Heterogeneous OS Security Agent Management via Host-Guest Coordination

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security techniques struggle to effectively manage and enhance security for devices with heterogeneous operating systems, such as Linux systems running on the Windows Subsystem for Linux (WSL), as they often fail to detect or respond to information leakage activities.

Innovation Solution

A method where a first security agent in the host OS collects guest OS information and manages a second security agent in the guest OS, allowing for the application of a security policy identical to the host OS and enabling automatic installation or re-execution of the second security agent if necessary.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a Windows security application controls WSL-related processes to prevent information leakage in Linux, then security protection is improved, but user services are restricted

Engineering Contradiction:
Improvesecurity protectionVSAvoiduser service
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent divides the security protection function into two separate security agents: a first security agent running in the host OS (Windows) and a second security agent running in the guest OS (Linux). This segmentation allows each agent to operate independently within its own OS environment, enabling security protection without restricting user services in the guest OS, as the host security agent can monitor and control only when necessary.

Inventive Principle:
Principle #1Segmentation

2Difficulty of detecting and measuring

If a security application is installed on Windows to detect information leakage, then security detection capability is improved, but it cannot detect activities on Linux in WSL

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidcross-OS detection
Core Design Contradiction:
Difficulty of detecting and measuringVSAdaptability or versatility

Solution Approach 1:

The patent introduces a first security agent in the host OS as an intermediary that bridges the detection gap between Windows security applications and Linux processes in WSL. This intermediary can detect information leakage activities in the guest OS by monitoring system calls and process behaviors through the WSL interface, while maintaining compatibility with existing Windows security detection mechanisms.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If different security policies are applied to host and guest OS, then OS-specific security needs are met, but security consistency is lost

Engineering Contradiction:
ImproveOS-specific securityVSAvoidsecurity policy consistency
Core Design Contradiction:
Adaptability or versatilityVSStability of the object's composition

Solution Approach 1:

The patent implements a feedback mechanism where the first security agent in the host OS receives status information from the second security agent in the guest OS, and can update or re-execute the second security agent to ensure policy consistency. This feedback loop maintains security policy alignment across heterogeneous OS environments while allowing each OS to have its own security agent optimized for its specific needs.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250139232A1Method, apparatus, system, and computer program for enhancing security of heterogeneous operating system device
Publication Date: 2025.05.01 SAMSUNG SDS CO LTD
  • US20250139232A1 patent drawing
  • US20250139232A1 patent drawing
  • US20250139232A1 patent drawing

AI summary

The present disclosure relates to a method, an apparatus, a system, and a computer program for enhancing security of a heterogeneous operating system device and, more specifically, provides a security method for a computing apparatus in which a heterogeneous operating system is driven, the method including an operation of collecting, by a first security agent driven in a host OS of the computing apparatus, guest OS information for a guest OS installed on the host OS and an operation of performing, by the first security agent on the basis of the guest OS information, management for a second security agent driven on the guest OS.