Host Firewall Isolation for Malware Containment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer systems are vulnerable to malware infiltration despite defensive measures, as malware can evade hardware-based firewalls and spread within networks, posing risks to sensitive information and system safety.

Innovation Solution

Implementing a host-based firewall system that creates a sandboxed computing environment with segregated processes and memory spaces, using a processor to determine the host's location and apply a location-specific firewall policy, and employing an internal isolation firewall to control data transfers and prevent unauthorized communication.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If hardware-based firewalls are deployed to block malware, then network security is improved, but malware can still evade these firewalls and reach computer systems

Engineering Contradiction:
Improvenetwork securityVSAvoidmalware infiltration
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system segments the computing environment into isolated containers (sandboxes) that run applications in separated memory spaces. This segmentation prevents malware from spreading across the entire system even if it penetrates the firewall, as each container operates in an isolated environment with restricted access to system resources.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary layer between the external network and the internal system resources. This includes both the hardware firewall as the first line of defense and additional software-based isolation mechanisms that act as intermediaries to filter and control traffic, preventing direct access to vulnerable system components.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If elaborate defensive protections are implemented to prevent malware, then security measures are strengthened, but the systems become costly and difficult to maintain

Engineering Contradiction:
Improvesecurity protectionVSAvoiddefensive system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The isolated computing environment provides self-service security by automatically containing and neutralizing malware threats within the sandboxed memory space. The system self-manages threat containment without requiring complex external intervention, reducing maintenance burden while maintaining strong security protections.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent adds a new dimension to security by implementing spatial isolation through separate memory spaces and containers. This dimensional approach to security (separating processes in memory space) complements traditional network-based security layers, providing protection without proportionally increasing system complexity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Reliability

If the isolated computing environment is completely isolated from the workspace, then malware containment is improved, but legitimate data transfer between environments is blocked

Engineering Contradiction:
Improvemalware containmentVSAvoiddata transfer capability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system extracts and separates dangerous or untrusted processes into an isolated computing environment with its own dedicated memory space. This extraction allows the system to maintain strict isolation for security-critical operations while permitting controlled data transfer for legitimate business needs, as the isolated environment can selectively interface with the workspace when safety is assured.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11336619B2Host process and memory separation
Publication Date: 2022.05.17 L3 TECHNOLOGIES INC
  • US11336619B2 patent drawing
  • US11336619B2 patent drawing
  • US11336619B2 patent drawing

AI summary

A host computer system may be configured to connect to a network. The host computer system may be configured to implement a workspace, an isolated computing environment, and a host-based firewall. The host computer system may be configured to isolate the isolated computing environment from the workspace using an internal isolation firewall. The internal isolation firewall may be configured to prevent data from being communicated between the isolated computing environment and the workspace, for example, without an explicit user input. The host computer system may be configured to determine, using one or more environmental indicators, a relative location of the host computer system. The processor may be configured to select a firewall policy based on the relative location of the host computer system. The firewall policy may include a configuration to apply to one or more of the internal isolation firewall or the host-based firewall.