Host Supervisory Security for Virtual Machine Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing computer operating systems are vulnerable to malware attacks, which can compromise the integrity of the system by accessing privileged operations, and existing security measures are often ineffective due to their own vulnerability to corruption.
Innovation Solution
Implementing a single security process or set of processes to monitor, protect, and repair multiple logically isolated virtual machines running on a host system, using a supervisory process to control security applications that can scan and repair virtual machines in a paused or saved state, and employing agent security processes within each virtual machine to detect and recover from attacks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security applications are installed on each computer system to prevent compromise, then security coverage is improved, but the security applications themselves become vulnerable to attack and corruption
Solution Approach 1:
The patent introduces a host system as an intermediary layer between the virtual machines and the security applications. The host system provides a protected environment where security applications can operate without being directly exposed to malware attacks on individual virtual machines. This mediator architecture allows security functions to be centralized and isolated from the vulnerable virtual machine environments.
Solution Approach 2:
The patent segments the security function from the vulnerable virtual machine environments by running security applications on the host system rather than within the virtual machines themselves. This segmentation separates the security protection layer from the potentially compromised application layers, ensuring that even if virtual machines are infected, the security infrastructure remains intact.
2Object-affected harmful factors
If virtual machines are isolated to confine malware damage, then containment is improved, but detection and response capability may be reduced
Solution Approach 1:
The patent implements feedback mechanisms where the host system continuously monitors virtual machines for signs of compromise. Security applications on the host receive information about virtual machine states and can detect anomalies, enabling the system to identify security breaches despite the isolation barriers between virtual machines and the host.
Solution Approach 2:
The host system acts as an intermediary that receives monitoring data from virtual machines while maintaining isolation boundaries. This mediator enables detection capabilities to penetrate the isolation layer without compromising the containment integrity, allowing the system to observe virtual machine behavior while keeping malware confined.
3Reliability
If multiple security applications run on each system, then comprehensive protection is improved, but system complexity and resource consumption increase
Solution Approach 1:
The patent merges multiple security functions into a unified architecture where a single host system runs multiple security applications that collectively protect multiple virtual machines. Instead of distributing separate security suites on each virtual machine, the system combines security monitoring, detection, and response functions in a centralized host environment, reducing overall complexity while maintaining comprehensive protection.
Solution Approach 2:
The host system provides universal security protection by running a single instance of security applications that can monitor and respond to threats across multiple different virtual machines. This multi-functional approach allows one security infrastructure to serve multiple protected environments, eliminating the need for redundant security software on each virtual machine.
Data Source
AI summary
A security scheme provides security to one or more self-contained operating environment instances executing on a computer. The security scheme may include implementing a set of security applications that may be controlled by a supervisory process, or the like. Both the set of security applications and the supervisory process may operate on a host system of the computer, which may also provide a platform for execution of the one or more self-contained operating environments. The security scheme protects processes running in the one or more self-contained operating environment and processes running on the computer outside of the self-contained operating environments.


