Host Supervisory Security for Virtual Machine Isolation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing computer operating systems are vulnerable to malware attacks, which can compromise the integrity of the system by accessing privileged operations, and existing security measures are often ineffective due to their own vulnerability to corruption.

Innovation Solution

Implementing a single security process or set of processes to monitor, protect, and repair multiple logically isolated virtual machines running on a host system, using a supervisory process to control security applications that can scan and repair virtual machines in a paused or saved state, and employing agent security processes within each virtual machine to detect and recover from attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security applications are installed on each computer system to prevent compromise, then security coverage is improved, but the security applications themselves become vulnerable to attack and corruption

Engineering Contradiction:
Improvesecurity protection reliabilityVSAvoidvulnerability to malware attack
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a host system as an intermediary layer between the virtual machines and the security applications. The host system provides a protected environment where security applications can operate without being directly exposed to malware attacks on individual virtual machines. This mediator architecture allows security functions to be centralized and isolated from the vulnerable virtual machine environments.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the security function from the vulnerable virtual machine environments by running security applications on the host system rather than within the virtual machines themselves. This segmentation separates the security protection layer from the potentially compromised application layers, ensuring that even if virtual machines are infected, the security infrastructure remains intact.

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If virtual machines are isolated to confine malware damage, then containment is improved, but detection and response capability may be reduced

Engineering Contradiction:
Improvemalware damage containmentVSAvoidsecurity breach detection
Core Design Contradiction:
Object-affected harmful factorsVSDifficulty of detecting and measuring

Solution Approach 1:

The patent implements feedback mechanisms where the host system continuously monitors virtual machines for signs of compromise. Security applications on the host receive information about virtual machine states and can detect anomalies, enabling the system to identify security breaches despite the isolation barriers between virtual machines and the host.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The host system acts as an intermediary that receives monitoring data from virtual machines while maintaining isolation boundaries. This mediator enables detection capabilities to penetrate the isolation layer without compromising the containment integrity, allowing the system to observe virtual machine behavior while keeping malware confined.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If multiple security applications run on each system, then comprehensive protection is improved, but system complexity and resource consumption increase

Engineering Contradiction:
Improvecomprehensive security protectionVSAvoidsecurity infrastructure complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent merges multiple security functions into a unified architecture where a single host system runs multiple security applications that collectively protect multiple virtual machines. Instead of distributing separate security suites on each virtual machine, the system combines security monitoring, detection, and response functions in a centralized host environment, reducing overall complexity while maintaining comprehensive protection.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The host system provides universal security protection by running a single instance of security applications that can monitor and respond to threats across multiple different virtual machines. This multi-functional approach allows one security infrastructure to serve multiple protected environments, eliminating the need for redundant security software on each virtual machine.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7409719B2Computer security management, such as in a virtual machine or hardened operating system
Publication Date: 2008.08.05 MICROSOFT TECHNOLOGY LICENSING LLC
  • US7409719B2 patent drawing
  • US7409719B2 patent drawing
  • US7409719B2 patent drawing

AI summary

A security scheme provides security to one or more self-contained operating environment instances executing on a computer. The security scheme may include implementing a set of security applications that may be controlled by a supervisory process, or the like. Both the set of security applications and the supervisory process may operate on a host system of the computer, which may also provide a platform for execution of the one or more self-contained operating environments. The security scheme protects processes running in the one or more self-contained operating environment and processes running on the computer outside of the self-contained operating environments.