Hypermonitor for Cloud Hypervisor Security via Nested Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

As computing resources transition to cloud-based solutions with multiple processors and virtual machines, security and introspection into host systems become increasingly challenging due to complexity, making it difficult to monitor and authenticate code execution effectively.

Innovation Solution

A hypervisor monitor is introduced to interact with host system components, handle exceptions, and perform real-time behavior-based malware detection by nesting between the hardware and hypervisor, using hash values to identify and prevent execution of malicious code, while allowing authorized code to execute.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If a hypervisor is used to manage multiple virtual machines on cloud-based host systems, then resource utilization and productivity are improved, but system complexity and security monitoring difficulty increase

Engineering Contradiction:
Improveresource utilizationVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements a nested monitor structure where a hardware-level monitor (hypermonitor) is embedded within the hypervisor architecture. This hypermonitor operates at a privileged level above the hypervisor, creating a nested monitoring hierarchy that enables introspection of hypervisor operations without disrupting virtual machine execution. The nested structure allows the system to maintain high resource utilization while providing enhanced security monitoring capabilities at multiple levels.

Inventive Principle:
Principle #7Nested doll (Nesting)

2Productivity

If cloud-based solutions with multiple processors and virtual machines are deployed, then computing capacity is improved, but security monitoring and code authentication become more difficult

Engineering Contradiction:
Improvecomputing capacityVSAvoidsecurity monitoring difficulty
Core Design Contradiction:
ProductivityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces a hypermonitor as an intermediary component that operates between the hardware and the hypervisor. This hypermonitor serves as a mediator that can observe and authenticate code execution at the hypervisor level without interfering with the normal operation of virtual machines or the computing capacity of the host system. The intermediary position enables effective security monitoring even in complex multi-processor cloud environments.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If real-time malware detection is implemented in cloud environments, then security reliability is improved, but system complexity and processing overhead increase

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements preliminary authentication of hypervisor code by the hypermonitor before the code executes. Hash values of hypervisor instructions are computed and verified in advance, allowing the system to detect malicious code before it can compromise virtual machines. This preliminary action approach maintains high security reliability while avoiding the need for complex real-time analysis of every instruction during execution.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9146767B2Secure cloud hypervisor monitor
Publication Date: 2015.09.29 NIGHTWING GROUP LLC
  • US9146767B2 patent drawing
  • US9146767B2 patent drawing
  • US9146767B2 patent drawing

AI summary

This disclosure addresses systems and methods for the protection of hardware and software in a computing environment. A hypervisor-monitor may be nested between the hardware of a host system and a hypervisor that is capable of supporting one or more guest virtual machines. The hypervisor-monitor may intercept exceptions generated by one or more processors in the host system and inspect software instructions for the hypervisor and the guests. Inspection may include performing a hash of the software instructions and a comparison of the hash with authorized software modules or a set of known malware. In this manner the hypervisor-monitor may monitor prevent the execution of malware by the hypervisor or the guests or provide a record of when code of an unknown origin was executed.