Hypervisor Application Control Engine for Virtualized Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In modern virtualized environments, managing and controlling software execution across diverse and dynamic software applications is challenging, particularly in preventing unauthorized software execution and reducing security risks from malicious software, as traditional application control methods are not effectively suited for hardware virtualization configurations.

Innovation Solution

A server computer system configured to perform application control transactions with client systems by receiving an identity indicator of a target process, transmitting an application control policy, and executing an application control engine outside guest virtual machines to detect and enforce execution permissions, preventing unauthorized processes from running.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional application control methods are used in virtualized environments, then application control can be implemented, but security effectiveness deteriorates due to the dynamic and heterogeneous nature of virtual machines

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidadaptability to virtualized environments
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent transitions application control from a guest-OS level approach to a hypervisor level approach, effectively moving control to another dimension of the virtualization stack. This allows the application control engine to operate outside guest VMs and enforce policies across all VMs on a host, addressing the security effectiveness issue in dynamic virtualized environments.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent introduces an application control engine that operates at the hypervisor level as an intermediary between the virtualized applications and the underlying hardware. This intermediary can detect, identify, and control applications across multiple VMs without being confined to individual guest OSes, improving security effectiveness in virtualized environments.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If application control engine executes inside guest virtual machines, then application control can be enforced, but security risk increases due to potential malware compromise of the control engine

Engineering Contradiction:
Improveapplication control enforcementVSAvoidsecurity risk from malware
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent extracts the application control engine from inside guest VMs and places it at the hypervisor level, outside the virtualized environment. This extraction removes the control engine from the attack surface of individual VMs, preventing malware within any single VM from compromising the application control functionality while maintaining enforcement capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

By positioning the application control engine at the hypervisor level before applications execute within VMs, the system can preemptively detect and block malicious applications before they can compromise the control mechanism. This preliminary anti-action prevents malware from gaining control of the application control engine.

Inventive Principle:
Principle #9Preliminary anti-action

3Productivity

If multiple virtual machines run simultaneously on the same physical machine, then resource utilization improves, but application control complexity increases due to heterogeneous software environments

Engineering Contradiction:
Improveresource utilizationVSAvoidapplication control complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent creates a universal application control engine at the hypervisor level that can manage applications across multiple diverse VMs simultaneously. This single control mechanism handles heterogeneous software environments (different OSes, applications, and VM configurations) through a unified approach, reducing control complexity while maintaining high resource utilization from multiple concurrent VMs.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10445498B2Systems and methods of application control in virtualized environments
Publication Date: 2019.10.15 BITDEFENDER IPR MANAGEMENT
  • US10445498B2 patent drawing
  • US10445498B2 patent drawing
  • US10445498B2 patent drawing

AI summary

Described systems and methods enable enforcing application control remotely and automatically, on a relatively large number of client systems (e.g., a corporate network, a virtual desktop infrastructure system, etc.). An application control engine executes outside a virtual machine exposed on a client system, the application control engine configured to enforce application control within the virtual machine according to a set of control policies. When a policy indicates that a specific process is not allowable on the respective client system, the app control engine may prevent execution of the respective process. To assist in data gathering and/or other activities associated with application control, some embodiments temporarily drop a control agent into the controlled virtual machine.