Hypervisor Application Control Engine for Virtualized Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In modern virtualized environments, managing and controlling software execution across diverse and dynamic software applications is challenging, particularly in preventing unauthorized software execution and reducing security risks from malicious software, as traditional application control methods are not effectively suited for hardware virtualization configurations.
Innovation Solution
A server computer system configured to perform application control transactions with client systems by receiving an identity indicator of a target process, transmitting an application control policy, and executing an application control engine outside guest virtual machines to detect and enforce execution permissions, preventing unauthorized processes from running.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional application control methods are used in virtualized environments, then application control can be implemented, but security effectiveness deteriorates due to the dynamic and heterogeneous nature of virtual machines
Solution Approach 1:
The patent transitions application control from a guest-OS level approach to a hypervisor level approach, effectively moving control to another dimension of the virtualization stack. This allows the application control engine to operate outside guest VMs and enforce policies across all VMs on a host, addressing the security effectiveness issue in dynamic virtualized environments.
Solution Approach 2:
The patent introduces an application control engine that operates at the hypervisor level as an intermediary between the virtualized applications and the underlying hardware. This intermediary can detect, identify, and control applications across multiple VMs without being confined to individual guest OSes, improving security effectiveness in virtualized environments.
2Ease of operation
If application control engine executes inside guest virtual machines, then application control can be enforced, but security risk increases due to potential malware compromise of the control engine
Solution Approach 1:
The patent extracts the application control engine from inside guest VMs and places it at the hypervisor level, outside the virtualized environment. This extraction removes the control engine from the attack surface of individual VMs, preventing malware within any single VM from compromising the application control functionality while maintaining enforcement capabilities.
Solution Approach 2:
By positioning the application control engine at the hypervisor level before applications execute within VMs, the system can preemptively detect and block malicious applications before they can compromise the control mechanism. This preliminary anti-action prevents malware from gaining control of the application control engine.
3Productivity
If multiple virtual machines run simultaneously on the same physical machine, then resource utilization improves, but application control complexity increases due to heterogeneous software environments
Solution Approach 1:
The patent creates a universal application control engine at the hypervisor level that can manage applications across multiple diverse VMs simultaneously. This single control mechanism handles heterogeneous software environments (different OSes, applications, and VM configurations) through a unified approach, reducing control complexity while maintaining high resource utilization from multiple concurrent VMs.
Data Source
AI summary
Described systems and methods enable enforcing application control remotely and automatically, on a relatively large number of client systems (e.g., a corporate network, a virtual desktop infrastructure system, etc.). An application control engine executes outside a virtual machine exposed on a client system, the application control engine configured to enforce application control within the virtual machine according to a set of control policies. When a policy indicates that a specific process is not allowable on the respective client system, the app control engine may prevent execution of the respective process. To assist in data gathering and/or other activities associated with application control, some embodiments temporarily drop a control agent into the controlled virtual machine.


