Hypervisor-Based Virtual Machine Audit Trail Recording
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In cloud-computing environments, it is challenging to monitor and secure evidential data for security incidents, such as data leakage and malware infections, as malicious users or malware often circumvent security measures, and evidence may be difficult to obtain due to frequent resource changes and sharing.
Innovation Solution
A method and apparatus that detect and record in real-time the execution of processes within a virtual machine, activating monitoring events for data inflow and outflow, and storing audit trails using a hypervisor to prevent and investigate security incidents, including executable file creation, user selection downloads, and abnormal behaviors.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If commercial security software is installed to block predicted security routes, then security prevention capability is improved, but malicious users or malware can circumvent or incapacitate such barriers, resulting in security incidents
Solution Approach 1:
The patent implements preliminary action by recording audit trails of process execution and data access before security incidents occur. The system proactively monitors and logs all process activities, file accesses, and data transfers in real-time, creating evidential data that can be used for post-incident analysis. This prevents the problem of lost evidence by ensuring records exist beforehand, rather than attempting to detect incidents after they happen.
Solution Approach 2:
The patent introduces an intermediary mechanism by implementing audit trail recording at the hypervisor level, which mediates between the virtual machine operations and the security monitoring system. This intermediary layer captures process execution and data access information without requiring installation of security agents inside virtual machines, thereby providing comprehensive monitoring while avoiding the limitations of traditional security software that can be circumvented.
2Measurement precision
If security agents are installed in virtual machines to monitor processes, then monitoring capability is improved, but device complexity and difficulty of deployment increase
Solution Approach 1:
The patent eliminates the need for security agents inside virtual machines by implementing the audit trail recording function at the hypervisor level. The hypervisor acts as an intermediary that can observe and record all process executions, file accesses, and data transfers occurring within virtual machines without requiring any software installation within the guest operating systems. This simplifies deployment while maintaining comprehensive monitoring capability.
Solution Approach 2:
The patent makes the hypervisor serve multiple functions: it continues to perform its primary role of virtual machine management while simultaneously providing security audit trail recording. By consolidating these functions in the hypervisor layer, the system avoids the complexity of installing and maintaining separate security agents in each virtual machine, while achieving universal monitoring across all virtualized environments.
3Productivity
If cloud resources are frequently created, deleted and shared to improve resource utilization, then productivity is improved, but evidential data becomes difficult to secure for security incident investigation
Solution Approach 1:
The patent addresses the transient nature of cloud resources by implementing preliminary action through real-time audit trail recording. The system continuously logs process execution, file access, and data transfer information as events occur, ensuring evidential data is captured and preserved before virtual machines are deleted or resources are reallocated. This allows security incidents to be investigated even after the involved resources no longer exist.
Solution Approach 2:
The patent implements copying by creating persistent audit trail records that replicate the essential security-relevant information from transient virtual machine operations. Instead of relying on the continued existence of the original virtual machines or their file systems, the system copies critical security data (process names, file paths, data transfer information) into durable audit logs that survive resource lifecycle changes, enabling later forensic analysis.
Data Source
AI summary
An apparatus and method for storing an audit trail in response to execution of a virtual-machine process. The method for storing an audit trail, performed by the apparatus for storing an audit trail in response to execution of a virtual-machine process, includes detecting execution of a process inside a virtual machine, determining whether the executed process is a monitoring target process and determining a type of the process, activating one or more monitoring events for monitoring at least one of an upload, a download and a drop by the process based on a result of the determination, and storing information about occurrence of the activated monitoring event as an audit trail.


