Hypervisor-Based Virtual Machine Audit Trail Recording

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud-computing environments, it is challenging to monitor and secure evidential data for security incidents, such as data leakage and malware infections, as malicious users or malware often circumvent security measures, and evidence may be difficult to obtain due to frequent resource changes and sharing.

Innovation Solution

A method and apparatus that detect and record in real-time the execution of processes within a virtual machine, activating monitoring events for data inflow and outflow, and storing audit trails using a hypervisor to prevent and investigate security incidents, including executable file creation, user selection downloads, and abnormal behaviors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If commercial security software is installed to block predicted security routes, then security prevention capability is improved, but malicious users or malware can circumvent or incapacitate such barriers, resulting in security incidents

Engineering Contradiction:
Improvesecurity prevention capabilityVSAvoidcircumvention of security measures
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary action by recording audit trails of process execution and data access before security incidents occur. The system proactively monitors and logs all process activities, file accesses, and data transfers in real-time, creating evidential data that can be used for post-incident analysis. This prevents the problem of lost evidence by ensuring records exist beforehand, rather than attempting to detect incidents after they happen.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary mechanism by implementing audit trail recording at the hypervisor level, which mediates between the virtual machine operations and the security monitoring system. This intermediary layer captures process execution and data access information without requiring installation of security agents inside virtual machines, thereby providing comprehensive monitoring while avoiding the limitations of traditional security software that can be circumvented.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If security agents are installed in virtual machines to monitor processes, then monitoring capability is improved, but device complexity and difficulty of deployment increase

Engineering Contradiction:
Improveprocess monitoring capabilityVSAvoidsecurity agent installation and configuration
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent eliminates the need for security agents inside virtual machines by implementing the audit trail recording function at the hypervisor level. The hypervisor acts as an intermediary that can observe and record all process executions, file accesses, and data transfers occurring within virtual machines without requiring any software installation within the guest operating systems. This simplifies deployment while maintaining comprehensive monitoring capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent makes the hypervisor serve multiple functions: it continues to perform its primary role of virtual machine management while simultaneously providing security audit trail recording. By consolidating these functions in the hypervisor layer, the system avoids the complexity of installing and maintaining separate security agents in each virtual machine, while achieving universal monitoring across all virtualized environments.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If cloud resources are frequently created, deleted and shared to improve resource utilization, then productivity is improved, but evidential data becomes difficult to secure for security incident investigation

Engineering Contradiction:
Improveresource utilization efficiencyVSAvoidevidential data availability
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent addresses the transient nature of cloud resources by implementing preliminary action through real-time audit trail recording. The system continuously logs process execution, file access, and data transfer information as events occur, ensuring evidential data is captured and preserved before virtual machines are deleted or resources are reallocated. This allows security incidents to be investigated even after the involved resources no longer exist.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements copying by creating persistent audit trail records that replicate the essential security-relevant information from transient virtual machine operations. Instead of relying on the continued existence of the original virtual machines or their file systems, the system copies critical security data (process names, file paths, data transfer information) into durable audit logs that survive resource lifecycle changes, enabling later forensic analysis.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS10802863B2Apparatus and method for storing audit trail in response to virtual-machine process execution
Publication Date: 2020.10.13 ELECTRONICS & TELECOMM RES INST
  • US10802863B2 patent drawing
  • US10802863B2 patent drawing
  • US10802863B2 patent drawing

AI summary

An apparatus and method for storing an audit trail in response to execution of a virtual-machine process. The method for storing an audit trail, performed by the apparatus for storing an audit trail in response to execution of a virtual-machine process, includes detecting execution of a process inside a virtual machine, determining whether the executed process is a monitoring target process and determining a type of the process, activating one or more monitoring events for monitoring at least one of an upload, a download and a drop by the process based on a result of the determination, and storing information about occurrence of the activated monitoring event as an audit trail.