Hypervisor Security Module Detecting Stealth Network Communications

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security techniques fail to detect and block stealth network communications used by malware to hide its presence and communicate with its base, as these techniques are evaded by malware using 'stealth' or 'rootkit' techniques, making it difficult to distinguish malicious traffic from normal traffic.

Innovation Solution

A method and system utilizing a hypervisor to supervise a virtual machine, which includes a communications module, verification module, and alteration module to identify and alter stealth network communications that the guest security module is unaware of, thereby blocking malicious communications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional security techniques (malware scanners and firewalls) are used to detect and block malware, then traditional malware can be detected and blocked, but stealth network communications used by modern malware cannot be detected

Engineering Contradiction:
Improvemalware detection capabilityVSAvoidstealth network communication detection
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces a new dimension of detection by implementing a hypervisor-based virtualization layer that operates at the hardware level, separate from the guest operating system. This allows the security module to monitor network communications in a dimension that is invisible to both the guest OS and malware, effectively adding a new layer of observation that bypasses stealth techniques.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

The patent employs a security module acting as an intermediary between the network interface card and the guest operating system. This intermediary captures and inspects all network traffic before it reaches the malware, allowing detection of stealth communications without being detected by the malware itself.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If malware uses stealth or rootkit techniques to hide its presence, then it can evade malware scanners, but this makes it impossible to distinguish malicious traffic from normal traffic

Engineering Contradiction:
Improvemalware evasion capabilityVSAvoidmalicious traffic identification
Core Design Contradiction:
Adaptability or versatilityVSDifficulty of detecting and measuring

Solution Approach 1:

Instead of trying to detect malware by analyzing its characteristics from within the guest OS (which malware can hide), the patent inverts the approach by monitoring network traffic from the hardware level upward. This allows identification of malicious traffic patterns that would be invisible to traditional scanners, effectively turning the detection problem inside out.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The security module performs preliminary inspection of network traffic at the hypervisor level, before the traffic reaches the guest OS or malware. This preliminary action allows the system to identify and block malicious communications before they can establish connections or exfiltrate data, preventing the malware from executing its evasion tactics.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If hardware firewalls are used to block network traffic, then they can filter traffic at the network level, but they cannot detect stealth network communications because malicious traffic is indistinguishable from normal traffic

Engineering Contradiction:
Improvenetwork traffic filtering efficiencyVSAvoidstealth communication detection accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent implements a nested architecture where a security module with its own verification logic is embedded within the hypervisor layer, which itself virtualizes the hardware firewall functionality. This nested structure allows multiple layers of inspection - the hardware firewall handles general traffic filtering while the embedded security module performs deep inspection of suspicious packets for stealth communications.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS8079030B1Detecting stealth network communications
Publication Date: 2011.12.13 CA TECH INC
  • US8079030B1 patent drawing
  • US8079030B1 patent drawing
  • US8079030B1 patent drawing

AI summary

A computer has a hypervisor that supervises a virtual machine. The virtual machine includes a guest security module that enforces a security policy on network traffic entering and exiting the virtual machine. Malicious software (malware) uses stealth network communications to avoid the guest security module and attempts to communicate with its home base. A security module within the hypervisor has access to all network communications entering and exiting the computer. The security module communicates with the guest security module to identify communications of which the guest security module is aware. The security module analyzes the network communications for the computer to identify a stealth network communication of which the guest security module is unaware. The security module alters the stealth network communication, thereby prevent the malware from communicating with its home base.