Hypervisor Security Module Detecting Stealth Network Communications
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional security techniques fail to detect and block stealth network communications used by malware to hide its presence and communicate with its base, as these techniques are evaded by malware using 'stealth' or 'rootkit' techniques, making it difficult to distinguish malicious traffic from normal traffic.
Innovation Solution
A method and system utilizing a hypervisor to supervise a virtual machine, which includes a communications module, verification module, and alteration module to identify and alter stealth network communications that the guest security module is unaware of, thereby blocking malicious communications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If conventional security techniques (malware scanners and firewalls) are used to detect and block malware, then traditional malware can be detected and blocked, but stealth network communications used by modern malware cannot be detected
Solution Approach 1:
The patent introduces a new dimension of detection by implementing a hypervisor-based virtualization layer that operates at the hardware level, separate from the guest operating system. This allows the security module to monitor network communications in a dimension that is invisible to both the guest OS and malware, effectively adding a new layer of observation that bypasses stealth techniques.
Solution Approach 2:
The patent employs a security module acting as an intermediary between the network interface card and the guest operating system. This intermediary captures and inspects all network traffic before it reaches the malware, allowing detection of stealth communications without being detected by the malware itself.
2Adaptability or versatility
If malware uses stealth or rootkit techniques to hide its presence, then it can evade malware scanners, but this makes it impossible to distinguish malicious traffic from normal traffic
Solution Approach 1:
Instead of trying to detect malware by analyzing its characteristics from within the guest OS (which malware can hide), the patent inverts the approach by monitoring network traffic from the hardware level upward. This allows identification of malicious traffic patterns that would be invisible to traditional scanners, effectively turning the detection problem inside out.
Solution Approach 2:
The security module performs preliminary inspection of network traffic at the hypervisor level, before the traffic reaches the guest OS or malware. This preliminary action allows the system to identify and block malicious communications before they can establish connections or exfiltrate data, preventing the malware from executing its evasion tactics.
3Productivity
If hardware firewalls are used to block network traffic, then they can filter traffic at the network level, but they cannot detect stealth network communications because malicious traffic is indistinguishable from normal traffic
Solution Approach 1:
The patent implements a nested architecture where a security module with its own verification logic is embedded within the hypervisor layer, which itself virtualizes the hardware firewall functionality. This nested structure allows multiple layers of inspection - the hardware firewall handles general traffic filtering while the embedded security module performs deep inspection of suspicious packets for stealth communications.
Data Source
AI summary
A computer has a hypervisor that supervises a virtual machine. The virtual machine includes a guest security module that enforces a security policy on network traffic entering and exiting the virtual machine. Malicious software (malware) uses stealth network communications to avoid the guest security module and attempts to communicate with its home base. A security module within the hypervisor has access to all network communications entering and exiting the computer. The security module communicates with the guest security module to identify communications of which the guest security module is aware. The security module analyzes the network communications for the computer to identify a stealth network communication of which the guest security module is unaware. The security module alters the stealth network communication, thereby prevent the malware from communicating with its home base.


