Hypervisor Stream Duplication for Non-Intrusive VM Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security techniques for virtual machines in cloud computing environments are inadequate, as customers are hesitant to integrate security agents provided by service providers due to concerns about data confidentiality and the potential impact on their virtual machines, and existing solutions do not fully meet the needs for comprehensive security monitoring.

Innovation Solution

A method and device for supervising the security of virtual machines by duplicating the data stream processed by the hypervisor, allowing a security agent to analyze a duplicate stream independently of the client's virtual machine, ensuring non-intrusive monitoring and maintaining the integrity of the client's virtual machine, with options for either duplicating the virtual machine in memory or building a memory representation for analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a security agent is installed on the customer's virtual machine to monitor security, then security monitoring capability is improved, but the customer's data confidentiality and virtual machine integrity are compromised

Engineering Contradiction:
Improvesecurity monitoring capabilityVSAvoiddata confidentiality risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent creates a duplicate copy of the data stream processed by the hypervisor and directs it to a separate security agent for analysis. This copying approach allows security monitoring without the agent having direct access to or control over the customer's actual virtual machine and data, thereby maintaining confidentiality while enabling monitoring.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces the hypervisor as an intermediary layer between the customer's virtual machine and the security agent. The hypervisor captures and redirects data streams to the security agent, preventing direct interaction between the agent and the customer's system. This intermediary mechanism ensures that the security agent can monitor for threats without compromising the integrity or confidentiality of the customer's virtual machine.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If a security agent is provided by the service provider and installed on the virtual machine, then comprehensive security coverage is improved, but customer trust and acceptance deteriorate due to lack of control

Engineering Contradiction:
Improvesecurity coverageVSAvoidcustomer control
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The hypervisor serves as an intermediary that enables the service provider to deploy security agents and configure security policies without requiring direct customer control or consent for each security decision. The intermediary architecture allows centralized security management while maintaining customer trust through transparent, non-intrusive monitoring of data streams.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If security monitoring is implemented through traditional agent-based methods, then security detection capability is improved, but system performance and processing efficiency deteriorate due to additional overhead

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidprocessing efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

Instead of installing agents that directly intercept and analyze system calls within the virtual machine (which would add significant overhead), the patent copies the already-processed data stream from the hypervisor. This copying approach leverages the hypervisor's existing processing infrastructure, avoiding duplicate analysis work and minimizing performance impact while maintaining comprehensive security detection capability.

Inventive Principle:
Principle #26Copying

Data Source

PatentEP3155551B1Virtual machine security management method in a cloud computing system
Publication Date: 2022.07.27 ORANGE SA
  • EP3155551B1 patent drawingFigure 1~4
  • EP3155551B1 patent drawingFigure 2~3

AI summary

The invention relates to a method for monitoring the security of a virtual machine (VMI) hosted by a host system (10), the virtual machine including an operating system (OSI) communicating with a hypervisor (101) of the host system, said hypervisor interfacing between the operating system and hardware resources of the host system, said method including the following steps: receiving (E3, E1') at least one machine instruction corresponding to an interruption in the operating system, said interruption following an event having occurred in the virtual machine; executing (E4, E2') the instruction by the hypervisor using the hardware resources of the host system and transmitting to the operating system a data stream including the result of the execution, characterised in that the sent data stream is duplicated (E5, E3') in a second stream and the second stream is analysed (E6, E4') by a security agent (102) running on an entity separate from the virtual machine (10-2, VMI') in order to detect a security problem during the processing of the interruption.