Isolated Computing Environment for Software Vulnerability Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional software vulnerability detection systems are ineffective in recognizing variants and unknown threats, as they rely on signature-based techniques that are reactive and prone to noise, making it difficult to detect and mitigate software vulnerabilities effectively.

Innovation Solution

An isolated computing environment is created with segregated computing units configured in different combinations of resources and software versions, where security tools and scanning programs are used to evaluate files and URLs, and security amplifying techniques are applied to cause malicious code to crash, allowing for precise identification of exploited vulnerabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If signature-based techniques are used to detect security threats, then known vulnerabilities can be identified, but variants and unknown threats cannot be recognized

Engineering Contradiction:
Improvedetection accuracyVSAvoidthreat variant recognition
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary actions by proactively deploying computing environments to the Internet before threats are known, allowing detection of unknown vulnerabilities before they can be exploited in the wild. This shifts from reactive signature-based detection to proactive exploration of software weaknesses.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system inverts the conventional approach by deliberately creating unsecure computing environments (HoneyPots) instead of secure ones, allowing threats to manifest and be captured in controlled settings. This inversion enables detection of threats that would otherwise remain hidden in secure production environments.

Inventive Principle:
Principle #13The other way round (Inversion)

2Speed

If HoneyPots are deployed to catch infections, then detection speed improves, but the approach becomes noisy and easily circumvented

Engineering Contradiction:
Improveinfection detection speedVSAvoiddetection precision
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The system segments the detection approach by creating multiple isolated computing environments with different configurations rather than using a single HoneyPot. Each environment is segmented to test specific vulnerability hypotheses, reducing noise by isolating detection signals to specific configuration contexts.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies local quality by configuring each computing environment with specific, targeted settings designed to reveal particular types of vulnerabilities. Rather than using generic HoneyPots, each environment has localized qualities (specific software versions, security configurations) that make detection more precise and harder to circumvent.

Inventive Principle:
Principle #3Local quality

3Measurement precision

If custom signatures are written for each vulnerability, then detection precision improves, but system complexity and time consumption increase

Engineering Contradiction:
Improvevulnerability identification precisionVSAvoidsignature maintenance complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system enables self-service by automatically generating vulnerability detections through controlled code execution in isolated environments. Rather than requiring security experts to manually create and maintain custom signatures, the system autonomously identifies vulnerabilities through programmatic exploration and analysis of software behavior in tested configurations.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9021587B2Detecting software vulnerabilities in an isolated computing environment
Publication Date: 2015.04.28 MICROSOFT TECHNOLOGY LICENSING LLC
  • US9021587B2 patent drawing
  • US9021587B2 patent drawing
  • US9021587B2 patent drawing

AI summary

The subject disclosure is directed towards detecting software vulnerabilities in an isolated computing environment. In order to evaluate each input submission from an external computer, a plurality of tasks are automatically generated for execution on one or more computing units running within the isolated computing environment. Various configurations of the one or more computing units are defined in which each computing unit executes the plurality of tasks. A report is produced comprising results associated with such an execution.