Microcode Security Agent Updates via Embedded Interpreter

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security technologies face challenges in effectively segmenting networks to reduce risk, particularly in cloud and data center environments, due to the complexity and cost of implementing and managing fine-grained access rules, as well as limitations in logging and reporting by lightweight local security agents.

Innovation Solution

The implementation of synthetic audit events, stream processing of telemetry for incremental network topology development, and software security agent updates via microcode, which collectively enhance network segmentation, logging, and security policy enforcement in a Zero Trust architecture.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If legacy virtual firewalls are used for network segmentation, then network security is improved, but the cost, complexity, and time involved in implementation and management increases significantly

Engineering Contradiction:
Improvenetwork securityVSAvoidsegmentation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent replaces traditional hardware-based virtual firewalls with a software agent embedded in the hypervisor that uses virtualization mechanisms to enforce security policies. This substitution reduces complexity by leveraging the existing virtualization infrastructure rather than adding separate hardware appliances for each segmentation function.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The security agent in the hypervisor serves multiple functions: it enforces security policies, performs logging and reporting, and manages network segmentation simultaneously. This multi-functionality reduces the need for separate systems and lowers overall complexity compared to traditional virtual firewall approaches.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Use of energy by moving object

If lightweight local security agents are deployed on hosts, then resource consumption is reduced, but logging and reporting capabilities are limited

Engineering Contradiction:
Improveagent resource consumptionVSAvoidlogging and reporting information
Core Design Contradiction:
Use of energy by moving objectVSLoss of information

Solution Approach 1:

The patent introduces the hypervisor as an intermediary layer between the lightweight security agents on hosts and the centralized logging system. The hypervisor aggregates security events from multiple agents and forwards consolidated logs to the logging system, enabling comprehensive reporting without requiring resource-intensive agents on each host.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent combines the logging and reporting functions of multiple lightweight agents into a centralized hypervisor-level logging system. This merging approach preserves the low resource consumption of individual agents while achieving comprehensive logging capabilities through aggregation at the hypervisor layer.

Inventive Principle:
Principle #5Merging (Combining)

3Measurement precision

If fine-grained access rules are created for each host and application, then security precision is improved, but the number of rules and management complexity increases

Engineering Contradiction:
Improveaccess control precisionVSAvoidrule management complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the network into virtual network segments controlled by the hypervisor, allowing fine-grained access control policies to be applied at the segment level rather than requiring individual rules for each host-application pair. This segmentation reduces the total number of rules while maintaining precision through targeted policy enforcement at appropriate granularities.

Inventive Principle:
Principle #1Segmentation

4Manufacturing precision

If manual crafting of security rules is performed, then policy accuracy is improved, but the time and expertise required increases significantly

Engineering Contradiction:
Improvepolicy accuracyVSAvoidrule creation time
Core Design Contradiction:
Manufacturing precisionVSLoss of time

Solution Approach 1:

The patent enables the system to automatically generate and enforce security policies based on observed network traffic patterns and defined security requirements. The hypervisor-based agent automatically adapts security rules without requiring manual crafting by security personnel, reducing both the time required and the expertise needed while maintaining policy accuracy through automated policy generation and enforcement.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250184366A1Software security agent updates via microcode
Publication Date: 2025.06.05 ZSCALER INC
  • US20250184366A1 patent drawing
  • US20250184366A1 patent drawing
  • US20250184366A1 patent drawing

AI summary

Systems and methods for updating a security agent installed on a computing device without requiring a scheduled software update window include steps of receiving a digitally signed script from a remote server, wherein the security agent includes an embedded interpreter configured to execute script-based instructions; verifying a digital signature of the digitally signed script using a public key embedded in the security agent; and executing the digitally signed script via the embedded interpreter at runtime to modify functionality of the security agent without recompiling or reinstalling compiled code.