Peer-Aware Self-Regulation for Virtual Machine Anti-Malware
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In virtualized environments, anti-malware solutions face challenges in detecting and managing resource-intensive operations across multiple virtual machines, leading to potential overload and inefficiencies in malware detection and prevention, especially with evolving malware threats.
Innovation Solution
A peer-aware self-regulation system that utilizes a monitor module to monitor and regulate resource usage across virtual machines, allowing or throttling operations based on predefined thresholds and rules to optimize resource allocation and prevent overload.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If multiple virtual machines perform anti-malware operations simultaneously, then malware detection coverage is improved, but system resource consumption increases and leads to overload
Solution Approach 1:
The monitor module continuously monitors resource usage across virtual machines and provides feedback to regulate anti-malware operations. When resource consumption thresholds are exceeded, the system automatically throttles or schedules operations to balance detection coverage with system resource availability, preventing overload while maintaining security effectiveness
Solution Approach 2:
The system dynamically adjusts the scheduling and throttling of anti-malware operations based on real-time resource conditions. Virtual machines can transition between different operation states (full scanning, throttled scanning, or deferred scanning) depending on current system load, allowing flexible adaptation to changing resource availability while maintaining comprehensive malware detection capability
2Stability of the object's composition
If virtual machines are isolated in virtualized environments, then system stability is improved, but awareness of peer operations is lost leading to resource conflicts
Solution Approach 1:
The monitor module acts as an intermediary between isolated virtual machines, collecting information about anti-malware operations and resource usage from each VM and sharing this information across the virtualized environment. This mediator approach maintains VM isolation for stability while enabling peer awareness for coordinated resource management, allowing VMs to adjust their operations based on what other VMs are doing without direct communication between them
3Reliability
If anti-malware operations are performed frequently, then malware detection effectiveness is improved, but system performance degrades due to resource-intensive operations
Solution Approach 1:
The system applies partial action by throttling anti-malware operations in virtual machines when system resources are constrained. Instead of allowing all VMs to perform full scanning simultaneously, the monitor module selectively reduces or defers operations in certain VMs based on current system performance, ensuring that critical security functions continue while preventing overall system degradation
Data Source
AI summary
Technologies for self-regulation for virtualized environments may include, by a virtual machine on an electronic device, detecting an attempted anti-malware operation by a monitored module, determining anti-malware operation levels of one or more other virtual machines on the electronic device, and, based on the attempted anti-malware operation and upon the anti-malware operation levels, determining whether to allow the attempted operation.


