Peer-Aware Self-Regulation for Virtual Machine Anti-Malware

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In virtualized environments, anti-malware solutions face challenges in detecting and managing resource-intensive operations across multiple virtual machines, leading to potential overload and inefficiencies in malware detection and prevention, especially with evolving malware threats.

Innovation Solution

A peer-aware self-regulation system that utilizes a monitor module to monitor and regulate resource usage across virtual machines, allowing or throttling operations based on predefined thresholds and rules to optimize resource allocation and prevent overload.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple virtual machines perform anti-malware operations simultaneously, then malware detection coverage is improved, but system resource consumption increases and leads to overload

Engineering Contradiction:
Improvemalware detection coverageVSAvoidsystem resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The monitor module continuously monitors resource usage across virtual machines and provides feedback to regulate anti-malware operations. When resource consumption thresholds are exceeded, the system automatically throttles or schedules operations to balance detection coverage with system resource availability, preventing overload while maintaining security effectiveness

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system dynamically adjusts the scheduling and throttling of anti-malware operations based on real-time resource conditions. Virtual machines can transition between different operation states (full scanning, throttled scanning, or deferred scanning) depending on current system load, allowing flexible adaptation to changing resource availability while maintaining comprehensive malware detection capability

Inventive Principle:
Principle #15Dynamics

2Stability of the object's composition

If virtual machines are isolated in virtualized environments, then system stability is improved, but awareness of peer operations is lost leading to resource conflicts

Engineering Contradiction:
Improvesystem stabilityVSAvoidpeer operation awareness
Core Design Contradiction:
Stability of the object's compositionVSLoss of information

Solution Approach 1:

The monitor module acts as an intermediary between isolated virtual machines, collecting information about anti-malware operations and resource usage from each VM and sharing this information across the virtualized environment. This mediator approach maintains VM isolation for stability while enabling peer awareness for coordinated resource management, allowing VMs to adjust their operations based on what other VMs are doing without direct communication between them

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If anti-malware operations are performed frequently, then malware detection effectiveness is improved, but system performance degrades due to resource-intensive operations

Engineering Contradiction:
Improvemalware detection effectivenessVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system applies partial action by throttling anti-malware operations in virtual machines when system resources are constrained. Instead of allowing all VMs to perform full scanning simultaneously, the monitor module selectively reduces or defers operations in certain VMs based on current system performance, ensuring that critical security functions continue while preventing overall system degradation

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9430647B2Peer-aware self-regulation for virtualized environments
Publication Date: 2016.08.30 MCAFEE LLC
  • US9430647B2 patent drawing
  • US9430647B2 patent drawing
  • US9430647B2 patent drawing

AI summary

Technologies for self-regulation for virtualized environments may include, by a virtual machine on an electronic device, detecting an attempted anti-malware operation by a monitored module, determining anti-malware operation levels of one or more other virtual machines on the electronic device, and, based on the attempted anti-malware operation and upon the anti-malware operation levels, determining whether to allow the attempted operation.