Sandboxed Browser Isolation for Malware Containment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Infected host computer systems pose security risks and efficiency reductions due to malware, compromising user privacy and allowing unauthorized access to networks, as existing solutions fail to effectively isolate and contain malicious software.

Innovation Solution

Implementing a sandbox-based internet isolation system with a trusted local area network (LAN) that segregates applications and processes using a sandbox container process, preventing unauthorized communication and executing malware within a controlled environment, while allowing user-initiated data transfers between memory spaces.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If a host computer system connects to the Internet to access beneficial data, then information access capability is improved, but the system becomes vulnerable to malware infection and security threats

Engineering Contradiction:
ImproveInternet access capabilityVSAvoidMalware infection risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent divides the host computer system into multiple isolated memory spaces (first memory space for legitimate applications, second memory space for sandboxed browser). This segmentation allows the system to access the Internet through the sandboxed environment while preventing malware from affecting the main system, thus resolving the contradiction between Internet access capability and malware infection risk.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a sandboxed computing environment as an intermediary between the host computer system and the Internet. The sandbox container process acts as a mediator that allows controlled communication while blocking malicious data from reaching the main system, enabling Internet access while protecting against malware.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If malware is downloaded and executed on a host computer system, then the system can access and process data, but system integrity and security are compromised

Engineering Contradiction:
ImproveData processing capabilityVSAvoidSystem integrity
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent segments the execution environment by creating a separate second memory space for sandboxed applications. This allows data processing to occur in the sandboxed environment while maintaining system integrity in the first memory space, resolving the contradiction between productivity and reliability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different security qualities to different parts of the system. The first memory space maintains high security and integrity for critical system operations, while the second memory space allows more permissive execution for sandboxed applications. This local differentiation enables data processing while preserving overall system integrity.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If the system allows free communication between all applications and network resources, then ease of operation is improved, but unauthorized access and security breaches increase

Engineering Contradiction:
ImproveApplication communication freedomVSAvoidUnauthorized network access
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent segments network communication paths by creating separate memory spaces with controlled access. The sandbox container process manages communication between the sandboxed environment and network resources, allowing legitimate applications to communicate freely while preventing unauthorized access through the sandboxed environment.

Inventive Principle:
Principle #1Segmentation

4Reliability

If the system implements strict isolation between memory spaces to prevent malware spread, then security is improved, but system functionality and user interaction are reduced

Engineering Contradiction:
ImproveSecurity isolationVSAvoidSystem functionality
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The sandbox container process serves as an intermediary that manages communication between the first and second memory spaces. It enforces security isolation while allowing controlled data transfer and user interaction, thus maintaining both security and system functionality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The sandbox container process performs multiple functions: it isolates the sandboxed environment, manages network communication, controls data transfer between memory spaces, and maintains security policies. This multi-functionality allows strict isolation while preserving system functionality through a single versatile component.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10558798B2Sandbox based Internet isolation in a trusted network
Publication Date: 2020.02.11 CROGA INNOVATIONS LTD
  • US10558798B2 patent drawing
  • US10558798B2 patent drawing
  • US10558798B2 patent drawing

AI summary

Methods and systems are disclosed for sandbox based internet isolation system in a trusted network. A networked computer system may include a trusted local area network (LAN) and at least one host computer system connected to the trusted LAN. The host computer system may include a host-based firewall, an operating system, a first memory space, and a second memory space. The host-based firewall may be configured to prevent unauthorized communication between the host computer system and one or more other devices on the trusted LAN. The second memory space may be configured to enable storage and/or operation of one or more applications and/or processes associated with a sandboxed computing environment. The host computer system may include a sandbox firewall that enforces a separation of the first and second memory spaces.