Sandboxed Browser Isolation for Malware Containment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Infected host computer systems pose security risks and efficiency reductions due to malware, compromising user privacy and allowing unauthorized access to networks, as existing solutions fail to effectively isolate and contain malicious software.
Innovation Solution
Implementing a sandbox-based internet isolation system with a trusted local area network (LAN) that segregates applications and processes using a sandbox container process, preventing unauthorized communication and executing malware within a controlled environment, while allowing user-initiated data transfers between memory spaces.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a host computer system connects to the Internet to access beneficial data, then information access capability is improved, but the system becomes vulnerable to malware infection and security threats
Solution Approach 1:
The patent divides the host computer system into multiple isolated memory spaces (first memory space for legitimate applications, second memory space for sandboxed browser). This segmentation allows the system to access the Internet through the sandboxed environment while preventing malware from affecting the main system, thus resolving the contradiction between Internet access capability and malware infection risk.
Solution Approach 2:
The patent introduces a sandboxed computing environment as an intermediary between the host computer system and the Internet. The sandbox container process acts as a mediator that allows controlled communication while blocking malicious data from reaching the main system, enabling Internet access while protecting against malware.
2Productivity
If malware is downloaded and executed on a host computer system, then the system can access and process data, but system integrity and security are compromised
Solution Approach 1:
The patent segments the execution environment by creating a separate second memory space for sandboxed applications. This allows data processing to occur in the sandboxed environment while maintaining system integrity in the first memory space, resolving the contradiction between productivity and reliability.
Solution Approach 2:
The patent applies different security qualities to different parts of the system. The first memory space maintains high security and integrity for critical system operations, while the second memory space allows more permissive execution for sandboxed applications. This local differentiation enables data processing while preserving overall system integrity.
3Ease of operation
If the system allows free communication between all applications and network resources, then ease of operation is improved, but unauthorized access and security breaches increase
Solution Approach 1:
The patent segments network communication paths by creating separate memory spaces with controlled access. The sandbox container process manages communication between the sandboxed environment and network resources, allowing legitimate applications to communicate freely while preventing unauthorized access through the sandboxed environment.
4Reliability
If the system implements strict isolation between memory spaces to prevent malware spread, then security is improved, but system functionality and user interaction are reduced
Solution Approach 1:
The sandbox container process serves as an intermediary that manages communication between the first and second memory spaces. It enforces security isolation while allowing controlled data transfer and user interaction, thus maintaining both security and system functionality.
Solution Approach 2:
The sandbox container process performs multiple functions: it isolates the sandboxed environment, manages network communication, controls data transfer between memory spaces, and maintains security policies. This multi-functionality allows strict isolation while preserving system functionality through a single versatile component.
Data Source
AI summary
Methods and systems are disclosed for sandbox based internet isolation system in a trusted network. A networked computer system may include a trusted local area network (LAN) and at least one host computer system connected to the trusted LAN. The host computer system may include a host-based firewall, an operating system, a first memory space, and a second memory space. The host-based firewall may be configured to prevent unauthorized communication between the host computer system and one or more other devices on the trusted LAN. The second memory space may be configured to enable storage and/or operation of one or more applications and/or processes associated with a sandboxed computing environment. The host computer system may include a sandbox firewall that enforces a separation of the first and second memory spaces.


