Secure AV Module for Virtual Machine Disk Image Scanning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for virus scanning in virtual machines are resource-intensive and costly, as they require transferring and scanning virtual machine disk images on VM servers, which consumes network and computing resources, and involve installing anti-virus software on each VM, leading to increased licensing and maintenance costs.

Innovation Solution

Implementing a secure AV module on network storage devices that coordinates with a file system and anti-virus engine to perform virus scans directly on VMDK files, eliminating the need to transfer VM disk images and reducing resource usage by scanning files locally on storage devices, thereby optimizing resource utilization and minimizing costs.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If virus scans are performed by transferring VM disk images to VM servers, then virus detection capability is improved, but network bandwidth consumption increases

Engineering Contradiction:
Improvevirus detection capabilityVSAvoidnetwork bandwidth consumption
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

Instead of transferring VM disk images to VM servers for scanning, the patent inverts the approach by deploying the scanning capability directly to the storage device where the VMDK files are stored. The secure AV module on the storage device performs virus scans locally, eliminating the need to transfer large disk image files over the network while maintaining comprehensive virus detection capability.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent segments the virus scanning function from the VM server infrastructure and places it on the storage device. By dividing the system into separate components (storage device with secure AV module, VM servers, and network), the scanning operation can be performed independently at the storage location, avoiding network transfer overhead while maintaining detection effectiveness.

Inventive Principle:
Principle #1Segmentation

2Reliability

If virus scans are performed by transferring VM disk images to VM servers, then virus detection capability is improved, but computing resource usage increases

Engineering Contradiction:
Improvevirus detection capabilityVSAvoidcomputing resource usage
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent inverts the traditional scanning architecture by moving the anti-virus scanning capability from VM servers to the storage device. The secure AV module on the storage device performs scans locally on VMDK files, eliminating the need to consume VM server computing resources for scanning operations while maintaining full virus detection capability.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The storage device provides self-service virus scanning capabilities through the secure AV module, which can independently scan VMDK files without requiring external computing resources from VM servers. The storage device serves its own security needs by performing scans locally, reducing the computing burden on the VM server infrastructure.

Inventive Principle:
Principle #25Self-service

3Reliability

If anti-virus software is installed on each VM, then virus protection coverage is improved, but licensing and maintenance costs increase

Engineering Contradiction:
Improvevirus protection coverageVSAvoidsoftware installation and maintenance
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal scanning solution where a single secure AV module on the storage device can scan multiple VMDK files from multiple VMs simultaneously. This multi-functional approach provides virus protection coverage for all VMs through one centralized scanning capability, eliminating the need for separate anti-virus software installations on each VM while maintaining comprehensive protection.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The secure AV module on the storage device acts as an intermediary between the VMs and the virus detection process. Instead of requiring direct anti-virus software on each VM, the mediator (secure AV module) performs scanning on the VMDK files at the storage level, providing indirect but effective virus protection for all VMs without the complexity of individual installations.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9268689B1Securing virtual machines with optimized anti-virus scan
Publication Date: 2016.02.23 COHESITY INC
  • US9268689B1 patent drawing
  • US9268689B1 patent drawing
  • US9268689B1 patent drawing

AI summary

The present disclosure provides for performing virus scans at a storage device that stores one or more virtual machine disk image files (VMDK files). A secure AV module can coordinate communication between a file system on the storage device, a file system (FS) decoder, and an anti-virus engine to perform a virus scan of files contained within a VMDK file. A secure AV module can determine a subset of files that include changed data, where the subset of files is stored in a file system volume within a VMDK file. The secure AV module can use an FS decoder to translate file addresses relative to the file system volume into file addresses relative to the network storage file system. A secure AV module can provide the network storage file system addresses of the subset of files to the anti-virus engine, which can perform a virus scan on the files.