Secure Virtual Machine for Malware Isolation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current data processing systems are vulnerable to unintentional malware downloads through email attachments and web site links, which can lead to disruptions and data breaches, as existing protection methods are inadequate in preventing malicious software infections.
Innovation Solution
A computer-implemented method utilizing secure virtual machines and secure central processing units, where a data processing system receives input to access an email attachment or web site link, generates a new secure virtual machine from a network server or cloud computing service, processes the input within this isolated environment, and discards it after use to prevent malware infection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a user opens email attachments or visits web sites directly on their device, then access to the content is immediate and convenient, but the device becomes vulnerable to malware infection
Solution Approach 1:
The patent introduces a secure virtual machine as an intermediary between the user's device and the potentially malicious content. The virtual machine acts as a mediator that receives email attachments or web site links, processes them in an isolated environment, and communicates results back to the user without exposing the user's device to malware. This resolves the contradiction by maintaining convenient access while blocking harmful factors through the intermediary layer.
Solution Approach 2:
The patent segments the content processing function into a separate virtual machine instance that is isolated from the user's host device. By dividing the system into distinct segments (host device and guest virtual machine), the patent allows the harmful content to be processed in the segmented environment without affecting the main system, thus maintaining ease of operation while preventing malware infection.
2Reliability
If existing protection methods are used, then some level of security is provided, but they are inadequate in preventing malicious software infections
Solution Approach 1:
The patent creates a copy of the user's computing environment in the form of a virtual machine. This copy includes a simplified operating system and application layer that can execute content safely. By working with a copy rather than the original system, the patent achieves reliable security protection - if malware executes in the virtual machine copy, it cannot infect the user's actual device, thus resolving the inadequacy of existing protection methods.
Solution Approach 2:
The patent creates an inert, isolated environment through the virtual machine that is separated from the user's main system. This inert environment acts as a containment zone where malicious software can execute without affecting the host device. The virtual machine's isolated architecture provides reliable security protection by ensuring that even if malware succeeds in the virtual environment, it cannot breach into the user's actual system.
3Object-affected harmful factors
If a secure virtual machine is generated and used to process content, then malware protection is achieved, but system complexity increases
Solution Approach 1:
The patent employs disposable virtual machine instances that are created, used, and then discarded after processing content. These short-living virtual environments provide malware protection for the duration of content processing, then are destroyed to prevent any persistence of malware. This approach achieves effective malware protection while managing system complexity by using temporary, self-contained units rather than permanent complex security infrastructure.
Solution Approach 2:
The patent changes the state of the virtual machine from a static, permanent system to a dynamic, transient one that is instantiated on-demand and destroyed after use. By parameterizing the virtual machine's lifecycle (creating it only when needed, destroying it after use), the patent achieves malware protection while minimizing the impact on system complexity - the virtual machine appears complex when active but disappears completely after use, leaving no residual complexity in the host system.
Data Source
AI summary
Protection from malware download is provided. A first input is received to access one of an email attachment or a web site link using an application. A newly generated secure virtual machine is obtained from one of a network server or a cloud computing service. The one of the email attachment or the web site link is sent to the newly generated secure virtual machine for processing.


