Proactive Security Coordinator for Cloud VM Adaptation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In cloud computing environments, hosting applications with different security requirements raises security issues, as attackers can leverage lower security systems to access highly secured systems, and conventional centralized management systems are reactive and inflexible, leading to vulnerabilities when one virtual machine is breached, potentially compromising others in the same environment.

Innovation Solution

A security coordinator is introduced to autonomously detect security conditions in one managed machine and proactively initiate modifications, such as policy changes or relocation, in other machines within the same environment, independent of the environment manager, to maintain compliance with security policies and prevent attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a centralized environment manager is used to manage security in a cloud computing environment, then the system structure is simplified and management is centralized, but the response to security conditions is reactive and slow, allowing security breaches to spread before detection

Engineering Contradiction:
Improvesecurity response speedVSAvoidsystem architecture complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the centralized security management function into distributed security agents deployed on individual virtual machines. Each security agent operates independently to detect and respond to security conditions locally, eliminating the single point of control bottleneck. This segmentation enables parallel security monitoring across multiple VMs, significantly improving detection and response speed while maintaining manageable complexity through modular agent design.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Security agents are pre-deployed on virtual machines before security breaches occur. These agents continuously monitor security conditions and are ready to immediately detect and respond to threats. By having security capabilities in place beforehand rather than waiting for centralized detection, the system achieves proactive security monitoring and faster response times without requiring complex real-time centralized coordination.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If virtual machines with different security requirements are hosted in the same cloud environment, then resource utilization is improved, but security vulnerabilities can spread from lower security systems to highly secured systems

Engineering Contradiction:
Improveresource utilizationVSAvoidsecurity vulnerability spread
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements security agents with customized security policies tailored to each virtual machine's specific security requirements. Each agent enforces local security rules appropriate to that VM's classification (highly secured, standard, low security), allowing diverse security levels to coexist in the same environment. This localized security enforcement prevents vulnerability spread by containing threats within their respective security zones while maintaining high resource utilization through shared infrastructure.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

Security agents continuously monitor their respective virtual machines and communicate security status information. When a security condition or vulnerability is detected in one VM, the feedback mechanism alerts other security agents, enabling them to adjust their monitoring and enforcement accordingly. This feedback loop allows the system to dynamically respond to security threats while maintaining the ability to host multiple security levels in the same environment.

Inventive Principle:
Principle #23Feedback

3Adaptability or versatility

If security policies are enforced centrally by the environment manager, then policy consistency is maintained, but the system cannot proactively adapt to emerging security threats before they affect multiple machines

Engineering Contradiction:
Improveproactive security adaptationVSAvoidsecurity management simplicity
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

Security agents are pre-configured with security policies and monitoring capabilities before deployment. They automatically detect security conditions and enforce appropriate responses without requiring real-time centralized intervention. This preliminary setup enables proactive adaptation to security threats while maintaining operational simplicity through automated local enforcement rather than complex centralized coordination for each security event.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Each virtual machine's security agent autonomously monitors its own security status and enforces security policies without requiring continuous centralized management intervention. The agents self-manage security detection and response activities, adapting to threats independently. This self-service approach enables proactive security adaptation while simplifying overall management by reducing the operational burden on centralized systems.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9503475B2Self-adaptive and proactive virtual machine images adjustment to environmental security risks in a cloud environment
Publication Date: 2016.11.22 CA TECH INC
  • US9503475B2 patent drawing
  • US9503475B2 patent drawing
  • US9503475B2 patent drawing

AI summary

A computer system includes a security coordinator configured to be communicatively coupled to a plurality of managed machines deployed in a same computing environment and managed by an environment manager. The security coordinator is configured to detect a security condition with respect to a first one of the managed machines, and to automatically initiate modification of a second one of the managed machines in the same computing environment responsive to detection of the security condition. The security coordinator is configured to initiate the modification of the second one of the managed machines prior to occurrence of a security condition therein and prior to action by the environment manager with respect to the second one of the managed machines in response to the detected security condition.