Segment Mapper Prevents Attacker Pivoting in Virtualized Systems
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cybersecurity measures for business processes in computing systems are inadequate as they allow attackers to pivot between systems, exploiting vulnerabilities and accessing higher criticality systems, despite application and network segmentation efforts.
Innovation Solution
Implementing a computing system architecture that uses virtual machine hypervisor technology for application segmentation and network segmentation, with an authentication/authorization service to map and control interactions between application and network segments, ensuring only authorized communication between specific segments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If application segmentation and network segmentation are implemented, then security isolation between systems is improved, but attackers can still exploit business process pathways to pivot between segmented systems
Solution Approach 1:
The patent introduces a segment mapper as an intermediary component that sits between application segments and network segments. This mediator enforces strict mapping rules that prevent attackers from exploiting business process pathways to pivot between segmented systems, while still allowing legitimate communication through properly mapped segments.
Solution Approach 2:
The patent implements fine-grained segmentation by dividing the system into application segments and network segments with explicit mapping relationships. This multi-layered segmentation approach creates additional barriers that prevent attacker pivoting, as each segment must have explicit authorization to communicate with specific network segments.
2Object-affected harmful factors
If operational systems are completely disconnected from other systems, then security against malicious interactions is improved, but business process efficiency deteriorates
Solution Approach 1:
The patent implements dynamic segmentation and mapping where application segments can be dynamically connected to appropriate network segments based on business process requirements. This allows operational systems to remain connected for efficiency while the segment mapper dynamically enforces security boundaries to prevent malicious interactions.
3Adaptability or versatility
If network communication is allowed across application segments, then business process functionality is improved, but security control is weakened
Solution Approach 1:
The patent applies local quality by allowing network communication across application segments only at specific authorized points defined by the segment mapper. Each application segment has customized communication permissions mapped to specific network segments, providing both business process connectivity and granular security control.
Data Source
AI summary
Computing system operational methods and apparatus are described. According to one aspect, a computing system operational method includes accessing user information regarding a user logging onto a computing device of the computing system, processing the user information to determine if the user information is authentic, as a result of the processing determining that the user information is authentic, first enabling the computing device to execute an application segment, and as a result of the processing determining that the user information is authentic, second enabling the application segment to communicate data externally of the computing device via one of a plurality of network segments of the computing system.


