Segment Mapper Prevents Attacker Pivoting in Virtualized Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity measures for business processes in computing systems are inadequate as they allow attackers to pivot between systems, exploiting vulnerabilities and accessing higher criticality systems, despite application and network segmentation efforts.

Innovation Solution

Implementing a computing system architecture that uses virtual machine hypervisor technology for application segmentation and network segmentation, with an authentication/authorization service to map and control interactions between application and network segments, ensuring only authorized communication between specific segments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If application segmentation and network segmentation are implemented, then security isolation between systems is improved, but attackers can still exploit business process pathways to pivot between segmented systems

Engineering Contradiction:
Improvesecurity isolationVSAvoidattacker pivoting capability
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a segment mapper as an intermediary component that sits between application segments and network segments. This mediator enforces strict mapping rules that prevent attackers from exploiting business process pathways to pivot between segmented systems, while still allowing legitimate communication through properly mapped segments.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements fine-grained segmentation by dividing the system into application segments and network segments with explicit mapping relationships. This multi-layered segmentation approach creates additional barriers that prevent attacker pivoting, as each segment must have explicit authorization to communicate with specific network segments.

Inventive Principle:
Principle #1Segmentation

2Object-affected harmful factors

If operational systems are completely disconnected from other systems, then security against malicious interactions is improved, but business process efficiency deteriorates

Engineering Contradiction:
Improvemalicious interactionsVSAvoidbusiness process efficiency
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The patent implements dynamic segmentation and mapping where application segments can be dynamically connected to appropriate network segments based on business process requirements. This allows operational systems to remain connected for efficiency while the segment mapper dynamically enforces security boundaries to prevent malicious interactions.

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If network communication is allowed across application segments, then business process functionality is improved, but security control is weakened

Engineering Contradiction:
Improvebusiness process connectivityVSAvoidsecurity control
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent applies local quality by allowing network communication across application segments only at specific authorized points defined by the segment mapper. Each application segment has customized communication permissions mapped to specific network segments, providing both business process connectivity and granular security control.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11985113B2Computing system operational methods and apparatus
Publication Date: 2024.05.14 BATTELLE MEMORIAL INST
  • US11985113B2 patent drawing
  • US11985113B2 patent drawing
  • US11985113B2 patent drawing

AI summary

Computing system operational methods and apparatus are described. According to one aspect, a computing system operational method includes accessing user information regarding a user logging onto a computing device of the computing system, processing the user information to determine if the user information is authentic, as a result of the processing determining that the user information is authentic, first enabling the computing device to execute an application segment, and as a result of the processing determining that the user information is authentic, second enabling the application segment to communicate data externally of the computing device via one of a plurality of network segments of the computing system.