Selective Virtualization for VM Threat Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security appliances using virtual machines for threat detection face challenges in maintaining accurate software configurations, leading to undetected malicious attacks due to interference from multiple application versions and plugin associations, which complicates malware detection and increases costs and delays in product releases.
Innovation Solution
A system and method for selective virtualization of resources within a VM-based sandbox environment, utilizing virtualization logic in user mode and kernel mode to intercept and redirect requests, ensuring reliable associations between resources and processes, and obfuscating duplicated versions to enhance malware detection.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple versions of application software are installed within a VM for comprehensive threat detection, then the detection coverage is improved, but the software configuration accuracy deteriorates leading to undetected malicious attacks
Solution Approach 1:
The patent segments the virtualization environment by creating separate virtual file systems, registry hives, and plugin directories for each application version. This segmentation prevents version conflicts and maintains accurate software configurations while allowing multiple versions to coexist for comprehensive threat detection.
Solution Approach 2:
The patent introduces an intermediary layer (virtualization logic) that mediates between multiple application versions and the underlying system resources. This intermediary manages associations between applications and their respective components, ensuring configuration accuracy while enabling multi-version detection coverage.
2Reliability
If complete virtualization of system resources is implemented, then resource isolation is improved, but threat detection accuracy deteriorates due to interference from virtualization overhead
Solution Approach 1:
The patent applies local quality by selectively virtualizing only the specific resources needed for each threat detection scenario rather than implementing complete virtualization. This approach maintains necessary resource isolation while minimizing virtualization overhead that could interfere with threat detection accuracy.
Solution Approach 2:
The patent implements partial virtualization by virtualizing only the necessary components (file systems, registry, plugins) for each application version rather than the entire system. This partial action provides sufficient isolation for reliable detection while reducing overhead that could compromise detection precision.
3Manufacturing precision
If labor intensive reviews are conducted to ensure VM maintains intended software configuration, then configuration accuracy is improved, but productivity deteriorates due to costs and delays
Solution Approach 1:
The patent implements self-service through automated virtualization logic that automatically maintains accurate software configurations for multiple application versions. The system self-manages associations between applications and their components without requiring labor-intensive manual reviews, thereby maintaining configuration accuracy while improving productivity.
Solution Approach 2:
The patent performs preliminary action by pre-configuring virtualized environments with accurate software configurations before threat detection begins. The virtualization logic is set up in advance to automatically maintain proper associations, eliminating the need for post-installation manual verification and accelerating product release timelines.
Data Source
AI summary
Selective virtualization of resources is provided, where the resources may be intercepted and services or the resources may be intercepted and redirected. Virtualization logic monitors for one or more activities that are performed in connection with one or more resources and conducted during processing of an object within the virtual machine. The first virtualization logic further selectively virtualizes resources associated with the one or more activities that are initiated during the processing of the object within the virtual machine by at least redirecting a first request of a plurality of requests to a different resource than requesting by a monitored activity of the one or more activities.


