Selective Virtualization for VM Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security appliances using virtual machines for threat detection face challenges in maintaining accurate software configurations, leading to undetected malicious attacks due to interference from multiple application versions and plugin associations, which complicates malware detection and increases costs and delays in product releases.

Innovation Solution

A system and method for selective virtualization of resources within a VM-based sandbox environment, utilizing virtualization logic in user mode and kernel mode to intercept and redirect requests, ensuring reliable associations between resources and processes, and obfuscating duplicated versions to enhance malware detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple versions of application software are installed within a VM for comprehensive threat detection, then the detection coverage is improved, but the software configuration accuracy deteriorates leading to undetected malicious attacks

Engineering Contradiction:
Improvedetection coverageVSAvoidsoftware configuration accuracy
Core Design Contradiction:
Adaptability or versatilityVSManufacturing precision

Solution Approach 1:

The patent segments the virtualization environment by creating separate virtual file systems, registry hives, and plugin directories for each application version. This segmentation prevents version conflicts and maintains accurate software configurations while allowing multiple versions to coexist for comprehensive threat detection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary layer (virtualization logic) that mediates between multiple application versions and the underlying system resources. This intermediary manages associations between applications and their respective components, ensuring configuration accuracy while enabling multi-version detection coverage.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If complete virtualization of system resources is implemented, then resource isolation is improved, but threat detection accuracy deteriorates due to interference from virtualization overhead

Engineering Contradiction:
Improveresource isolationVSAvoidthreat detection accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent applies local quality by selectively virtualizing only the specific resources needed for each threat detection scenario rather than implementing complete virtualization. This approach maintains necessary resource isolation while minimizing virtualization overhead that could interfere with threat detection accuracy.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent implements partial virtualization by virtualizing only the necessary components (file systems, registry, plugins) for each application version rather than the entire system. This partial action provides sufficient isolation for reliable detection while reducing overhead that could compromise detection precision.

Inventive Principle:
Principle #16Partial or excessive action

3Manufacturing precision

If labor intensive reviews are conducted to ensure VM maintains intended software configuration, then configuration accuracy is improved, but productivity deteriorates due to costs and delays

Engineering Contradiction:
Improveconfiguration accuracyVSAvoiddetection product release speed
Core Design Contradiction:
Manufacturing precisionVSProductivity

Solution Approach 1:

The patent implements self-service through automated virtualization logic that automatically maintains accurate software configurations for multiple application versions. The system self-manages associations between applications and their components without requiring labor-intensive manual reviews, thereby maintaining configuration accuracy while improving productivity.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent performs preliminary action by pre-configuring virtualized environments with accurate software configurations before threat detection begins. The virtualization logic is set up in advance to automatically maintain proper associations, eliminating the need for post-installation manual verification and accelerating product release timelines.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11868795B1Selective virtualization for security threat detection
Publication Date: 2024.01.09 MAGENTA SECURITY HOLDINGS LLC
  • US11868795B1 patent drawing
  • US11868795B1 patent drawing
  • US11868795B1 patent drawing

AI summary

Selective virtualization of resources is provided, where the resources may be intercepted and services or the resources may be intercepted and redirected. Virtualization logic monitors for one or more activities that are performed in connection with one or more resources and conducted during processing of an object within the virtual machine. The first virtualization logic further selectively virtualizes resources associated with the one or more activities that are initiated during the processing of the object within the virtual machine by at least redirecting a first request of a plurality of requests to a different resource than requesting by a monitored activity of the one or more activities.