Self-Replicating Application Control via Policy Mediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Self-replicating applications, such as anti-worms, are difficult to control and can be vulnerable to misuse, as existing techniques do not effectively manage their replication across diverse networking environments, leading to potential malicious behavior.

Innovation Solution

Implementing rules-based self-replication controls, where self-replicating applications check for presence on white and black lists, and require user approval, to limit replication to specific conditions, such as private address spaces and user authorization, ensuring secure and controlled propagation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If self-replicating applications are allowed to spread freely across endpoints, then their ability to perform benevolent operations (such as installing patches and detecting threats) is improved, but they become vulnerable to misuse and malicious subversion

Engineering Contradiction:
Improveability to perform operationsVSAvoidsecurity against misuse
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent introduces a control service as an intermediary between the self-replicating application and the endpoints. This control service receives replication requests, evaluates them against predefined policies, and authorizes or denies replication actions. This mediator structure enables the application to spread effectively while preventing misuse through centralized policy enforcement.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent implements dynamic control mechanisms where replication permissions are not static but adapt based on policy evaluations. The control service can dynamically adjust authorization decisions based on the current state, policy rules, and environmental factors, allowing flexible management of replication behavior to balance productivity and security.

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If the payload of an anti-worm is modified to enhance functionality, then its operational capability is improved, but it may be co-opted for malicious purposes

Engineering Contradiction:
Improveoperational capabilityVSAvoidmalicious behavior risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements feedback mechanisms where the control service continuously monitors and evaluates replication requests against policies. This feedback loop ensures that even if payload modifications occur, the system can detect and prevent malicious behavior by evaluating each replication action against security policies, maintaining adaptability while preventing harm.

Inventive Principle:
Principle #23Feedback

3Reliability

If manual review of all anti-worm actions is implemented, then security control is improved, but the service does not scale well

Engineering Contradiction:
Improvesecurity controlVSAvoidscalability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements self-service mechanisms where the control service automatically evaluates replication requests against predefined policies without requiring manual human review for each action. The system serves itself by autonomously making authorization decisions based on policy rules, maintaining security control while achieving scalability through automation.

Inventive Principle:
Principle #25Self-service

4Reliability

If exact actions of individual anti-worms are prescribed, then security control is improved, but the service becomes unlikely to be useful to customers with different requirements

Engineering Contradiction:
Improvesecurity controlVSAvoidcustomization for different customers
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the control mechanism into modular policy rules that can be independently configured and evaluated. Each replication request is evaluated against specific policy segments rather than a monolithic control structure. This segmentation allows different customers to have customized policy sets that reflect their specific requirements while maintaining security control through the structured policy evaluation framework.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11693695B1Application self-replication control
Publication Date: 2023.07.04 VMWARE INC
  • US11693695B1 patent drawing
  • US11693695B1 patent drawing
  • US11693695B1 patent drawing

AI summary

The disclosure provides an approach for controlling application self-replication in a network. Embodiments include determining, by a self-replicating application, one or more parameters related to a networking environment. Embodiments include applying, by the self-replicating application, one or more rules to the one or more parameters related to the networking environment. Embodiments include determining, by the self-replicating application, whether to replicate within the networking environment based on the applying of the one or more rules to the one or more parameters related to the networking environment.