Separation Kernel Hypervisor Isolation for Malicious Code Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing hypervisor systems face limitations in detecting and defending against malicious code, as they cannot prevent corruption of monitoring agents within the same guest operating system and allow malicious code to spread between guest operating systems, lacking effective isolation and proximity to malicious code.
Innovation Solution
A Separation Kernel Hypervisor is designed to provide secure, isolated mechanisms for monitoring and detecting malicious code by using Guest Operating System Virtual Machine Protection Domains and a Virtualization Assistance Layer, ensuring real-time notification and action on memory access, while maintaining isolation from malicious code.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a hypervisor allows guests to monitor the activities of another guest, then debugging and security monitoring capabilities are improved, but the hypervisor cannot prevent corruption of the monitoring agent by malicious code within the same guest operating system
Solution Approach 1:
The system divides the virtualized environment into distinct protection domains, separating the monitoring agent from the monitored guest operating system. The monitoring agent executes in a separate protection domain that is isolated from the guest OS, preventing malicious code within the guest from corrupting the monitoring agent while still allowing it to observe and monitor the guest's activities.
Solution Approach 2:
The patent introduces a protection domain mechanism as an intermediary layer between the monitoring agent and the guest operating system. This intermediary structure enables the monitoring agent to safely observe guest activities without direct exposure to malicious code, while still maintaining the ability to detect and report security issues.
2Measurement precision
If a hypervisor provides monitoring mechanisms within the same guest operating system, then close proximity to malicious code is achieved, but the monitoring agent is vulnerable to corruption and subversion by that same malicious code
Solution Approach 1:
The system segments the execution environment into separate protection domains, allowing the monitoring agent to maintain close proximity to malicious code for effective detection while simultaneously isolating it from corruption. The agent operates in a dedicated protection domain that provides both observational access and protective isolation.
Solution Approach 2:
The patent adds a new dimension to the monitoring architecture by introducing protection domains as a separate layer of abstraction. This dimensional addition allows the monitoring agent to achieve both close proximity to malicious code and immunity from its effects, resolving the fundamental trade-off between detection capability and agent integrity.
3Reliability
If a hypervisor allows guests to poll memory and information within another guest, then monitoring capability is improved, but malicious code can spread between guest operating systems
Solution Approach 1:
The system implements protection domains that segment the memory and information access between guests. The monitoring agent can observe and poll memory within the monitored guest's protection domain, but the isolated domain structure prevents malicious code from spreading to other guests, as each guest operates within its own protected boundary.
Solution Approach 2:
The protection domain mechanism acts as a flexible isolating shell between guest operating systems. It allows controlled interaction and monitoring while maintaining strict boundaries that prevent malicious code propagation, enabling security monitoring without compromising system isolation.
Data Source
AI summary
Systems, methods, computer readable media and articles of manufacture consistent with innovations herein are directed to computer virtualization, computer security and/or memory access. According to some illustrative implementations, innovations herein may utilize and/or involve a separation kernel hypervisor which may include the use of a guest operating system virtual machine protection domain, a virtualization assistance layer, and/or a detection mechanism (which may be proximate in temporal and/or spatial locality to malicious code, but isolated from it), inter alia, for detection and/or notification of, and action by a monitoring guest upon access by a monitored guest to predetermined physical memory locations.


