Segregated Shadow Workloads for Threat Detection in Virtualized Environments
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In distributed computing environments, especially those using cloud services and spanning multiple geographic locations, threat detection and remediation are challenging due to the complexity of managing security across diverse hosting services and the difficulty in differentiating between authorized and unauthorized processes.
Innovation Solution
The implementation of a workload orchestration platform that manages logical networks with both regular workloads and shadow workloads, where shadow workloads are instantiated with known processes, allowing a security application to detect and manage threats without affecting the operational workloads, and an administrator application to manage regular workloads independently of shadow workloads.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security monitoring is implemented across distributed data centers using multiple hosting services, then threat detection capability is improved, but system complexity and difficulty of management worsen
Solution Approach 1:
A workload orchestration platform is introduced as an intermediary system that centralizes the management of shadow workloads across distributed data centers. This platform provides a unified interface for deploying, configuring, and monitoring shadow workloads, eliminating the need to manage security monitoring separately at each hosting service location and thereby reducing system complexity while maintaining improved threat detection capability
2Measurement precision
If shadow workloads are deployed to detect threats, then threat detection precision is improved, but resource consumption increases
Solution Approach 1:
Shadow workloads are deployed selectively at specific hosting service locations based on risk assessment and organizational requirements, rather than uniformly across all data centers. This localized deployment strategy maintains high threat detection precision where needed while minimizing unnecessary resource consumption at lower-risk locations
Solution Approach 2:
Shadow workloads are designed as lightweight virtual copies of legitimate workloads that consume minimal resources. They replicate only the essential characteristics needed for threat detection (such as network traffic patterns and system calls) without requiring full operational capacity, thereby reducing resource consumption while maintaining detection precision
3Reliability
If security applications are given permissions to manage shadow workloads, then security monitoring effectiveness is improved, but access control complexity worsens
Solution Approach 1:
Access control permissions are segmented into distinct roles: security applications receive permissions specifically for managing shadow workloads, while administrator applications receive permissions for managing legitimate workloads. This segmentation ensures that each application has only the minimum necessary permissions for its function, improving security monitoring effectiveness while organizing access control in a manageable way through role-based access control (RBAC)
Data Source
AI summary
The technology disclosed herein enables the detection and subsequent mitigation of threats in virtualized workload environments. In a particular embodiment, a method provides, in a workload orchestration platform, managing one or more first logical networks that include a plurality of first workloads and a plurality of shadow workloads. One or more initial processes of the shadow workloads, when instantiated, are known to a security application. The method further includes providing security permissions to the security application that enable the security application to manage the shadow workloads. Also, the method includes providing admin permissions to an administrator application that enable the administrator application to manage the first workloads irrespective of the shadow workloads.


