Segregated Shadow Workloads for Threat Detection in Virtualized Environments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In distributed computing environments, especially those using cloud services and spanning multiple geographic locations, threat detection and remediation are challenging due to the complexity of managing security across diverse hosting services and the difficulty in differentiating between authorized and unauthorized processes.

Innovation Solution

The implementation of a workload orchestration platform that manages logical networks with both regular workloads and shadow workloads, where shadow workloads are instantiated with known processes, allowing a security application to detect and manage threats without affecting the operational workloads, and an administrator application to manage regular workloads independently of shadow workloads.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security monitoring is implemented across distributed data centers using multiple hosting services, then threat detection capability is improved, but system complexity and difficulty of management worsen

Engineering Contradiction:
Improvethreat detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

A workload orchestration platform is introduced as an intermediary system that centralizes the management of shadow workloads across distributed data centers. This platform provides a unified interface for deploying, configuring, and monitoring shadow workloads, eliminating the need to manage security monitoring separately at each hosting service location and thereby reducing system complexity while maintaining improved threat detection capability

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If shadow workloads are deployed to detect threats, then threat detection precision is improved, but resource consumption increases

Engineering Contradiction:
Improvethreat detection precisionVSAvoidresource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

Shadow workloads are deployed selectively at specific hosting service locations based on risk assessment and organizational requirements, rather than uniformly across all data centers. This localized deployment strategy maintains high threat detection precision where needed while minimizing unnecessary resource consumption at lower-risk locations

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

Shadow workloads are designed as lightweight virtual copies of legitimate workloads that consume minimal resources. They replicate only the essential characteristics needed for threat detection (such as network traffic patterns and system calls) without requiring full operational capacity, thereby reducing resource consumption while maintaining detection precision

Inventive Principle:
Principle #26Copying

3Reliability

If security applications are given permissions to manage shadow workloads, then security monitoring effectiveness is improved, but access control complexity worsens

Engineering Contradiction:
Improvesecurity monitoring effectivenessVSAvoidaccess control complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Access control permissions are segmented into distinct roles: security applications receive permissions specifically for managing shadow workloads, while administrator applications receive permissions for managing legitimate workloads. This segmentation ensures that each application has only the minimum necessary permissions for its function, improving security monitoring effectiveness while organizing access control in a manageable way through role-based access control (RBAC)

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS11595414B2Threat mitigation in a virtualized workload environment using segregated shadow workloads
Publication Date: 2023.02.28 VMWARE INC
  • US11595414B2 patent drawing
  • US11595414B2 patent drawing
  • US11595414B2 patent drawing

AI summary

The technology disclosed herein enables the detection and subsequent mitigation of threats in virtualized workload environments. In a particular embodiment, a method provides, in a workload orchestration platform, managing one or more first logical networks that include a plurality of first workloads and a plurality of shadow workloads. One or more initial processes of the shadow workloads, when instantiated, are known to a security application. The method further includes providing security permissions to the security application that enable the security application to manage the shadow workloads. Also, the method includes providing admin permissions to an administrator application that enable the administrator application to manage the first workloads irrespective of the shadow workloads.