Trusted Threat-Aware Microvisor for Virtualization Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing virtualization systems are vulnerable to malicious code infiltration due to unforeseen security flaws, necessitating a malware-resistant system that can detect exploits and malware effectively.
Innovation Solution
A trusted threat-aware microvisor is deployed beneath the operating system kernel to control access to kernel resources, enforce security policies, and conduct run-time security analysis, including exploit and malware detection, through a lightweight module that operates as a micro-hypervisor, utilizing a chain of loading for secure deployment and enhanced verification to ensure trustedness.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If a hypervisor is used to create and manage virtual machines, then resource sharing and isolation are improved, but the system becomes vulnerable to malicious code infiltration through security flaws
Solution Approach 1:
The system is segmented into multiple virtual machines with isolated execution environments. Each VM is contained within its own protection domain, preventing malicious code in one VM from affecting the hypervisor or other VMs. This segmentation resolves the contradiction by maintaining resource sharing while enhancing security through isolation.
Solution Approach 2:
A trusted verification layer is introduced as an intermediary between the hypervisor and the virtual machines. This layer performs runtime verification of VM behavior and enforces security policies, acting as a mediator that allows resource sharing while blocking malicious code infiltration attempts.
2Reliability
If policy enforcement and containment analysis are implemented to isolate malicious code, then system security is improved, but the hypervisor itself remains vulnerable to unforeseen security flaws
Solution Approach 1:
Security policies and verification rules are established beforehand during system configuration. The verification layer is pre-configured with security policies that automatically enforce containment analysis, eliminating the need for complex runtime decision-making and reducing verification complexity while maintaining security.
Solution Approach 2:
The verification layer performs self-verification through automated monitoring and analysis of VM behavior against predefined security policies. This self-service approach reduces the need for external verification complexity while maintaining high security standards through continuous automated monitoring.
3Measurement precision
If a lightweight microvisor module is deployed for run-time security analysis, then detection capability is improved, but system complexity increases
Solution Approach 1:
The microvisor module merges security analysis functions with the existing virtualization infrastructure. By combining threat detection capabilities with the resource management functions already present in the hypervisor, the system achieves improved detection precision without proportionally increasing overall system complexity.
Solution Approach 2:
The microvisor module is designed with multi-functionality, serving both resource management and security analysis purposes. This universal design allows a single component to perform multiple functions, improving threat detection capability while minimizing the increase in system complexity through functional consolidation.
Data Source
AI summary
A trusted threat-aware microvisor may be deployed as a module of a trusted computing base (TCB). The microvisor is illustratively configured to enforce a security policy of the TCB, which may be implemented as a security property of the microvisor. The microvisor may manifest (i.e., demonstrate) the security property in a manner that enforces the security policy. Trustedness denotes a predetermined level of confidence that the security property is demonstrated by the microvisor. The predetermined level of confidence is based on an assurance (i.e., grounds) that the microvisor demonstrates the security property. Trustedness of the microvisor may be verified by subjecting the TCB to enhanced verification analysis configured to ensure that the TCB conforms to an operational model with an appropriate level of confidence over an appropriate range of activity. The operational model may then be configured to analyze conformance of the microvisor to the security property. A combination of conformance by the microvisor to the operational model and to the security property provides assurance (i.e., grounds) for the level of confidence and, thus, verifies trustedness.


