Virtual Browsing Environment Isolation for Secure Web Access

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing browsing technologies lack effective isolation and detection mechanisms for malicious activities associated with browser applications, which can compromise the entire computer system.

Innovation Solution

A virtual browsing environment is created using a host operating system and a guest operating system, where the browser application is executed within a virtual computer, allowing for isolation and easy detection of malicious activities, with features like secure bookmarks and health monitoring.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If browser application is executed directly on the host operating system, then ease of operation is improved, but security and reliability deteriorate due to lack of isolation from malicious activities

Engineering Contradiction:
Improveease of operationVSAvoidsecurity
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system divides the computing environment into distinct segments: a host operating system and a guest operating system running in a virtual machine. The browser application executes within the guest OS, creating an isolated browsing environment that prevents malicious activities from affecting the host system, thus resolving the security concern while maintaining operational ease.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

A virtual machine acts as an intermediary layer between the browser application and the host operating system. This intermediary enables the browser to run with full functionality while preventing direct access to host system resources, thereby maintaining both ease of operation and security through controlled isolation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If virtual browsing environment is created with host and guest operating systems, then security and reliability are improved, but device complexity increases

Engineering Contradiction:
ImprovesecurityVSAvoiddevice complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The virtual machine infrastructure provides multiple functions simultaneously: it isolates the browsing environment for security, enables easy restoration through snapshots, and maintains full browser functionality. This multi-functionality justifies the added complexity by delivering comprehensive security and operational benefits in a single integrated system.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Difficulty of detecting and measuring

If browser application is isolated in virtual environment, then detection of malicious activities is improved, but ease of operation deteriorates due to additional configuration requirements

Engineering Contradiction:
Improvedetection capabilityVSAvoidease of operation
Core Design Contradiction:
Difficulty of detecting and measuringVSEase of operation

Solution Approach 1:

The system implements automatic health monitoring and snapshot management that operates without user intervention. The virtual machine automatically captures snapshots, monitors browser health, and can restore to clean states without requiring user configuration or manual detection of malicious activities, thus maintaining ease of operation while improving detection capability.

Inventive Principle:
Principle #25Self-service

4Productivity

If snapshots are taken frequently for quick restoration, then productivity is improved, but use of energy increases due to continuous snapshot operations

Engineering Contradiction:
ImproveproductivityVSAvoiduse of energy
Core Design Contradiction:
ProductivityVSUse of energy by moving object

Solution Approach 1:

The system takes snapshots at predetermined intervals and upon detection of malicious activities, rather than continuously. This preliminary action approach ensures that restoration points are readily available when needed (improving productivity) while avoiding the energy waste of continuous snapshot operations, as snapshots are created only when necessary for recovery or at scheduled times.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10120998B2Virtual browsing environment
Publication Date: 2018.11.06 GEORGE MASON UNIVERSITY
  • US10120998B2 patent drawing
  • US10120998B2 patent drawing
  • US10120998B2 patent drawing

AI summary

An embodiment for providing a secure virtual browsing environment includes creating a virtual browsing environment with a virtualized operating system sharing an operating system kernel of a supporting operating system and executing the browser application within the virtual browsing environment. Another embodiment includes receiving a website selection within a browser application, determining if the website selection corresponds to a secure bookmark, and creating a second virtual browsing environment and executing the browser application within the second virtual browsing environment to access the website selection when the website selection corresponds to a website specified as a secure bookmark. Yet another embodiment includes monitoring operation of the operating system within the at least one virtual browsing environment, determining when the operation of the operating system includes potential malicious activity, and terminating the virtual browsing environment when the operation includes potential malicious activity.