Virtual Container Isolation for Suspicious Code Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional security systems often fail to prevent harmful code from spreading to other systems within an organization, requiring costly and time-consuming measures that hinder operations.

Innovation Solution

A security system utilizing virtual containers for analysts to isolate and analyze suspicious information, providing physical and logical separation from other systems, and using non-native applications to review information in a different format, thereby preventing the spread of harmful code.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security systems are used to identify harmful code, then security analysis can be performed, but harmful code may spread to other systems in the organization

Engineering Contradiction:
Improvesecurity analysis reliabilityVSAvoidharmful code spread
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system divides the computing environment into isolated virtual containers, each capable of running suspicious code independently. This segmentation prevents harmful code from spreading to other systems while maintaining the ability to perform security analysis. Each container acts as a separate execution environment with controlled access to resources.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a sandboxed virtual container as an intermediary between the suspicious code and the host system. This intermediary layer allows security analysts to observe and analyze harmful code behavior without direct exposure to the main system, effectively mediating the interaction between potentially malicious code and the organization's infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If expensive and restrictive security measures are implemented to prevent harmful code spread, then security may be improved, but organization operations are hampered

Engineering Contradiction:
Improvesecurity protectionVSAvoidorganization operations
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

By segmenting the execution environment into virtual containers, the system provides strong security isolation without requiring expensive physical air-gapping or complete system shutdowns. Analysts can safely execute and analyze suspicious code in isolated containers while the rest of the organization's systems continue to operate normally, maintaining productivity while ensuring security.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system changes the operational parameters of security analysis by allowing dynamic creation and destruction of virtual containers. This enables on-demand isolation environments that can be quickly provisioned for analysis and then discarded, replacing static, restrictive security measures with flexible, parameter-driven isolation that maintains both security and operational efficiency.

Inventive Principle:
Principle #35Parameter changes

3Object-affected harmful factors

If virtual containers are used to isolate suspicious information, then harmful code spread is prevented, but system complexity increases

Engineering Contradiction:
Improveharmful code containmentVSAvoidisolation system structure
Core Design Contradiction:
Object-affected harmful factorsVSDevice complexity

Solution Approach 1:

The virtual container infrastructure provides multiple functions within a single system architecture: isolation of malicious code, controlled execution environment, resource management, and secure analysis platform. This multi-functionality reduces the need for separate specialized systems for each security function, thereby managing complexity while achieving comprehensive harmful code containment.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11797669B2System for isolated access and analysis of suspicious code in a computing environment
Publication Date: 2023.10.24 BANK OF AMERICA CORP
  • US11797669B2 patent drawing
  • US11797669B2 patent drawing
  • US11797669B2 patent drawing

AI summary

Providing an isolation system that allows analysts to analyze suspicious information in way that aids in preventing any harmful information from spreading to other applications and systems on a network. The isolation systems are physically and/or logically separated from other systems on the network. A plurality of virtual containers, which may be disposable and specific to each analyst, may be utilized to analyze the suspicious information within the isolation systems. Should a virtual container be infected with harmful information it may be discarded a new virtual container may be used to review the suspicious information. A non-native application may be used to transform the format of the suspicious information into a non-native format in order to aid preventing the harmful information from infecting the other systems on the network.