Virtual Container Isolation for Suspicious Code Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional security systems often fail to prevent harmful code from spreading to other systems within an organization, requiring costly and time-consuming measures that hinder operations.

Innovation Solution

A security system utilizing virtual containers and non-native applications to analyze suspicious information in isolation, providing physical and logical separation, and using APIs to prevent the transfer of harmful information, allowing analysts to identify and mitigate threats without compromising other systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security systems are used to identify harmful code, then security analysis can be performed, but harmful code may spread to other systems in the organization

Engineering Contradiction:
Improvesecurity analysis reliabilityVSAvoidharmful code spread
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system divides the computing environment into multiple isolated virtual containers. Each container is segmented from others and from the host system, allowing security analysis to be performed in isolation. When suspicious code is detected, it is contained within its specific container and cannot spread to other containers or the host system, thus resolving the contradiction between performing security analysis and preventing harmful code spread.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces virtual containers as intermediary layers between the suspicious code and the host system. These containers act as mediators that allow analysts to interact with and analyze suspicious code while preventing direct access to the host system. The containerization technology serves as an intermediary barrier that enables security analysis without risking harmful code spread.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If expensive and restrictive security measures are implemented to prevent harmful code spread, then security can be improved, but organization operations are hampered

Engineering Contradiction:
Improvesecurity protectionVSAvoidorganization operations
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The virtual containerization system provides multiple functions within a single infrastructure: it isolates suspicious code, enables security analysis, prevents harmful code spread, and maintains system operations simultaneously. This multi-functional approach replaces the need for multiple separate security measures that would otherwise hamper operations, thus improving security protection without negatively impacting organization productivity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system changes the operational parameters of suspicious code by running it in a virtualized environment with modified system calls and restricted access permissions. This parameter change allows the code to execute in a controlled manner for analysis purposes while preventing it from performing harmful actions on the host system, thereby maintaining both security and operational efficiency.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11880461B2Application interface based system for isolated access and analysis of suspicious code in a computing environment
Publication Date: 2024.01.23 BANK OF AMERICA CORP
  • US11880461B2 patent drawing
  • US11880461B2 patent drawing
  • US11880461B2 patent drawing

AI summary

Providing an isolation system that allows analysts to analyze suspicious information in way that aids in preventing harmful information from spreading to other applications and systems on a network. A plurality of virtual containers may be used by analysts to analyze the suspicious information. The analyst may utilize a non-native application to analyze the suspicious information within the virtual container. The non-native application may be used to analyze the suspicious information in an analysis format instead of an original format for which the suspicious information, and any harmful information therein, were intended to be accessed. Additionally, the virtual containers may be accessed through the use of an API that allows an analyst to analyze the suspicious information in the virtual container without transferring information from the virtual container back to the analyst user computer system.