Virtual Container Isolation for Suspicious Code Analysis
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional security systems often fail to prevent harmful code from spreading to other systems within an organization, requiring costly and time-consuming measures that hinder operations.
Innovation Solution
A security system utilizing virtual containers and non-native applications to analyze suspicious information in isolation, providing physical and logical separation, and using APIs to prevent the transfer of harmful information, allowing analysts to identify and mitigate threats without compromising other systems.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If traditional security systems are used to identify harmful code, then security analysis can be performed, but harmful code may spread to other systems in the organization
Solution Approach 1:
The system divides the computing environment into multiple isolated virtual containers. Each container is segmented from others and from the host system, allowing security analysis to be performed in isolation. When suspicious code is detected, it is contained within its specific container and cannot spread to other containers or the host system, thus resolving the contradiction between performing security analysis and preventing harmful code spread.
Solution Approach 2:
The system introduces virtual containers as intermediary layers between the suspicious code and the host system. These containers act as mediators that allow analysts to interact with and analyze suspicious code while preventing direct access to the host system. The containerization technology serves as an intermediary barrier that enables security analysis without risking harmful code spread.
2Reliability
If expensive and restrictive security measures are implemented to prevent harmful code spread, then security can be improved, but organization operations are hampered
Solution Approach 1:
The virtual containerization system provides multiple functions within a single infrastructure: it isolates suspicious code, enables security analysis, prevents harmful code spread, and maintains system operations simultaneously. This multi-functional approach replaces the need for multiple separate security measures that would otherwise hamper operations, thus improving security protection without negatively impacting organization productivity.
Solution Approach 2:
The system changes the operational parameters of suspicious code by running it in a virtualized environment with modified system calls and restricted access permissions. This parameter change allows the code to execute in a controlled manner for analysis purposes while preventing it from performing harmful actions on the host system, thereby maintaining both security and operational efficiency.
Data Source
AI summary
Providing an isolation system that allows analysts to analyze suspicious information in way that aids in preventing harmful information from spreading to other applications and systems on a network. A plurality of virtual containers may be used by analysts to analyze the suspicious information. The analyst may utilize a non-native application to analyze the suspicious information within the virtual container. The non-native application may be used to analyze the suspicious information in an analysis format instead of an original format for which the suspicious information, and any harmful information therein, were intended to be accessed. Additionally, the virtual containers may be accessed through the use of an API that allows an analyst to analyze the suspicious information in the virtual container without transferring information from the virtual container back to the analyst user computer system.


