Virtual Guest Isolation for Internet Security Threats
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current security systems fail to effectively protect computer systems and local networks from malware infections, particularly when accessing the Internet, leading to potential data loss, system inefficiencies, and remote control vulnerabilities.
Innovation Solution
A system is implemented where a host computer runs a virtual guest system with a firewall, isolating it from direct Internet access except to trusted sites, using a hypervisor to create a separate virtual machine environment for Internet browsing, and employing a virtual private network (VPN) for secure Internet access, limiting interactions to prevent malware infections from spreading to the host system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of operation
If a computer system accesses the Internet directly, then Internet browsing functionality is improved, but the system becomes vulnerable to malware infections and security threats
Solution Approach 1:
The system is divided into two separate virtual machine environments: an Internet-facing VM that handles all Internet browsing and communication, and a protected host system that runs critical applications. The Internet VM is segmented from the host through virtualization boundaries, firewalls, and restricted network permissions, allowing Internet access functionality while containing security risks within the isolated VM environment.
2Reliability
If a virtual machine environment is used to isolate Internet access, then system security is improved, but device complexity increases
Solution Approach 1:
The host system runs a universal operating system that can execute both protected applications and manage the virtualized Internet VM environment. The virtualization platform provides multi-functional capabilities including VM management, network routing, security policy enforcement, and resource allocation, consolidating these functions into a single system rather than requiring separate dedicated hardware for each function.
3Object-affected harmful factors
If direct Internet access is blocked from the host system, then malware infection risk is reduced, but legitimate data transfer capabilities are limited
Solution Approach 1:
A controlled communication interface acts as an intermediary between the Internet VM and the host system. This intermediary enables legitimate data transfers for essential operations (such as software updates, license verification, and cloud synchronization) while blocking malicious data flows. The intermediary monitors and filters communications, allowing only authorized data exchanges between the isolated Internet environment and the protected host.
Data Source
AI summary
A host computer supports a virtual guest system running thereon. The host system has a firewall that prevents it from communicating directly with the Internet, except with predetermined trusted sites. The virtual guest runs on a hypervisor, and the virtual guest comprises primarily a browser program that is allowed to contact the Internet freely via an Internet access connection that is completely separate from the host computer connection, such as a dedicated network termination point with its specific Internet IP address, or by tunneling through the host machine architecture to reach the Internet without exposing the host system. The virtual guest system is separated and completely isolated by an internal firewall from the host, and the guest cannot access any of the resources of the host computer, except that the guest can initiate cut, copy and paste operations that reach the host, and the guest can also request print of documents. The host can transfer files to and from a virtual data storage area accessible by the guest by manual operator action. No other transfer of data except these user initiated actions is permitted.

