Virtual Guest Isolation for Internet Security Threats

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security systems fail to effectively protect computer systems and local networks from malware infections, particularly when accessing the Internet, leading to potential data loss, system inefficiencies, and remote control vulnerabilities.

Innovation Solution

A system is implemented where a host computer runs a virtual guest system with a firewall, isolating it from direct Internet access except to trusted sites, using a hypervisor to create a separate virtual machine environment for Internet browsing, and employing a virtual private network (VPN) for secure Internet access, limiting interactions to prevent malware infections from spreading to the host system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of operation

If a computer system accesses the Internet directly, then Internet browsing functionality is improved, but the system becomes vulnerable to malware infections and security threats

Engineering Contradiction:
ImproveInternet browsing functionalityVSAvoidsystem security
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system is divided into two separate virtual machine environments: an Internet-facing VM that handles all Internet browsing and communication, and a protected host system that runs critical applications. The Internet VM is segmented from the host through virtualization boundaries, firewalls, and restricted network permissions, allowing Internet access functionality while containing security risks within the isolated VM environment.

Inventive Principle:
Principle #1Segmentation

2Reliability

If a virtual machine environment is used to isolate Internet access, then system security is improved, but device complexity increases

Engineering Contradiction:
Improvesystem securityVSAvoidvirtualization infrastructure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The host system runs a universal operating system that can execute both protected applications and manage the virtualized Internet VM environment. The virtualization platform provides multi-functional capabilities including VM management, network routing, security policy enforcement, and resource allocation, consolidating these functions into a single system rather than requiring separate dedicated hardware for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Object-affected harmful factors

If direct Internet access is blocked from the host system, then malware infection risk is reduced, but legitimate data transfer capabilities are limited

Engineering Contradiction:
Improvemalware infection riskVSAvoiddata transfer capability
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

A controlled communication interface acts as an intermediary between the Internet VM and the host system. This intermediary enables legitimate data transfers for essential operations (such as software updates, license verification, and cloud synchronization) while blocking malicious data flows. The intermediary monitors and filters communications, allowing only authorized data exchanges between the isolated Internet environment and the protected host.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10601780B2Internet isolation for avoiding internet security threats
Publication Date: 2020.03.24 L3 TECHNOLOGIES INC
  • US10601780B2 patent drawing
  • US10601780B2 patent drawing

AI summary

A host computer supports a virtual guest system running thereon. The host system has a firewall that prevents it from communicating directly with the Internet, except with predetermined trusted sites. The virtual guest runs on a hypervisor, and the virtual guest comprises primarily a browser program that is allowed to contact the Internet freely via an Internet access connection that is completely separate from the host computer connection, such as a dedicated network termination point with its specific Internet IP address, or by tunneling through the host machine architecture to reach the Internet without exposing the host system. The virtual guest system is separated and completely isolated by an internal firewall from the host, and the guest cannot access any of the resources of the host computer, except that the guest can initiate cut, copy and paste operations that reach the host, and the guest can also request print of documents. The host can transfer files to and from a virtual data storage area accessible by the guest by manual operator action. No other transfer of data except these user initiated actions is permitted.