Multi-Partition Virtual Machine Quarantine for Malware Assessment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users face challenges in safely installing and managing applications on computing devices due to the risk of malware, as existing sandbox solutions often impose strict security parameters that may incorrectly label benign behaviors as unsafe, limiting the functionality of applications.
Innovation Solution
Implementing a system with multiple quarantine partitions or a multi-partition space within a computing device, where each partition is configured with user-specific rules and capabilities, allowing for the safe execution of downloaded content and enabling user-controlled approval of access to sensitive data and features, with periodic malware detection and monitoring.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If a single sandbox with strict security parameters is used to quarantine applications, then malware detection reliability is improved, but application functionality and user experience deteriorate due to false positives
Solution Approach 1:
The patent divides a single sandbox into multiple virtual machine partitions, each with different security parameter sets. This segmentation allows the system to maintain strict security for high-risk applications while providing relaxed parameters for trusted applications, thereby resolving the contradiction between reliable malware detection and preserving application functionality.
Solution Approach 2:
The system dynamically selects appropriate security parameter sets based on the specific application being quarantined and the user context. Rather than using fixed strict parameters for all applications, the security configuration adapts to each application's risk profile and the user's contextual needs, reducing false positives while maintaining reliability.
2Reliability
If strict security parameters are applied universally in a sandbox, then security reliability is improved, but the system loses adaptability to different user contexts and environments
Solution Approach 1:
Different virtual machine partitions are configured with different security parameter sets tailored to specific user contexts and environments. Each partition has localized security characteristics appropriate for its intended use case, allowing the system to maintain high security where needed while adapting to varying user contexts without compromising overall security reliability.
3Adaptability or versatility
If multiple virtual machine partitions with different security parameters are implemented, then adaptability to different user contexts is improved, but system complexity increases
Solution Approach 1:
The virtual machine partitioning system is designed to provide multiple functions within a unified framework. The same infrastructure supports different security parameter sets, user contexts, and application types, reducing the overall complexity that would result from implementing separate systems for each function.
4Adaptability or versatility
If applications are allowed to access sensitive data in a sandbox, then application functionality is improved, but the risk of malware exposure increases
Solution Approach 1:
The virtual machine partitions act as intermediary layers between applications and sensitive host system resources. By controlling what each partition can access and isolating applications within their respective partitions, the system enables application functionality while preventing malware from directly accessing sensitive data, thus reducing exposure risk.
Data Source
AI summary
Described are embodiments that provide for the use of multiple quarantine partitions and/or multi-partition spaces (e.g., virtual machines) for initially installing and running downloaded content. The downloaded content can be run securely in the quarantine partitions and/or multi-partition spaces. Each quarantine partition and/or multi-partition space can be configured differently with different capabilities. Based on the configuration and capabilities of the quarantine partitions and/or multi-partition spaces, the downloaded content may have limited capabilities to access secure data, applications, or other code limiting the damage that the content can potentially cause.


