Virtual Security Isolation via Dynamic ACL Reconfiguration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current virtual security isolation technologies fail to prevent the spread of security risks within a virtual LAN, as virtual machines can still attack each other even when isolated, allowing compromised machines to scan and infect others within the same network.

Innovation Solution

A method and system for virtual security isolation that monitors security status information of virtual machines, determines abnormalities, generates security risk information, processes it using a preset treatment method to create ACL setting information, and sends isolation commands to access control lists to reconfigure and isolate compromised machines, preventing further communication and risk propagation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If virtual machines are isolated using traditional VLAN division, then security isolation between different VLANs is achieved, but security isolation among virtual machines within the same VLAN cannot be achieved

Engineering Contradiction:
Improvesecurity isolationVSAvoidisolation granularity
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the virtual network into multiple isolation domains by introducing virtual private networks (VPNs) within VLANs. Each virtual machine can be assigned to different VPN segments, enabling fine-grained isolation at the virtual machine level rather than only at the VLAN level. This allows security isolation among virtual machines within the same VLAN while maintaining the existing VLAN structure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent adds a new dimension of isolation by introducing VPN segmentation within the existing VLAN structure. Instead of only isolating at the VLAN level (one dimension), the solution creates a multi-dimensional isolation architecture where virtual machines can be isolated both by VLAN and by VPN segment, enabling finer-grained security control without disrupting the existing network hierarchy.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If access control lists are configured on network isolation components, then security isolation between VLANs is achieved, but prevention of security risk proliferation within VLAN is not achieved

Engineering Contradiction:
Improvesecurity isolationVSAvoidisolation mechanism complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces virtual network components (virtual switches, virtual routers, and VPN gateways) as intermediaries between virtual machines within the same VLAN. These intermediary components enforce security policies and control communication flows at the virtual machine level, preventing direct communication that would allow security risks to proliferate, while maintaining the simplicity of the underlying physical network infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent enables the virtualization platform to automatically manage security isolation through software-defined networking (SDN) controllers and virtual network functions. The isolation mechanisms are self-configured and self-managed within the virtualized environment, eliminating the need for complex manual configuration of physical network devices while providing fine-grained security control at the virtual machine level.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If virtual machines with different security levels are allowed to visit each other, then network accessibility is maintained, but security risks of mutual attacks cannot be eliminated

Engineering Contradiction:
Improvenetwork accessibilityVSAvoidsecurity attack risk
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The patent applies different security isolation qualities to different virtual machines based on their security levels and trust requirements. Virtual machines with higher security requirements can be placed in more restricted VPN segments with tighter access controls, while less sensitive virtual machines can have broader access. This local quality approach allows network accessibility where needed while eliminating security risks in sensitive areas through differentiated isolation policies.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10033745B2Method and system for virtual security isolation
Publication Date: 2018.07.24 SANGFOR TECH INC
  • US10033745B2 patent drawing
  • US10033745B2 patent drawing
  • US10033745B2 patent drawing

AI summary

A virtual security isolation method includes monitoring security status information of a plurality of virtual machines in a virtual LAN; determining whether the security status information has abnormity; and generating security risk information corresponding to the virtual machine when it is determined that the security status information of a virtual machine has abnormity. The method also includes processing the security risk information according to a preset security risk treatment method having a corresponding relationship with the security risk information, generating ACL setting information for isolating the virtual machine; and sending an isolation command carrying the ACL setting information to an access control list module corresponding to the virtual LAN. The access control list module executes the isolation command and reconfigures the access control list according to the ACL setting information.