Virtual Security Isolation via Dynamic ACL Reconfiguration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current virtual security isolation technologies fail to prevent the spread of security risks within a virtual LAN, as virtual machines can still attack each other even when isolated, allowing compromised machines to scan and infect others within the same network.
Innovation Solution
A method and system for virtual security isolation that monitors security status information of virtual machines, determines abnormalities, generates security risk information, processes it using a preset treatment method to create ACL setting information, and sends isolation commands to access control lists to reconfigure and isolate compromised machines, preventing further communication and risk propagation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If virtual machines are isolated using traditional VLAN division, then security isolation between different VLANs is achieved, but security isolation among virtual machines within the same VLAN cannot be achieved
Solution Approach 1:
The patent segments the virtual network into multiple isolation domains by introducing virtual private networks (VPNs) within VLANs. Each virtual machine can be assigned to different VPN segments, enabling fine-grained isolation at the virtual machine level rather than only at the VLAN level. This allows security isolation among virtual machines within the same VLAN while maintaining the existing VLAN structure.
Solution Approach 2:
The patent adds a new dimension of isolation by introducing VPN segmentation within the existing VLAN structure. Instead of only isolating at the VLAN level (one dimension), the solution creates a multi-dimensional isolation architecture where virtual machines can be isolated both by VLAN and by VPN segment, enabling finer-grained security control without disrupting the existing network hierarchy.
2Reliability
If access control lists are configured on network isolation components, then security isolation between VLANs is achieved, but prevention of security risk proliferation within VLAN is not achieved
Solution Approach 1:
The patent introduces virtual network components (virtual switches, virtual routers, and VPN gateways) as intermediaries between virtual machines within the same VLAN. These intermediary components enforce security policies and control communication flows at the virtual machine level, preventing direct communication that would allow security risks to proliferate, while maintaining the simplicity of the underlying physical network infrastructure.
Solution Approach 2:
The patent enables the virtualization platform to automatically manage security isolation through software-defined networking (SDN) controllers and virtual network functions. The isolation mechanisms are self-configured and self-managed within the virtualized environment, eliminating the need for complex manual configuration of physical network devices while providing fine-grained security control at the virtual machine level.
3Ease of operation
If virtual machines with different security levels are allowed to visit each other, then network accessibility is maintained, but security risks of mutual attacks cannot be eliminated
Solution Approach 1:
The patent applies different security isolation qualities to different virtual machines based on their security levels and trust requirements. Virtual machines with higher security requirements can be placed in more restricted VPN segments with tighter access controls, while less sensitive virtual machines can have broader access. This local quality approach allows network accessibility where needed while eliminating security risks in sensitive areas through differentiated isolation policies.
Data Source
AI summary
A virtual security isolation method includes monitoring security status information of a plurality of virtual machines in a virtual LAN; determining whether the security status information has abnormity; and generating security risk information corresponding to the virtual machine when it is determined that the security status information of a virtual machine has abnormity. The method also includes processing the security risk information according to a preset security risk treatment method having a corresponding relationship with the security risk information, generating ACL setting information for isolating the virtual machine; and sending an isolation command carrying the ACL setting information to an access control list module corresponding to the virtual LAN. The access control list module executes the isolation command and reconfigures the access control list according to the ACL setting information.


