Virtualization Platform Intrusion Prevention Fast Slow Path
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing virtualization security systems face challenges in protecting virtualized environments from malware and intrusions, particularly due to limitations in appliance-based security solutions that are blind to inter-VM traffic, mobility issues, and performance bottlenecks, which require a more effective method for intrusion prevention and detection.
Innovation Solution
A distributed system and method for intrusion detection and prevention that deploys security agents within the virtualization platform, utilizing a security virtual machine to intercept and inspect packet streams, with a fast-path and slow-path processing mechanism to filter and verify traffic, ensuring protection closer to the asset and reducing latency and performance impacts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If appliance-based security systems are deployed in virtualized environments, then security coverage is provided, but the systems are blind to inter-VM traffic and cannot protect against intrusions between virtual machines
Solution Approach 1:
The patent segments the security function into two parts: a virtual appliance for external threat protection and a hypervisor-level module for internal traffic monitoring. This segmentation allows each component to specialize in specific security tasks, with the hypervisor module providing visibility into inter-VM traffic that appliance-based systems cannot detect
Solution Approach 2:
The patent introduces a hypervisor-level security module as an intermediary between the virtual appliances and the virtual machines. This intermediary captures and inspects traffic at the virtualization layer, providing comprehensive visibility into both external and internal traffic flows without requiring modification of the guest OS or appliances
2Reliability
If security inspection is performed on all packet streams, then comprehensive intrusion detection is achieved, but performance bottlenecks and latency increase
Solution Approach 1:
The patent applies partial inspection by examining only selected packets based on filtering criteria rather than inspecting every packet. The system uses fast-path processing for obvious threats and slow-path processing for suspicious traffic, achieving comprehensive security coverage while minimizing performance impact through selective inspection
Solution Approach 2:
The patent segments packet processing into fast-path and slow-path mechanisms. The fast path handles obvious threats with simple filtering rules for high-speed processing, while the slow path performs comprehensive deep packet inspection only on suspicious traffic, thereby maintaining both security completeness and system performance
3Productivity
If virtual machines are moved between physical servers for resource optimization, then resource utilization improves, but security context is lost and mobility challenges arise
Solution Approach 1:
The patent merges the security functionality into the hypervisor layer, which manages virtual machine lifecycle including migration. By embedding security agents at the hypervisor level rather than within individual VMs or physical servers, the security context travels with the VM during migration, maintaining continuous protection regardless of physical location
Solution Approach 2:
The patent creates a universal security architecture at the hypervisor level that serves multiple functions: protecting VMs during migration, monitoring inter-VM traffic across different physical hosts, and providing centralized security management. This universal approach eliminates security context loss during VM mobility
Data Source
AI summary
A distributed and coordinated security system providing intrusion-detection and intrusion-prevention for the virtual machines (VMs) in a virtual server is described. The virtualization platform of the virtual server is enhanced with networking drivers that provide a “fast path” firewall function for pre-configured guest VMs that already have dedicated deep packet inspection security agents installed. A separate security VM is deployed to provide virtual security agents providing deep packet inspection for non pre-configured guest VMs. The network drivers are then configured to intercept the data traffic of these guest VMs and route it through their corresponding virtual security agents, thus providing a “slow-path” for intrusion detection and prevention.


