Virtualization Layer Impedes Malicious Guest Software

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Computer systems are vulnerable to unauthorized access and malicious software, with existing protection methods often being compromised by the very threats they aim to mitigate, making it difficult to reliably interdict malicious code once an exploit gains privileged access.

Innovation Solution

Implementing a virtualization system that monitors and selectively impedes the progress of malicious software by altering virtual machine operations, modifying memory mappings, and introducing faults or interrupts, without relying on compromised guest operating systems, thereby providing a robust interdiction mechanism that operates independently of existing anti-malware systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing anti-malware systems are used to detect and terminate malicious code, then malicious software can be identified and mitigated, but the protection system becomes vulnerable to compromise by the very threats it aims to mitigate

Engineering Contradiction:
Improvereliability of malicious code interdictionVSAvoidvulnerability to compromise
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent introduces a virtualization layer as an intermediary between the guest operating system and the hardware. This virtualization system monitors execution contexts and can impede malicious software progress without relying on the guest OS, effectively mediating the trust relationship and eliminating the vulnerability where the protection system itself could be compromised by malicious code.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent adds a new dimension of protection by implementing virtualization at a system level above the guest operating system. Instead of relying on the guest OS's own security mechanisms, the virtualization layer provides a separate dimension of monitoring and control that remains independent of the guest system's compromise state.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Object-generated harmful factors

If the operating system is compromised by malicious code, then the system can execute malicious operations, but the ability to protect against the malicious code is lost

Engineering Contradiction:
Improveexecution of malicious operationsVSAvoidprotection capability
Core Design Contradiction:
Object-generated harmful factorsVSReliability

Solution Approach 1:

The virtualization system acts as an intermediary that monitors execution contexts from the guest operating system without requiring trust in the guest OS. Even when the guest OS is compromised, the virtualization layer maintains independent monitoring capability through hardware-supported virtualization mechanisms, allowing it to detect and impede malicious code execution.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments the system into distinct layers: the guest operating system (which may be compromised) and the virtualization system (which remains trusted). This segmentation isolates the protection function from the potentially compromised guest OS, ensuring that the ability to protect against malicious code is not lost even when the guest system executes harmful operations.

Inventive Principle:
Principle #1Segmentation

3Difficulty of detecting and measuring

If conventional anti-virus systems are used, then signature-based detection can identify known malware, but behavior-based detection and real-time interdiction remain difficult

Engineering Contradiction:
Improvedetection capabilityVSAvoidreal-time interdiction speed
Core Design Contradiction:
Difficulty of detecting and measuringVSProductivity

Solution Approach 1:

The patent replaces conventional software-based anti-virus detection mechanisms with hardware-supported virtualization mechanisms. The virtualization system uses hardware virtualization extensions to monitor execution contexts and impede malicious code progress directly at the hardware level, eliminating the need for slow software-based signature matching and enabling real-time interdiction.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The virtualization system is configured in advance to monitor execution contexts and is ready to impede malicious code progress as soon as it is detected. This preliminary setup eliminates the delay inherent in conventional anti-virus systems that must scan and analyze files, allowing immediate response to malicious behavior.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8763115B2Impeding progress of malicious guest software
Publication Date: 2014.06.24 VMWARE INC
  • US8763115B2 patent drawing
  • US8763115B2 patent drawing
  • US8763115B2 patent drawing

AI summary

One embodiment of the present invention is a method of operating a virtualization system, the method including: (a) instantiating a virtualization system on an underlying hardware machine, the virtualization system exposing a virtual machine in which multiple execution contexts of a guest execute; (b) monitoring the execution contexts from the virtualization system; and (c) selectively impeding computational progress of a particular one of the execution contexts.