Virtualization Security Inside-Outside Process for Connectivity Loss

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Securing client machines in a virtualized environment, especially in high availability mode, is challenging due to transitory disconnections that expose them to threats, necessitating improved protection methods.

Innovation Solution

A multi-part distributed vendor-neutral virtualization security system is implemented, featuring an inside/outside approach where the inside process provides real-time protection if communication with the outside process is lost, ensuring continuous security even when connectivity is disrupted.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If the client machine relies on external security processes for protection, then centralized security management is improved, but security protection is lost when connectivity is interrupted

Engineering Contradiction:
Improvecentralized security managementVSAvoidsecurity protection continuity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The security system is divided into two independent parts: an external security process for centralized management and an internal security process for local protection. This segmentation allows the system to maintain centralized security management capabilities while ensuring continuous protection through the internal process that operates independently when connectivity is lost.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The internal security process is pre-configured with security policies and protection mechanisms before connectivity is lost. This preliminary action ensures that when the external process becomes unavailable, the internal process can immediately take over and provide continuous security protection without interruption.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If the inside security process remains dormant to conserve resources, then system performance is improved, but real-time protection capability is reduced

Engineering Contradiction:
Improvesystem performanceVSAvoidreal-time protection capability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The internal security process dynamically adjusts its operational state based on connectivity status. When connected to the external process, it remains dormant to conserve resources and maintain system performance. When connectivity is lost, it activates to provide real-time protection, thus adapting its behavior to balance performance and reliability requirements.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The internal security process is designed to autonomously activate and provide protection when the external process is unavailable. This self-service capability ensures that the system can maintain security protection without requiring constant external intervention, balancing resource consumption with protection capability.

Inventive Principle:
Principle #25Self-service

3Reliability

If the system switches to internal security process when external connectivity is lost, then security protection continuity is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity protection continuityVSAvoidsecurity system architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The security system is divided into two independent parts: an external security process for centralized management and an internal security process for local protection. This segmentation allows the system to maintain centralized security management capabilities while ensuring continuous protection through the internal process that operates independently when connectivity is lost.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The internal security process is designed to serve multiple functions: it acts as a backup when the external process is available, takes over when connectivity is lost, and can operate autonomously. This multi-functionality reduces the need for separate dedicated backup systems, thereby managing complexity while ensuring protection continuity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS8732791B2Multi-part internal-external process system for providing virtualization security protection
Publication Date: 2014.05.20 SOPHOS LTD
  • US8732791B2 patent drawing
  • US8732791B2 patent drawing
  • US8732791B2 patent drawing

AI summary

In embodiments of the present invention improved capabilities are described for a host machine that manages a plurality of virtual machines associated with an enterprise through a supervisory process, the host machine including a threat management facility coupled in a communicating relationship with the plurality of virtual machines and enforcing a security policy of the enterprise for the plurality of virtual machines; and a first virtual machine from among the plurality of virtual machines, the first virtual machine capable of operating in a first state on the host machine wherein the security policy is enforced by the threat management facility, and the first virtual machine capable of operating in a second state wherein a local security facility executable on the first virtual machine autonomously enforces the security policy in the absence of the threat management facility.