Virtualization Security Inside-Outside Process for Connectivity Loss
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Securing client machines in a virtualized environment, especially in high availability mode, is challenging due to transitory disconnections that expose them to threats, necessitating improved protection methods.
Innovation Solution
A multi-part distributed vendor-neutral virtualization security system is implemented, featuring an inside/outside approach where the inside process provides real-time protection if communication with the outside process is lost, ensuring continuous security even when connectivity is disrupted.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If the client machine relies on external security processes for protection, then centralized security management is improved, but security protection is lost when connectivity is interrupted
Solution Approach 1:
The security system is divided into two independent parts: an external security process for centralized management and an internal security process for local protection. This segmentation allows the system to maintain centralized security management capabilities while ensuring continuous protection through the internal process that operates independently when connectivity is lost.
Solution Approach 2:
The internal security process is pre-configured with security policies and protection mechanisms before connectivity is lost. This preliminary action ensures that when the external process becomes unavailable, the internal process can immediately take over and provide continuous security protection without interruption.
2Productivity
If the inside security process remains dormant to conserve resources, then system performance is improved, but real-time protection capability is reduced
Solution Approach 1:
The internal security process dynamically adjusts its operational state based on connectivity status. When connected to the external process, it remains dormant to conserve resources and maintain system performance. When connectivity is lost, it activates to provide real-time protection, thus adapting its behavior to balance performance and reliability requirements.
Solution Approach 2:
The internal security process is designed to autonomously activate and provide protection when the external process is unavailable. This self-service capability ensures that the system can maintain security protection without requiring constant external intervention, balancing resource consumption with protection capability.
3Reliability
If the system switches to internal security process when external connectivity is lost, then security protection continuity is improved, but system complexity increases
Solution Approach 1:
The security system is divided into two independent parts: an external security process for centralized management and an internal security process for local protection. This segmentation allows the system to maintain centralized security management capabilities while ensuring continuous protection through the internal process that operates independently when connectivity is lost.
Solution Approach 2:
The internal security process is designed to serve multiple functions: it acts as a backup when the external process is available, takes over when connectivity is lost, and can operate autonomously. This multi-functionality reduces the need for separate dedicated backup systems, thereby managing complexity while ensuring protection continuity.
Data Source
AI summary
In embodiments of the present invention improved capabilities are described for a host machine that manages a plurality of virtual machines associated with an enterprise through a supervisory process, the host machine including a threat management facility coupled in a communicating relationship with the plurality of virtual machines and enforcing a security policy of the enterprise for the plurality of virtual machines; and a first virtual machine from among the plurality of virtual machines, the first virtual machine capable of operating in a first state on the host machine wherein the security policy is enforced by the threat management facility, and the first virtual machine capable of operating in a second state wherein a local security facility executable on the first virtual machine autonomously enforces the security policy in the absence of the threat management facility.


