Virtualized Migration Control Appliance for Removable Storage Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Importing data from removable storage media can lead to data corruption and malware infection, which can adversely affect host computers and virtual machines, especially in virtual environments where a single hardware platform supports multiple virtual machines.
Innovation Solution
A virtualized migration control appliance is executed by a hypervisor to manage removable storage medium data, blocking access if policies are not met and performing actions like data washing, decryption, and malware removal to ensure compliance before allowing data access or transfer.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If removable storage medium is directly accessed by virtual machine, then data transfer efficiency is improved, but risk of data corruption and malware infection increases
Solution Approach 1:
The patent introduces a control appliance as an intermediary component between the removable storage medium and the virtual machine. This control appliance intercepts I/O requests, performs policy-based decisions, and executes corrective actions such as data washing and malware scanning. By placing this intermediary layer, the system maintains efficient data transfer through the virtual machine while simultaneously protecting against data corruption and malware infection risks through automated security checks and remediation processes.
2Reliability
If policy-based access control is implemented, then security is improved, but system complexity increases
Solution Approach 1:
The control appliance serves as a centralized intermediary that consolidates policy management and security enforcement functions. Rather than distributing complex security logic across multiple components, the appliance provides a single point of control that manages policies, makes access decisions, and executes corrective actions. This approach improves security through comprehensive policy enforcement while managing system complexity by centralizing control functions in a dedicated component.
Solution Approach 2:
The control appliance implements automated self-service capabilities including automatic policy evaluation, dynamic decision-making, and self-execution of corrective actions such as data washing and malware removal. The system automatically monitors I/O requests, evaluates them against security policies, and performs remediation without requiring manual intervention. This automation improves security response effectiveness while reducing operational complexity by eliminating the need for manual security management.
3Reliability
If data washing and malware removal are performed, then data purity is improved, but processing time increases
Solution Approach 1:
The control appliance performs data washing and malware removal as preliminary actions before data is transferred to or accessed by the virtual machine. By proactively cleaning data at the point of entry or before access is granted, the system ensures data purity is established in advance, preventing potential corruption or malware execution. This preliminary processing approach improves data reliability while managing time loss by performing security checks before critical data operations rather than after issues arise.
Solution Approach 2:
The control appliance implements optimized processing that can skip or expedite data washing and malware removal steps when security policies determine they are not necessary. The system evaluates each I/O request against security policies and only performs corrective actions when actually needed, rather than universally processing all data. This selective approach improves data purity when required while minimizing processing time overhead by avoiding unnecessary security checks on trusted or low-risk data transfers.
Data Source
AI summary
A method includes executing a hypervisor (165) with computing hardware (105) to implement a virtual machine (175); responsive to detecting a removable storage medium (115) communicatively coupled to the computing hardware (105), executing a virtualized migration control appliance (180) through the hypervisor (165) separate from the virtual machine (175); and blocking the virtual machine (175) from accessing data (185) stored by the removable storage medium (115) with the virtualized migration control appliance (180) if at least one governing policy prohibits the virtual machine (175) from accessing the data (185).


