Virtual Machine Attack Detection via Resource Contention Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current attack detection methods in cloud computing environments are inadequate for detecting a new type of attack that exploits resource contention management mechanisms, causing performance degradation in virtual machines without targeting specific machines, leading to security vulnerabilities.

Innovation Solution

A method that detects attacks by analyzing temporal correlations between performance degradation in one virtual machine and resource usage variations of other virtual machines, using data collected at regular intervals to identify malicious behavior and potential attacks triggered by resource contention mechanisms such as memory inflation or migration.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If resource contention management mechanisms are implemented to balance resource usage among virtual machines, then resource utilization and economic performance are improved, but security vulnerabilities arise allowing attackers to cause performance degradation in other virtual machines through side effects

Engineering Contradiction:
Improveresource utilizationVSAvoidsecurity vulnerability
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements a detection mechanism that continuously monitors resource usage patterns and performance metrics of virtual machines. When an anomaly is detected (such as unexpected performance degradation correlated with resource contention events), the system generates feedback to identify and alert security personnel about potential attacks, thereby closing the security loop while maintaining resource contention management

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces a security monitoring layer that acts as an intermediary between the resource contention management mechanisms and the virtual machines. This intermediary monitors the side effects of resource contention management and can detect when these side effects are being exploited for attacks, providing an additional security barrier without interfering with resource management operations

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If attack detection methods focus on resources directly manipulated by attackers, then detection of direct attacks is improved, but detection of side effect attacks through resource contention mechanisms is lost

Engineering Contradiction:
Improveattack detection accuracyVSAvoidattack type coverage
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent creates a detection system that serves multiple functions: it monitors both direct attacks on virtual machine resources and indirect attacks through resource contention mechanisms. The same monitoring infrastructure detects various attack vectors by analyzing different patterns in resource usage and performance data, providing universal protection against multiple attack types

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Productivity

If virtual machines are over-committed to maximize economic performance, then resource capacity utilization is improved, but performance degradation occurs when resource contention management mechanisms are activated

Engineering Contradiction:
Improveresource capacity utilizationVSAvoidperformance stability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system continuously monitors performance metrics and resource usage patterns, providing feedback when performance degradation is detected. This feedback mechanism allows the system to identify when over-commitment is causing stability issues and can alert operators to adjust resource allocation, balancing economic performance with reliability

Inventive Principle:
Principle #23Feedback

Data Source

PatentEP2962242B1Virtual machines attack detection process
Publication Date: 2018.05.02 ORANGE SA
  • EP2962242B1 patent drawingFigure 1
  • EP2962242B1 patent drawingFigure 2
  • EP2962242B1 patent drawingFigure 3

AI summary

The invention relates to a method for detecting attacks on at least one virtual machine in a system including at least one host server (10) hosting a set of virtual machines (VM1, VM2, VM3, etc.), the method including the steps of: receiving (E2) an alert indicating a breakdown in performance in a virtual machine; verifying (E3) that a mechanism for managing resource contention has been implemented for the virtual machine; detecting (E5), over a given time interval, at least one time correlation between the breakdown in performance that occurred in the virtual machine and a variation in the use of at least one resource of the host server by at least one other virtual machine, data representing the use of resources being collected at regular intervals.