Virtual Machine Attribute Verification for Security Integrity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In modern data centers employing virtual server technology, malicious individuals can modify virtual machine attributes to perpetrate crimes or hide configuration errors, making it difficult to ensure security and integrity, as discrepancies between reported and actual attributes can be masked, leading to potential security breaches.

Innovation Solution

A virtual machine verifier is introduced to compare information about virtual machine attributes from host machines with actual attributes, using a network map and rules to detect discrepancies, generating a report on any inconsistencies, thereby automatically identifying potential malicious modifications or configuration errors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Difficulty of detecting and measuring

If virtual machine attributes are modified to mask malicious changes, then the difficulty of detecting security breaches increases, but the security and integrity of the virtual machine decreases

Engineering Contradiction:
Improvedifficulty of detecting malicious modificationsVSAvoidsecurity and integrity of virtual machine
Core Design Contradiction:
Difficulty of detecting and measuringVSReliability

Solution Approach 1:

The patent implements a verification system that continuously monitors virtual machine attributes and compares them against expected values. When discrepancies are detected (such as unauthorized changes to processor count, memory allocation, or disk space), the system generates alerts and can trigger remediation actions. This feedback loop ensures that malicious modifications are detected and addressed, maintaining security while allowing legitimate configuration changes.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent establishes baseline configurations for virtual machines before they are deployed or modified. These baselines include expected values for critical attributes such as processor count, memory allocation, network bandwidth, and disk space. By having these predetermined expectations in place beforehand, the system can quickly identify and respond to unauthorized changes, preventing malicious activities before they can cause significant harm.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If manual verification of virtual machine attributes is performed, then detection accuracy improves, but the time and resources required increase

Engineering Contradiction:
Improvedetection accuracy of attribute discrepanciesVSAvoidtime required for verification
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The verification system operates autonomously without requiring manual intervention. It automatically collects virtual machine attribute data from the virtualization platform, compares these attributes against stored baselines, identifies discrepancies, and generates verification reports. This self-service approach maintains high detection accuracy while eliminating the time consumption and resource requirements of manual verification processes.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual verification processes with an automated computational system. Instead of security personnel manually checking virtual machine configurations, the system uses software agents and scripts to automatically gather attribute data, perform comparisons, and generate alerts. This substitution of mechanical human effort with automated computational processes maintains precision while dramatically reducing the time and resources required.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Reliability

If comprehensive monitoring of all virtual machine attributes is implemented, then security coverage improves, but system complexity increases

Engineering Contradiction:
Improvesecurity coverage of virtual machinesVSAvoidcomplexity of verification system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements monitoring for all virtual machine attributes but applies different verification strategies based on the criticality of each attribute. Critical attributes such as processor count, memory allocation, and disk space have strict verification rules with immediate alerts for any changes. Less critical attributes have more flexible monitoring with threshold-based alerts. This localized quality approach ensures comprehensive security coverage while managing system complexity through differentiated monitoring intensity.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The verification system divides the monitoring task into separate modular components, each responsible for specific virtual machine attributes or functions. The system segments verification into baseline management, data collection, comparison logic, alert generation, and reporting modules. This segmentation allows the system to comprehensively monitor all attributes while keeping each component simple and maintainable, reducing overall system complexity.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8732703B2Verifying virtual machines
Publication Date: 2014.05.20 HEWLETT PACKARD ENTERPRISE DEV LP
  • US8732703B2 patent drawing
  • US8732703B2 patent drawing
  • US8732703B2 patent drawing

AI summary

According to one embodiment, virtual machine attributes are verified. Information (142) about attributes for a virtual machine (152) is obtained (320) from a host machine (120) that the virtual machine (152) executes on. Actual virtual machine attributes (162) are obtained 330 from the virtual machine (152). Discrepancies between the information (142) about the attributes and the actual virtual machine attributes (162) are determined (340) by comparing the information (142) about the attributes to the actual virtual machine attributes (162).