VM Cloning Detection via Malware-Type Agents

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Unauthorized virtual machine cloning in cloud environments leads to information leakage and privacy breaches, as existing technologies lack effective methods to detect and mitigate cloned VMs.

Innovation Solution

Embedding malware-type agents within virtual machines that generate unique identifiers and communicate with a central server or peer-to-peer network to detect clones, initiating remedial actions such as self-destruction or network disruption if unauthorized cloning is detected.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If virtual machines are cloned in cloud environments, then VM productivity and resource utilization are improved, but information leakage and privacy breaches occur

Engineering Contradiction:
ImproveVM productivityVSAvoidinformation leakage
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent embeds agents within virtual machines before cloning occurs, and these agents pre-register unique identifiers with a detection entity. This preliminary setup enables automatic detection of unauthorized clones when they attempt to communicate using the same identifier, thereby preventing information leakage while allowing legitimate cloning operations to proceed

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The detection entity continuously monitors identifier transmissions from multiple VMs and provides feedback when duplicate identifiers are detected. This feedback mechanism enables real-time detection of unauthorized cloning and triggers remedial actions, resolving the contradiction by maintaining productivity while preventing information leakage through active monitoring and response

Inventive Principle:
Principle #23Feedback

2Measurement precision

If agents are embedded in virtual machines to detect cloning, then detection accuracy is improved, but the agents become difficult to distinguish from malware

Engineering Contradiction:
Improvedetection accuracyVSAvoidagent detection difficulty
Core Design Contradiction:
Measurement precisionVSDifficulty of detecting and measuring

Solution Approach 1:

The patent intentionally designs the embedded agents to exhibit behavior similar to malware, including persistent operation and network communication. This converts the potential harm of malware-like behavior into a benefit by making the agents undetectable through conventional means, thereby maintaining high detection accuracy for unauthorized cloning while avoiding false positives from security tools

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Solution Approach 2:

The patent introduces a separate detection entity that acts as an intermediary between the embedded agents and the monitoring system. This intermediary receives identifier transmissions from agents and performs the actual cloning detection, separating the detection function from the agent itself and reducing the risk of the agents being misidentified as malware

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If unique identifiers are transmitted to detect clones, then cloning detection capability is improved, but network communication requirements increase

Engineering Contradiction:
Improvecloning detection capabilityVSAvoidnetwork communication requirements
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements periodic transmission of unique identifiers by embedded agents to the detection entity, rather than continuous transmission. This periodic action maintains reliable cloning detection capability by regularly updating identifier status while significantly reducing network communication requirements and associated energy consumption compared to continuous monitoring approaches

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS8782809B2Limiting information leakage and piracy due to virtual machine cloning
Publication Date: 2014.07.15 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US8782809B2 patent drawing
  • US8782809B2 patent drawing
  • US8782809B2 patent drawing

AI summary

Techniques for detecting a cloned virtual machine instance. A method includes transmitting an identifier associated a virtual machine from an agent embedded in the virtual machine akin to a malware to a detection entity in a network, determining whether the identifier is a unique identifier or whether the identifier is a clone of an identifier associated with a separate virtual machine in the network, and initiating at least one remedial action with the agent embedded in the virtual machine if the identifier is determined to be a clone of an identifier associated with a separate virtual machine in the network.