Virtual Machine File Tracking via Shared Scanning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current virtual machine configurations on a single physical platform face limitations in accommodating multiple virtual machines due to resource sharing constraints, particularly in terms of security software and processing duplication, which restricts the number of virtual machines that can be supported.

Innovation Solution

Implementing a sharing facility that allows information sharing between virtual machines, including threat management, malware detection, and configuration information, using a virtual machine monitor like a hypervisor to consolidate resources and reduce redundant processing requirements, enabling increased efficiency and security through isolated protected environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security software and processing resources are duplicated for each virtual machine to maintain isolation and security, then security and reliability are improved, but the number of virtual machines that can be accommodated on a single physical platform is limited

Engineering Contradiction:
ImprovesecurityVSAvoidnumber of virtual machines
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent merges security scanning functionality across multiple virtual machines by implementing a shared scanning mechanism. The host system performs malware scanning and shares results with guest virtual machines, eliminating the need for each VM to maintain separate security software instances. This consolidation maintains security coverage while reducing resource duplication, allowing more virtual machines to be accommodated on the same physical platform.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If each virtual machine runs its own security software independently, then security isolation is maintained, but processing resources and memory usage increase

Engineering Contradiction:
Improvesecurity isolationVSAvoidprocessing resources
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent introduces a sharing facility as an intermediary component that mediates between the host system and guest virtual machines. This facility enables secure information sharing about malware threats and scanning results without compromising the isolation boundaries. The intermediary allows guest VMs to benefit from host-level security scanning while maintaining their own security boundaries, reducing the processing overhead required for independent security operations in each VM.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If security scanning is performed independently in each virtual machine, then comprehensive malware detection is achieved, but scanning time and processing requirements are duplicated

Engineering Contradiction:
Improvemalware detectionVSAvoidscanning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary malware scanning at the host level before files are accessed by guest virtual machines. By performing the scanning action in advance and sharing the results with guest VMs, the system avoids redundant scanning operations. This preliminary action ensures comprehensive malware detection while significantly reducing the time and processing resources required, as guest VMs can rely on the host's pre-computed security information.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9177145B2Modified file tracking on virtual machines
Publication Date: 2015.11.03 SOPHOS LTD
  • US9177145B2 patent drawing
  • US9177145B2 patent drawing
  • US9177145B2 patent drawing

AI summary

In embodiments of the present invention improved capabilities are described for tracking modified files on a virtual machine including the steps of identifying an altered disk sector, associating the altered disk sector with code that is operated in a virtual machine, and causing a malicious code scan to be performed on the code.