External Introspection for Virtual Machine Integrity

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Virtual machines in virtualized environments face challenges in detecting, analyzing, and managing attacks and exploits due to complexity and interoperability issues across different operating systems, making it difficult to ensure security and integrity.

Innovation Solution

A system that monitors the execution of software components in virtualized environments from an external location, assesses their integrity by comparing monitored execution to expected operations based on source code, and facilitates execution through validation, debugging, and response to exploits, using introspection modules to bridge the semantic gap and manage virtual machines and applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If multiple types of operating systems are executed on a single physical machine to improve resource utilization, then productivity and resource efficiency are improved, but device complexity and security management difficulty increase

Engineering Contradiction:
Improveresource utilizationVSAvoidsecurity management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent introduces a security manager as an intermediary component that operates outside the virtual machines to provide unified security management. This mediator handles the complexity of managing multiple operating systems by providing a centralized interface that abstracts the underlying system diversity, allowing security policies to be applied consistently across different virtual machine types without increasing operational complexity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If virtual machines are monitored from an external location to detect attacks, then security detection capability is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent implements a universal monitoring framework that can observe multiple types of virtual machines through a single external interface. The security manager provides multi-functional capabilities including attack detection, integrity assessment, and system validation through a unified architecture, eliminating the need for separate monitoring solutions for each virtual machine type and reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If integrity assessment is performed by comparing monitored execution to expected operation based on source code, then measurement precision of security status is improved, but loss of time increases

Engineering Contradiction:
Improveintegrity assessment precisionVSAvoidintegrity assessment time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent employs preliminary action by pre-computing and storing expected operation profiles for virtual machines during the initialization phase. These profiles are established before actual monitoring begins, allowing the security manager to perform rapid comparisons during runtime without repeatedly analyzing source code. This pre-processing approach maintains high measurement precision while significantly reducing the time required for continuous integrity assessments.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8356285B2Facilitated introspection of virtualized environments
Publication Date: 2013.01.15 ORACLE AMERICAN INC
  • US8356285B2 patent drawing
  • US8356285B2 patent drawing
  • US8356285B2 patent drawing

AI summary

Some embodiments provide a system that manages the execution of a software component in a virtualized environment. During operation, the system monitors the execution of the software component from an external location to the virtualized environment. Next, the system assesses an integrity of the software component by comparing the monitored execution to an expected operation of the software component, wherein the expected operation is determined based on source code for the software component. Finally, the system uses the assessed integrity of the software component to facilitate the execution of the software component.