Virtual Machine Migration Detection via Physical Profile Comparison

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing virtualization technologies face challenges in preventing unauthorized usage and copying of virtual machines due to the ease of migration and cloning, which complicates software copy protection measures.

Innovation Solution

A method and apparatus that monitor physical and configuration characteristics of virtual machines to detect unauthorized migration and usage by comparing them to stored profiles, enabling remediation actions such as disabling features or services if unauthorized activity is detected.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If virtual machine migration is enabled for flexibility and resource optimization, then adaptability and productivity are improved, but unauthorized copying and software protection become more difficult

Engineering Contradiction:
Improvevirtual machine migration capabilityVSAvoidsoftware copy protection
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary actions by capturing and storing a baseline configuration profile of the virtual machine before migration occurs. This baseline includes configuration data from multiple sources (guest OS, hypervisor, hardware abstraction layer) that serves as a reference for detecting unauthorized changes later, enabling the system to distinguish between authorized migration modifications and unauthorized copying

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms by continuously monitoring the virtual machine configuration during and after migration, comparing current configuration data against the stored baseline profile. When deviations are detected, the system generates alerts and can trigger remediation actions, providing real-time feedback on the authorization status of migration operations

Inventive Principle:
Principle #23Feedback

2Reliability

If virtual machine configuration is monitored to detect unauthorized usage, then software protection is improved, but device complexity and measurement difficulty increase

Engineering Contradiction:
Improveunauthorized usage detectionVSAvoidmonitoring system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The monitoring system is segmented into multiple independent components that collect configuration data from different layers of the virtualization stack. The baseline profile is divided into discrete configuration elements from the guest operating system, hypervisor, and hardware abstraction layer, which can be independently monitored and compared, reducing the complexity of any single monitoring component

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces configuration profiles as intermediary data structures that mediate between the complex virtual machine environment and the detection logic. These profiles serve as a standardized interface for storing and comparing configuration states, simplifying the monitoring process by providing a consistent format for analysis without requiring direct complex interactions with all virtualization components

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If configuration characteristics are compared to expected values, then unauthorized usage detection is improved, but loss of time for monitoring and comparison increases

Engineering Contradiction:
Improveunauthorized usage detection accuracyVSAvoidconfiguration monitoring time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system applies partial monitoring by focusing on specific configuration characteristics that are most indicative of unauthorized usage rather than monitoring all possible configuration parameters. The baseline profile captures key configuration elements from multiple layers, and comparisons are performed on these critical parameters, achieving effective detection without the time cost of exhaustive full-configuration analysis

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10180851B2Detection of unauthorized use of virtual resources
Publication Date: 2019.01.15 CISCO TECHNOLOGY INC
  • US10180851B2 patent drawing
  • US10180851B2 patent drawing
  • US10180851B2 patent drawing

AI summary

In one implementation, an original physical profile file and a configuration baseline are stored for a virtual machine. The physical profile file includes physical characteristics of a physical device running the virtual machine. The configuration baseline includes configuration settings or attributes of the instance of the virtual machine. A network device detects current value for at least one physical characteristic and compares the current value to the original physical profile file. When the current values deviate enough from the original physical profile file to exceed a threshold amount of deviation that is permissible, the network device determines that the virtual machine has been moved to another physical device. In response, the network device monitors current configuration settings or attributes with respect to the configuration baseline in order to detect an unauthorized usage of the virtual machine.