Virtual Machine Security Appliance for Cloud Intrusion Prevention

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud computing environments face significant security challenges due to the lack of control over network topology and hardware, making them vulnerable to botnet attacks and data compromise, with existing security measures being inadequate for virtual machines in elastic and public IaaS environments.

Innovation Solution

A system utilizing an agent executive that operates within a virtual machine to provide automated, portable, and elastic security management, including firewall management, vulnerability detection, compliance monitoring, and intrusion prevention, which securely interoperates with a remote grid computer system for centralized security management across multiple data centers and cloud providers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If cloud servers are deployed in public IaaS environments to gain scalability and flexibility, then productivity and adaptability improve, but security reliability deteriorates due to lack of control over network topology and hardware

Engineering Contradiction:
ImprovescalabilityVSAvoidsecurity
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a security appliance that acts as an intermediary between the virtual machine and the network. This appliance interceptors network traffic and performs security functions (firewall, intrusion prevention, etc.) without requiring the virtual machine to have direct control over network topology or hardware. The security appliance bridges the gap between the need for cloud scalability and the requirement for security control.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system segments security functions from the virtual machine itself and places them in a separate security appliance. This allows the virtual machine to maintain its cloud-based scalability while the security functions are isolated in a dedicated component that can enforce security policies independently of the underlying infrastructure control.

Inventive Principle:
Principle #1Segmentation

2Reliability

If perimeter security controls are implemented in traditional data centers, then security reliability improves, but device complexity increases due to hardware requirements

Engineering Contradiction:
ImprovesecurityVSAvoidhardware control
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a virtualized copy of perimeter security functionality within the cloud environment. Instead of requiring physical perimeter security hardware, the system implements security functions (firewall, IDS/IPS) as virtual appliances that replicate traditional perimeter security behavior in the virtualized network space, eliminating the need for complex hardware control.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system replaces mechanical/physical perimeter security controls with software-based security functions running in the virtualized environment. The security appliance implements firewall and intrusion prevention rules through software rather than requiring physical network perimeter devices, substituting mechanical control with virtualized software control.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Measurement precision

If wire-level network traffic inspection is performed to detect intrusions, then measurement precision improves, but productivity deteriorates due to performance implications

Engineering Contradiction:
Improveintrusion detectionVSAvoidperformance
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The security appliance acts as an intermediary that interceptors network traffic at a point where it can be inspected without impacting the performance of the virtual machine. The appliance performs wire-level inspection of traffic passing through it, enabling precise intrusion detection while isolating the performance impact from the protected virtual machine through the virtualization layer.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9124640B2Systems and methods for implementing computer security
Publication Date: 2015.09.01 FIDELIS SECURITY LLC
  • US9124640B2 patent drawing
  • US9124640B2 patent drawing
  • US9124640B2 patent drawing

AI summary

A computing device includes a security control module to monitor and control security of the operating system and security of one or more applications executing within the operating system. The security control module transmits to a remote security server a policy identifier, which identifies a security policy that applies to the operating system and to the applications. The security control module receives from the remote security server a unique cryptographic key. The security control module periodically retrieves from the security server a set of commands selected by the remote security server according to the security policy and current conditions. The security control module executes each command. Each command either modifies execution of an executable program or process, collects information, or performs an action that modifies data associated with the operating system, data associated with the security control module, or data associated with the one or more applications.