Virtual Machine Security Monitoring via Baseline Trend Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In untrusted cloud computing environments, existing security and integrity measures are ineffective due to uncertainty about physical hardware access and interactions between virtual and host machines, posing challenges in maintaining security and integrity.

Innovation Solution

A system and method for monitoring virtual machines in cloud environments, which includes a baseline module to generate baseline files, a trends module to analyze these files, and a benchmark module to detect differences and generate reports on security and integrity changes, enabling continuous monitoring and threat identification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If known security measures are implemented in untrusted cloud environments, then security and integrity monitoring is attempted, but effectiveness is reduced due to uncertainty about physical hardware access and virtual machine interactions

Engineering Contradiction:
Improvesecurity and integrity monitoring effectivenessVSAvoiduncertainty about physical hardware access and virtual machine interactions
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security monitoring system into distinct functional modules: a baseline module that captures system state information, a storage module that preserves historical baselines, and an analysis module that compares current states against stored baselines. This segmentation allows each module to operate independently, reducing the impact of hardware uncertainty on overall system effectiveness while maintaining comprehensive monitoring capabilities.

Inventive Principle:
Principle #1Segmentation

2Reliability

If continuous monitoring of virtual machines is performed through baseline generation and comparison, then security threats are identified timely, but system resources are consumed continuously

Engineering Contradiction:
Improvethreat identification timelinessVSAvoidsystem resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements periodic action by generating baseline files at scheduled intervals rather than continuously. The system captures system state information at predetermined time points, stores these baselines, and performs comparative analysis periodically. This approach maintains timely threat identification while significantly reducing system resource consumption compared to continuous monitoring, as the baseline module only activates at scheduled intervals to collect and compare system states.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS9542213B2Method and system for identifying virtualized operating system threats in a cloud computing environment
Publication Date: 2017.01.10 MAXISIQ INC
  • US9542213B2 patent drawing
  • US9542213B2 patent drawing
  • US9542213B2 patent drawing

AI summary

Systems for monitoring a virtual machine in a cloud computing environment are disclosed. The systems include a baseline module residing on the virtual machine configured to retrieve baseline information from the virtual machine and create a plurality of baseline files and a trends module configured to retrieve a number of baseline files, comparatively analyze the number of baseline files and generate at least one trends report based on the comparative analysis of baseline files.