VM Security via Restricted Boltzmann Machine Graph Analysis

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Virtualized computer systems in cloud environments are vulnerable to cyber-attacks, including malware and botnet infections, due to insufficient security measures and default configurations, which can lead to compromised VMs being used for coordinated attacks.

Innovation Solution

A computer-implemented method using a machine learning algorithm, specifically a restricted Boltzmann machine, to identify susceptible VM configurations by analyzing relationships between VM parameters and attack characteristics, generating a directed graph to determine vulnerable parameters, and implementing protective measures to mitigate attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional security measures and default configurations are used to protect VMs, then implementation simplicity is maintained, but security reliability is insufficient leading to vulnerable configurations

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsecurity configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system performs self-diagnosis by automatically analyzing VM configurations against the directed graph model to identify vulnerable parameters, eliminating the need for manual security audits and enabling automated protective measure implementation

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The directed graph data structure is pre-computed from training data to encode attack sequences and vulnerable configuration relationships, enabling rapid vulnerability assessment without performing complex analysis during actual security evaluation

Inventive Principle:
Principle #10Preliminary action

2Reliability

If comprehensive security analysis is performed to identify all vulnerable VM configurations, then security coverage is improved, but analysis time and computational resources increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidanalysis time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent replaces traditional mechanical security analysis methods with machine learning-based automated analysis using directed graphs, enabling comprehensive security coverage to be achieved through algorithmic processing rather than manual or traditional systematic analysis

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system changes the analysis approach by representing security configurations as graph structures with nodes and edges, transforming the problem from exhaustive configuration checking to graph traversal and pattern matching, which significantly reduces computational complexity

Inventive Principle:
Principle #35Parameter changes

3Measurement precision

If detailed VM configuration parameters are analyzed to identify attack vulnerabilities, then detection precision is improved, but data processing complexity increases

Engineering Contradiction:
Improvevulnerability detection precisionVSAvoiddata processing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system extracts only the critical configuration parameters that are relevant to security vulnerabilities from the complete VM configuration set, focusing analysis on high-risk parameters identified through training data rather than processing all configuration details

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10484402B2Security in virtualized computing environments
Publication Date: 2019.11.19 BRITISH TELECOM PLC
  • US10484402B2 patent drawing
  • US10484402B2 patent drawing
  • US10484402B2 patent drawing

AI summary

A computer implemented method to identify one or more parameters of a configuration of a target virtual machine (VM) in a virtualized computing environment used in a security attack against the target VM, the security attack exhibiting a particular attack characteristic, is disclosed.