Virtual Machine Vulnerability Metric Assignment for Cloud Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud network virtual machines are vulnerable to attacks like DDoS, which compromise resources and are difficult to protect due to shared infrastructure and user-installed applications, making centralized security measures ineffective.

Innovation Solution

An attack analyzer assigns a vulnerability metric to virtual machines, placing them into a detection phase for monitoring and selecting countermeasures based on alerts, with a network controller reconfiguring traffic flow to prevent attacks and quarantine compromised machines.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized security measures are implemented to protect virtual machines, then network security is improved, but effectiveness deteriorates due to user-installed applications and shared infrastructure

Engineering Contradiction:
Improvenetwork securityVSAvoideffectiveness of security measures
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent segments the security approach by assigning individual vulnerability metrics to each virtual machine rather than applying centralized security measures uniformly across the network. This allows customized security responses tailored to each VM's specific vulnerability profile, overcoming the ineffectiveness of centralized measures against user-installed applications and shared infrastructure vulnerabilities.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements local quality by assigning specific vulnerability metrics to individual virtual machines based on their unique characteristics, installed applications, and traffic patterns. This enables localized security responses that adapt to each VM's specific needs, rather than applying blanket centralized security measures that fail to address individual vulnerabilities.

Inventive Principle:
Principle #3Local quality

2Measurement precision

If all virtual machines are monitored continuously for attacks, then detection capability is improved, but power consumption increases

Engineering Contradiction:
Improveattack detection capabilityVSAvoidpower consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent applies partial action by monitoring virtual machines selectively based on their vulnerability metrics rather than continuously monitoring all VMs. Virtual machines with higher vulnerability scores undergo more intensive monitoring and countermeasure application, while those with lower scores receive reduced monitoring, thereby reducing overall power consumption while maintaining adequate detection capability.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The patent changes the monitoring parameter dynamically by adjusting the intensity of security measures based on the calculated vulnerability metric for each virtual machine. This allows the system to optimize power consumption by scaling monitoring resources according to actual risk levels rather than maintaining constant high-level monitoring across all VMs.

Inventive Principle:
Principle #35Parameter changes

3Ease of manufacture

If vulnerability metrics are assigned to identify vulnerable virtual machines, then security targeting is improved, but system complexity increases

Engineering Contradiction:
Improvesecurity implementation efficiencyVSAvoidsystem complexity
Core Design Contradiction:
Ease of manufactureVSDevice complexity

Solution Approach 1:

The patent implements self-service by automatically calculating vulnerability metrics for each virtual machine based on analyzing their traffic patterns and characteristics. The system autonomously assigns vulnerability scores and determines appropriate countermeasures without requiring manual assessment, thereby improving security implementation efficiency while managing system complexity through automation rather than manual processes.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS9160761B2Selection of a countermeasure
Publication Date: 2015.10.13 HEWLETT PACKARD ENTERPRISE DEV LP
  • US9160761B2 patent drawing
  • US9160761B2 patent drawing
  • US9160761B2 patent drawing

AI summary

Examples disclose a method, executable by a processor, to assign a metric of vulnerability to a virtual machine. Based on the metric of vulnerability, the method places the virtual machine into a detection phase. Additionally, the examples disclose the method is to receive an alert corresponding to the virtual machine and based this received alert, the method implements a countermeasure.