Virtual Machine Vulnerability Metric Assignment for Cloud Security
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Cloud network virtual machines are vulnerable to attacks like DDoS, which compromise resources and are difficult to protect due to shared infrastructure and user-installed applications, making centralized security measures ineffective.
Innovation Solution
An attack analyzer assigns a vulnerability metric to virtual machines, placing them into a detection phase for monitoring and selecting countermeasures based on alerts, with a network controller reconfiguring traffic flow to prevent attacks and quarantine compromised machines.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If centralized security measures are implemented to protect virtual machines, then network security is improved, but effectiveness deteriorates due to user-installed applications and shared infrastructure
Solution Approach 1:
The patent segments the security approach by assigning individual vulnerability metrics to each virtual machine rather than applying centralized security measures uniformly across the network. This allows customized security responses tailored to each VM's specific vulnerability profile, overcoming the ineffectiveness of centralized measures against user-installed applications and shared infrastructure vulnerabilities.
Solution Approach 2:
The patent implements local quality by assigning specific vulnerability metrics to individual virtual machines based on their unique characteristics, installed applications, and traffic patterns. This enables localized security responses that adapt to each VM's specific needs, rather than applying blanket centralized security measures that fail to address individual vulnerabilities.
2Measurement precision
If all virtual machines are monitored continuously for attacks, then detection capability is improved, but power consumption increases
Solution Approach 1:
The patent applies partial action by monitoring virtual machines selectively based on their vulnerability metrics rather than continuously monitoring all VMs. Virtual machines with higher vulnerability scores undergo more intensive monitoring and countermeasure application, while those with lower scores receive reduced monitoring, thereby reducing overall power consumption while maintaining adequate detection capability.
Solution Approach 2:
The patent changes the monitoring parameter dynamically by adjusting the intensity of security measures based on the calculated vulnerability metric for each virtual machine. This allows the system to optimize power consumption by scaling monitoring resources according to actual risk levels rather than maintaining constant high-level monitoring across all VMs.
3Ease of manufacture
If vulnerability metrics are assigned to identify vulnerable virtual machines, then security targeting is improved, but system complexity increases
Solution Approach 1:
The patent implements self-service by automatically calculating vulnerability metrics for each virtual machine based on analyzing their traffic patterns and characteristics. The system autonomously assigns vulnerability scores and determines appropriate countermeasures without requiring manual assessment, thereby improving security implementation efficiency while managing system complexity through automation rather than manual processes.
Data Source
AI summary
Examples disclose a method, executable by a processor, to assign a metric of vulnerability to a virtual machine. Based on the metric of vulnerability, the method places the virtual machine into a detection phase. Additionally, the examples disclose the method is to receive an alert corresponding to the virtual machine and based this received alert, the method implements a countermeasure.


