Workspace Architecture Swapping to Reduce Attack Surface
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Malicious actors can gain access to Information Handling Systems (IHS) through various entry points, potentially downloading or uploading data, compromising the security of the system.
Innovation Solution
Implement a method for generating a first workspace definition on an IHS using a first computing architecture, initiating a timer, and upon expiration, redeploying the workspace using a second computing architecture, with the duration of the timer based on security and productivity metrics, and potentially involving different hardware and software resources, including virtual machines and cloud resources.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If the workspace is deployed using a static computing architecture, then the system is easier to operate and maintain, but the attack surface remains exposed allowing malicious actors to compromise the system
Solution Approach 1:
The computing architecture is transformed from static to dynamic by implementing automated architecture swapping. The system periodically changes between different computing architectures (e.g., virtualized, containerized, bare-metal) based on timer expiration or security events, making the system adaptable and difficult for malicious actors to compromise through static exploitation methods.
Solution Approach 2:
The system implements periodic architecture swapping by initiating timers upon workspace deployment. When the timer expires or security events occur, the system automatically swaps to a different computing architecture, creating periodic changes that disrupt malicious actors' ability to maintain persistent access or exploit known vulnerabilities.
2Reliability
If the workspace is frequently redeployed using different computing architectures, then the attack surface is reduced and security is enhanced, but the deployment complexity and resource overhead increase
Solution Approach 1:
The system implements self-service automated architecture swapping without requiring manual intervention. The workspace manager autonomously monitors timer expiration and security events, automatically generates new workspace definitions with different computing architectures, and redeloys workspaces, thereby reducing deployment complexity despite frequent architecture changes.
Solution Approach 2:
The workspace manager is designed with multi-functionality to handle diverse computing architectures (virtualized, containerized, bare-metal) through a unified interface. This universal approach simplifies deployment complexity by providing consistent management mechanisms across different architecture types rather than requiring separate management for each architecture.
3Reliability
If the timer duration is randomized based on security metrics, then the unpredictability enhances security against timing-based attacks, but the complexity of timer management increases
Solution Approach 1:
The timer duration parameter is changed from fixed to randomized values based on security metrics. The system calculates randomized timer durations using security-related seed values, creating unpredictable expiration times that enhance security against timing-based attacks while the workspace manager automatically handles the complexity of generating and managing these variable timer parameters.
Data Source
AI summary
Systems and methods are provided for swapping computing architectures used by workspaces operating on an Information Handling System (IHS). A first workspace definition is generated for deployment of a workspace on the IHS using a first computing architecture. A timer is initiated upon deployment of the workspace on the IHS according to the first workspace definition. Upon expiration of the timer, a second workspace definition is generated for redeployment of the workspace using a second computing architecture. The workspace is then redeployed on the IHS according to the second workspace definition. The duration of the timer may be a randomized interval, or may be selected based on security and/or productivity metrics for the deployment of the workspace on the IHS. Through swapping of the computing architecture used by the workspace, the attack surface presented by the workspace is regularly altered, thus thwarting malicious actors attempting to compromise the workspace.


