Active Scanner Identifying Misconfigured VM Instances

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Service providers' cloud-based networks face vulnerabilities due to misconfigured virtual machine instances, allowing attackers to access sensitive information, as customers often fail to properly configure Web Application Proxy servers, leading to unchecked access to resources.

Innovation Solution

An automated security assessment service employs a scanner tool that actively identifies and notifies customers of misconfigured Internet-accessible VM instances by sending requests to determine security vulnerabilities, storing results for customer remediation, and selectively scanning only accessible instances to minimize resource consumption and service interruptions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If a scanner tool actively scans all customer VM instances to identify security vulnerabilities, then security detection capability is improved, but resource consumption and service interruptions increase

Engineering Contradiction:
Improvesecurity vulnerability detection capabilityVSAvoidcomputing resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent segments the scanning process by first identifying only Internet-accessible VM instances through automated reasoning services that analyze network configurations, rather than scanning all customer VM instances. This segmentation reduces the scanning scope to only those instances that pose actual security risks, thereby improving detection efficiency while reducing resource consumption and service interruptions.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If automated reasoning services analyze network configurations to identify Internet-accessible instances, then scanning accuracy is improved, but service interruption risk increases

Engineering Contradiction:
Improveinstance identification accuracyVSAvoidservice continuity
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent applies preliminary action by having automated reasoning services analyze network configurations and identify Internet-accessible VM instances before the actual security scanning begins. This preliminary identification phase allows the system to prepare a targeted list of instances to scan, improving accuracy while minimizing service interruptions during the main scanning operation by avoiding unnecessary analysis of non-accessible instances.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11803766B1Active scanning tool for identifying customer misconfigurations of virtual machine instances
Publication Date: 2023.10.31 AMAZON TECH INC
  • US11803766B1 patent drawing
  • US11803766B1 patent drawing
  • US11803766B1 patent drawing

AI summary

An automated security assessment service of a service provider network may identify, and notify a customer of, misconfigured VM instances that can be access (e.g., via the Internet). A scanner tool may call an automated reasoning service to identify any VM instances of a customer that can be accessed, and may receive information from the automated reasoning service that is usable to exchange packets with those identified instances. The scanner tool can use the information to send requests to the identified instances. After receiving responses from the identified instances, the scanner tool can store, in storage of a network-based storage service, and in association with a customer account of the customer, encrypted data about the results of the scan (e.g., any VM instances that are vulnerable to attackers), and this encrypted data is thereby accessible to the customer with proper decrypt permissions.