Agentless Cloud Workload Scanning With Dynamic Module Loading
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cloud workload scanning technologies often require agent-based solutions, which can introduce security vulnerabilities and inefficiencies, particularly in complex network environments.
Innovation Solution
Implementing an agentless scanning configuration using a scanning driver that provides an interface between data structures and scan modules, allowing for dynamic loading of new scan modules to concurrently analyze data without privileged access.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If agent-based scanning solutions are used, then scanning capability is provided, but security vulnerabilities and inefficiencies are introduced
Solution Approach 1:
The patent extracts and removes the scanning agent from the cloud workload environment, implementing agentless scanning through network-based protocols. This eliminates the security vulnerabilities associated with agents while maintaining scanning capability by using external network access points to collect data from workloads without installing software on them.
Solution Approach 2:
The patent introduces an intermediary scanning infrastructure that communicates with cloud workloads through network protocols rather than direct agent installation. This intermediary layer enables data collection and analysis without requiring privileged access or software installation on the workloads themselves, thereby eliminating security vulnerabilities.
2Productivity
If agent-based scanning solutions are used, then scanning capability is provided, but inefficiencies are introduced in complex network environments
Solution Approach 1:
The patent implements a universal scanning infrastructure that can communicate with multiple cloud workload types through standard network protocols. This multi-functional approach eliminates the need for different agents for different workloads, simplifying the network environment while maintaining comprehensive scanning capability across diverse cloud resources.
Solution Approach 2:
The patent replaces the mechanical agent installation and execution model with network-based communication mechanisms. Instead of installing and running software agents on each workload, the system uses network protocols to collect data, thereby simplifying the network environment and improving efficiency in complex cloud architectures.
3Loss of information
If privileged access is required for scanning, then comprehensive data collection is enabled, but security risks increase
Solution Approach 1:
The patent enables workloads to self-disclose their own data and configuration information through network protocols without requiring external agents or privileged access. Each workload independently provides its own data, eliminating security risks associated with privileged access while maintaining complete data collection through the workload's own operational data.
Solution Approach 2:
The patent changes the fundamental parameter of data collection from requiring privileged access to using standard network communication parameters. By collecting data through network protocols rather than privileged file system access, the system maintains data collection completeness while eliminating security risks associated with privileged access.
4Ease of manufacture
If static scanning configurations are used, then implementation is simple, but adaptability to new scan modules is limited
Solution Approach 1:
The patent segments the scanning functionality into separate, modular scan modules that can be independently developed, tested, and loaded. This segmentation maintains implementation simplicity through a standardized interface while enabling high adaptability by allowing dynamic loading of new scan modules to address emerging cloud workload types without modifying the core infrastructure.
Solution Approach 2:
The patent introduces dynamic configurability to the scanning system, allowing scan modules to be loaded and unloaded at runtime based on the cloud workload environment. This dynamic approach maintains the simplicity of the base implementation while providing versatility to adapt to new scanning requirements through modular additions rather than complex reconfigurations.
Data Source
AI summary
An illustrative method includes a scanning driver providing an interface between data included in a data structure located within a compute environment and one or more scan modules included in an unprivileged agentless workload scanning configuration executing within the compute environment, the one or more scan modules configured to concurrently analyze the data in accordance with one or more respective scan use cases; receiving a request to add a new scan module to the unprivileged agentless workload scanning configuration, the new scan module associated with a new scan use case different than the one or more respective scan use cases, and dynamically loading, based on the request and while the one or more scan modules are concurrently analyzing the data, the new scan module into the unprivileged agentless workload scanning configuration.


