Agentless Cloud Workload Scanning With Dynamic Module Loading

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud workload scanning technologies often require agent-based solutions, which can introduce security vulnerabilities and inefficiencies, particularly in complex network environments.

Innovation Solution

Implementing an agentless scanning configuration using a scanning driver that provides an interface between data structures and scan modules, allowing for dynamic loading of new scan modules to concurrently analyze data without privileged access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If agent-based scanning solutions are used, then scanning capability is provided, but security vulnerabilities and inefficiencies are introduced

Engineering Contradiction:
ImprovesecurityVSAvoidsecurity vulnerabilities
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

The patent extracts and removes the scanning agent from the cloud workload environment, implementing agentless scanning through network-based protocols. This eliminates the security vulnerabilities associated with agents while maintaining scanning capability by using external network access points to collect data from workloads without installing software on them.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces an intermediary scanning infrastructure that communicates with cloud workloads through network protocols rather than direct agent installation. This intermediary layer enables data collection and analysis without requiring privileged access or software installation on the workloads themselves, thereby eliminating security vulnerabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If agent-based scanning solutions are used, then scanning capability is provided, but inefficiencies are introduced in complex network environments

Engineering Contradiction:
Improvescanning efficiencyVSAvoidnetwork environment complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements a universal scanning infrastructure that can communicate with multiple cloud workload types through standard network protocols. This multi-functional approach eliminates the need for different agents for different workloads, simplifying the network environment while maintaining comprehensive scanning capability across diverse cloud resources.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent replaces the mechanical agent installation and execution model with network-based communication mechanisms. Instead of installing and running software agents on each workload, the system uses network protocols to collect data, thereby simplifying the network environment and improving efficiency in complex cloud architectures.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Loss of information

If privileged access is required for scanning, then comprehensive data collection is enabled, but security risks increase

Engineering Contradiction:
Improvedata collection completenessVSAvoidsecurity risks
Core Design Contradiction:
Loss of informationVSObject-affected harmful factors

Solution Approach 1:

The patent enables workloads to self-disclose their own data and configuration information through network protocols without requiring external agents or privileged access. Each workload independently provides its own data, eliminating security risks associated with privileged access while maintaining complete data collection through the workload's own operational data.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent changes the fundamental parameter of data collection from requiring privileged access to using standard network communication parameters. By collecting data through network protocols rather than privileged file system access, the system maintains data collection completeness while eliminating security risks associated with privileged access.

Inventive Principle:
Principle #35Parameter changes

4Ease of manufacture

If static scanning configurations are used, then implementation is simple, but adaptability to new scan modules is limited

Engineering Contradiction:
Improveimplementation simplicityVSAvoidscan module adaptability
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent segments the scanning functionality into separate, modular scan modules that can be independently developed, tested, and loaded. This segmentation maintains implementation simplicity through a standardized interface while enabling high adaptability by allowing dynamic loading of new scan modules to address emerging cloud workload types without modifying the core infrastructure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces dynamic configurability to the scanning system, allowing scan modules to be loaded and unloaded at runtime based on the cloud workload environment. This dynamic approach maintains the simplicity of the base implementation while providing versatility to adapt to new scanning requirements through modular additions rather than complex reconfigurations.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12368746B1Modular agentless scanning of cloud workloads
Publication Date: 2025.07.22 FORTINET INC
  • US12368746B1 patent drawing
  • US12368746B1 patent drawing
  • US12368746B1 patent drawing

AI summary

An illustrative method includes a scanning driver providing an interface between data included in a data structure located within a compute environment and one or more scan modules included in an unprivileged agentless workload scanning configuration executing within the compute environment, the one or more scan modules configured to concurrently analyze the data in accordance with one or more respective scan use cases; receiving a request to add a new scan module to the unprivileged agentless workload scanning configuration, the new scan module associated with a new scan use case different than the one or more respective scan use cases, and dynamically loading, based on the request and while the one or more scan modules are concurrently analyzing the data, the new scan module into the unprivileged agentless workload scanning configuration.