Agentless Host Configuration Detection via Inspectable Disk Copy

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing solutions for disk inspection in cloud computing environments require agent installation, which consumes memory and processor resources, making them inefficient for vulnerability assessment.

Innovation Solution

The proposed method generates an inspectable disk based on a host's disk in a virtualized environment, allowing for agentless host configuration detection by evaluating definitions from a markup language document, thereby reducing resource usage.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If an agent is installed on the host to perform disk inspection, then the inspection capability is improved, but the memory and processor resource usage increases

Engineering Contradiction:
Improveinspection capabilityVSAvoidmemory and processor resource usage
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent creates a copy of the host disk (inspectable disk) that can be analyzed independently. The inspection engine evaluates definitions against this copied disk image rather than requiring an agent on the live host, thereby maintaining inspection capability while eliminating the resource overhead of a continuously running agent process

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The inspection functionality is extracted from the host system by creating a separate inspection engine that operates on a copied disk image. This extraction removes the need for an agent residing on the host, eliminating the memory and processor resources that would otherwise be consumed by the agent while preserving the ability to perform comprehensive disk inspection

Inventive Principle:
Principle #2Taking out (Extraction)

2Measurement precision

If an agent is installed on the host to perform vulnerability assessment, then the assessment accuracy is improved, but the device complexity increases

Engineering Contradiction:
Improvevulnerability assessment accuracyVSAvoidagent installation complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

By creating a copy of the disk for inspection purposes, the system maintains the ability to perform accurate vulnerability assessments without requiring complex agent installation and configuration on the host. The copy can be freely analyzed without affecting the host system

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The inspectable disk image serves as an intermediary between the inspection engine and the actual host disk. This intermediary allows the inspection engine to access and analyze disk contents without requiring direct access to the host system through an agent, thereby simplifying the overall system architecture while maintaining assessment accuracy

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If an agent is installed on the host for configuration detection, then the detection capability is improved, but the ease of operation deteriorates

Engineering Contradiction:
Improveconfiguration detection capabilityVSAvoidagent installation and maintenance
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The inspection functionality is extracted from the host system and implemented as a separate inspection engine that operates on a copied disk image. This extraction eliminates the need for agent installation, configuration, and maintenance on the host, thereby improving ease of operation while preserving configuration detection capability

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

By working with a copy of the disk rather than requiring an agent on the host, the system improves operational simplicity. The inspection engine can be deployed and configured independently without requiring access to or modification of the host system, making the overall process easier to operate and maintain

Inventive Principle:
Principle #26Copying

Data Source

PatentUS20250181714A1System and method for agentless host configuration detection in a computing environment
Publication Date: 2025.06.05 WIZ INC
  • US20250181714A1 patent drawing
  • US20250181714A1 patent drawing
  • US20250181714A1 patent drawing

AI summary

A system and method for evaluating definitions from a markup language document for agentless host configuration includes generating an inspectable disk based on a disk of a host, the host deployed in a virtualized computing environment. The system is configured to: receive a markup language document, the markup language document including a plurality of definitions, each definition including a data element; inspect the inspectable disk for a cybersecurity object corresponding to a first data element of a first definition of the plurality of definitions; evaluate the first definition further based on the cybersecurity object to generate an evaluated first definition result, in response to determining that the definition is evaluable; generate an output based on the evaluated first definition result; and generate the output based on a predetermined notification, in response to determining that the definition is unevaluable.