Agentless Host Configuration Detection via Inspectable Disk
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing solutions for disk inspection in cloud computing environments are resource-intensive, requiring agents that consume memory and processor resources, making them inefficient for widespread deployment.
Innovation Solution
The proposed solution involves generating an inspectable disk based on a host's disk in a virtualized environment, allowing for agentless host configuration detection. This involves receiving a markup language document with definitions, inspecting the disk for cybersecurity objects, evaluating definitions, and generating outputs based on evaluable or unevaluable definitions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If agent-based solutions are used for disk inspection, then inspection capability is improved, but resource consumption (memory and processor) increases
Solution Approach 1:
The patent extracts the inspection logic from the host system by using an external inspection system that analyzes disk data without requiring agents on the host. The inspection system retrieves disk data through API calls and performs all evaluation operations externally, eliminating the need for resource-consuming agents on the inspected systems.
Solution Approach 2:
The patent introduces an intermediary inspection system that acts as a mediator between the disk data and the evaluation process. This intermediary system handles all the computational work for evaluating definitions against disk data, while the host systems merely provide data through standard APIs without running any inspection software.
2Measurement precision
If agents are installed on hosts for inspection, then detection accuracy is improved, but device complexity increases
Solution Approach 1:
The patent extracts the complex inspection logic and evaluation engine from the host systems and consolidates them in a centralized inspection system. This allows detection accuracy to be maintained through comprehensive definition evaluation while reducing device complexity on individual hosts, as they only need to provide data through standard APIs.
Solution Approach 2:
The patent merges multiple inspection functions and definition evaluation capabilities into a single centralized inspection system. This consolidation maintains high detection accuracy through comprehensive analysis while reducing the complexity burden on individual host systems, as all complex operations are performed in the unified inspection platform.
3Ease of manufacture
If agentless inspection is implemented, then ease of deployment is improved, but inspection depth may be reduced
Solution Approach 1:
The patent enables the inspection system to self-service by directly accessing disk data through standard cloud APIs without requiring agent installation on host systems. The inspection system autonomously retrieves, processes, and evaluates disk data, maintaining inspection depth through comprehensive definition evaluation while achieving ease of deployment through agentless operation.
Solution Approach 2:
The inspection system acts as an intermediary that bridges the gap between agentless operation and deep inspection capability. By using standard APIs to access disk data and performing comprehensive definition evaluation in the centralized system, it achieves both ease of deployment (no agents needed) and inspection depth (thorough vulnerability assessment).
Data Source
AI summary
A system and method for evaluating definitions from a markup language document for agentless host configuration includes generating an inspectable disk based on a disk of a host, the host deployed in a virtualized computing environment. The system is configured to: receive a markup language document, the markup language document including a plurality of definitions, each definition including a data element; inspect the inspectable disk for a cybersecurity object corresponding to a first data element of a first definition of the plurality of definitions; evaluate the first definition further based on the cybersecurity object to generate an evaluated first definition result, in response to determining that the definition is evaluable; generate an output based on the evaluated first definition result; and generate the output based on a predetermined notification, in response to determining that the definition is unevaluable.


