Agentless Vulnerability Inspection via Inspectable Disk Generation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity monitoring solutions face challenges such as high computational resource usage due to agent-based scanning, and the need for multiple tailored solutions across different environments, which are costly and require constant maintenance.

Innovation Solution

An agentless method that initiates network communication between an on-premises environment and an inspection environment, generates an inspectable disk, and provides access to an inspector to scan for cybersecurity threats without allocating dedicated resources, allowing for efficient detection and resource conservation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If agent-based scanning solutions are deployed to gain wide access to machine data including run time data, then detection capability is improved, but computational resource consumption increases significantly

Engineering Contradiction:
Improvedetection capabilityVSAvoidcomputational resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent introduces an intermediary component that sits between the agentless scanner and the target systems. This intermediary captures and processes data streams from multiple sources (logs, metrics, traces) without requiring direct agent deployment on target machines, thereby maintaining detection capability while reducing computational burden on scanned systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Instead of deploying actual scanning agents on target machines, the system creates virtual representations and copies of data through centralized collection of logs, metrics, and traces. This allows the scanning functionality to be replicated and executed centrally without the overhead of multiple agent instances running on scanned systems.

Inventive Principle:
Principle #26Copying

2Measurement precision

If multiple tailored monitoring solutions are deployed across different environments to address specific cybersecurity threats, then detection accuracy is improved, but system complexity and maintenance requirements increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent implements a universal agentless scanning platform that can operate across multiple different environments (cloud, on-premises, hybrid) without requiring environment-specific agents. The system achieves tailored detection for different environments through configuration and data source selection rather than through separate specialized solutions, thereby reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system adapts to different environments by changing operational parameters such as data source configurations, scanning profiles, and analysis rules rather than requiring fundamentally different scanning solutions. This allows a single platform to provide environment-specific detection accuracy through parameter adjustment rather than structural complexity.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20240330456A1Techniques for agentless vulnerability inspection in on-premises computing environments
Publication Date: 2024.10.03 WIZ INC
  • US20240330456A1 patent drawing
  • US20240330456A1 patent drawing
  • US20240330456A1 patent drawing

AI summary

A system and method for inspecting a resource in an on-premises environment for a cybersecurity threat are disclosed. According to an embodiment, the method includes initiating a network communication between an on-premises environment and an inspection environment; scanning the on-premises environment for a workload, the workload including a disk; generating an inspectable disk based on the disk; providing access to an inspector deployed in the inspection environment to inspect the inspectable disk for a cybersecurity object; and releasing a resource allocated to the inspectable disk in response to detecting that inspection of the inspectable disk is complete.