Automated Network Scanning in Dynamic Virtualized Environments

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In dynamic virtualized environments, existing network scanning tools face inefficiencies due to the vast number of hosts in multi-tenancy clouds, leading to prolonged scanning times and inaccuracies from unintentional scanning of foreign hosts.

Innovation Solution

The Host Information Processing System (HIPRS) automates network scanning by using an API to retrieve and synchronize inventory records, load-balancing across multiple vulnerability scanners, and managing jobs to exclude terminated hosts, ensuring accurate reporting and minimizing operational overhead.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional vulnerability scanning tools are used to scan all hosts in a multi-tenancy cloud, then comprehensive security coverage is achieved, but scanning time becomes excessively long and operational overhead increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidscanning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the cloud infrastructure into management networks and customer networks, with the vulnerability scanner restricted to scanning only management network hosts. This segmentation allows comprehensive security coverage of critical management infrastructure while avoiding time-consuming scans of customer-owned hosts, thereby resolving the contradiction between security coverage and scanning time.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent extracts and isolates the management network infrastructure from the customer networks, creating a separate scanning scope. By taking out only the management network hosts into the vulnerability scanning scope, the system achieves complete security coverage for critical infrastructure without the overhead of scanning the entire cloud environment including customer hosts.

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If vulnerability scanners continuously scan all hosts to ensure security, then security monitoring is comprehensive, but operational overhead and resource consumption increase

Engineering Contradiction:
Improvesecurity monitoringVSAvoidoperational overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the scanning scope to exclude customer networks from automated vulnerability scanning, restricting scans to management network hosts only. This reduces operational overhead by eliminating the need to manage and coordinate scans across the entire multi-tenancy environment, while maintaining comprehensive security monitoring for critical management infrastructure.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements automated job management where the system automatically creates, schedules, and manages vulnerability scanning jobs for management network hosts without requiring manual intervention. This self-service automation reduces operational overhead by eliminating manual job creation and coordination, while maintaining continuous security monitoring.

Inventive Principle:
Principle #25Self-service

3Reliability

If the vulnerability scanner scans hosts that have been terminated or migrated, then scanning completeness is maintained, but accuracy of scan results decreases due to scanning foreign or non-existent hosts

Engineering Contradiction:
Improvescan completenessVSAvoidscan result accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent implements feedback mechanisms where the vulnerability scanner continuously monitors the status of management network hosts and adjusts its scanning scope accordingly. When hosts are terminated or migrated, the system receives feedback about their status changes and automatically updates the scanning job to exclude these hosts, maintaining both scan completeness for active hosts and accuracy by preventing scans of foreign or non-existent hosts.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent performs preliminary actions by pre-identifying and excluding hosts that are not part of the management network or have been terminated before the scanning process begins. This preliminary filtering ensures that the scanner only targets valid, active management network hosts, maintaining scan completeness for the intended scope while ensuring accuracy by preventing scans of foreign or non-existent hosts.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS9479527B2Methods and systems for automated network scanning in dynamic virtualized environments
Publication Date: 2016.10.25 ZYNGA INC
  • US9479527B2 patent drawing
  • US9479527B2 patent drawing
  • US9479527B2 patent drawing

AI summary

Systems and methods for managing jobs to be scanned based on existence of processing nodes are described. One of the methods includes obtaining identification information regarding operation of a first set of the processing nodes from an inventory and creating a job for scanning the processing nodes of the first set for security vulnerability. The job includes the identification information. The method further includes verifying the inventory to determine the first identifying information of the first set of processing nodes for removal from the job and loading the job having second identifying information for a second set of processing nodes that remain after the verifying operation.