Backup Machine Vulnerability Analysis via Snapshot Retrieval

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Patch management systems face engineering complexity and operational burdens due to the deployment of software agents across heterogeneous software environments, which complicates the remediation of software vulnerabilities.

Innovation Solution

A backup machine manages software vulnerabilities by retrieving snapshot images from a database, processing them to identify vulnerabilities, and pushing patches without the need to deploy software agents on the production machine, enabling vulnerability remediation and analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If software agents are deployed across heterogeneous software environments, then standard communications protocol is enabled, but engineering complexity increases

Engineering Contradiction:
Improvestandard communications protocolVSAvoidengineering complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent extracts the vulnerability scanning function from the production environment by using snapshot images stored in databases. Instead of deploying agents on production machines, the system retrieves snapshot images and processes them in isolated analysis environments, removing the complexity of agent deployment while maintaining vulnerability detection capability

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent uses snapshot images as copies of the production environment state. These snapshots are stored in databases and can be retrieved for analysis without affecting the actual production systems. This copying approach enables vulnerability scanning without requiring live agents on production machines

Inventive Principle:
Principle #26Copying

2Reliability

If software agents are deployed for patch management, then vulnerability detection capability is improved, but operational burden increases

Engineering Contradiction:
Improvevulnerability detection capabilityVSAvoidoperational burden
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent performs vulnerability analysis in advance by processing snapshot images before patches are applied. The system retrieves snapshots, analyzes them for vulnerabilities, and prepares remediation plans ahead of time, reducing the operational burden of immediate response while maintaining detection capability

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces snapshot images as an intermediary between the production environment and the analysis system. This intermediary allows vulnerability scanning without direct agent deployment on production machines, reducing operational complexity while preserving detection effectiveness

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of manufacture

If snapshot images are retrieved and processed, then vulnerability identification is enabled without software agents, but data processing requirements increase

Engineering Contradiction:
Improvedeployment simplicityVSAvoiddata processing requirements
Core Design Contradiction:
Ease of manufactureVSUse of energy by moving object

Solution Approach 1:

The patent segments the vulnerability management process into distinct phases: snapshot creation, snapshot storage, snapshot retrieval, and vulnerability analysis. This segmentation allows processing to occur in controlled environments using existing database infrastructure, managing data processing requirements while maintaining deployment simplicity

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20230169183A1Facilitating analysis of software vulnerabilities
Publication Date: 2023.06.01 RUBRIK INC
  • US20230169183A1 patent drawing
  • US20230169183A1 patent drawing
  • US20230169183A1 patent drawing

AI summary

Systems and methods for facilitating an analysis of software vulnerabilities are described. The system receives a first request to present software vulnerabilities of a virtual machine on a production machine. The system receives a first request to present software vulnerabilities of a virtual machine on a production machine. The first request includes a first selection including a virtual machine identifier identifying the virtual machine on the production machine. The software vulnerabilities include a first software vulnerability. The system presents a first electronic user interface including software vulnerabilities for the virtual machine. The system receives a second request including a second selection identifying a first software vulnerability. The system presents a second electronic user interface including presenting recovery point identifiers corresponding to snapshot images stored on a database. The snapshot images being of the production machine and including the virtual machine and the first software vulnerability.