Cloud Application Path Detection With Targeted Active Inspection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing active scanning methods for detecting vulnerabilities in cloud environments generate excessive network traffic and risk service disruptions, providing incomplete information about actual accessible paths.

Innovation Solution

A method utilizing static analysis to determine reachable resources and network paths, followed by active inspection to validate accessibility, reducing resource consumption and ensuring a more accurate assessment of security risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If active scanning is used to discover external attack surface, then vulnerability detection capability is improved, but network traffic volume increases causing congestion and potential service disruption

Engineering Contradiction:
Improvevulnerability detection capabilityVSAvoidnetwork traffic volume
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent applies preliminary action by performing static analysis of cloud environment configurations, security group rules, and network path definitions before conducting active scanning. This pre-processing step identifies potential attack paths and vulnerable resources without generating network traffic, allowing the subsequent active scanning to be targeted and minimized rather than broad and exhaustive.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary layer that acts as a mediator between the active scanner and the cloud environment. This intermediary uses static analysis results to filter and prioritize scan targets, translating comprehensive configuration data into a focused set of high-risk paths for active scanning. This intermediary processing reduces the overall scan volume while maintaining detection effectiveness.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If comprehensive active scanning is performed to map all network paths, then complete vulnerability picture is achieved, but resource consumption and network bandwidth usage increase

Engineering Contradiction:
Improvecompleteness of vulnerability pictureVSAvoidresource consumption
Core Design Contradiction:
Loss of informationVSUse of energy by moving object

Solution Approach 1:

The patent segments the vulnerability assessment process into two distinct phases: static analysis phase and active scanning phase. The static analysis phase processes configuration data, security group rules, and network path definitions to identify potential attack surfaces without resource-intensive network operations. The active scanning phase then focuses only on the segmented high-risk paths identified in the first phase, reducing overall resource consumption while maintaining comprehensive coverage of actual vulnerabilities.

Inventive Principle:
Principle #1Segmentation

3Adaptability or versatility

If random port and domain scanning is used to discover cloud environment vulnerabilities, then external attack surface is mapped, but network congestion and service disruption risk increase

Engineering Contradiction:
Improveattack surface mapping capabilityVSAvoidproduction environment availability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent performs preliminary static analysis of cloud environment configurations, security group rules, and network path definitions before conducting active scanning. This pre-processing step identifies actual accessible paths and vulnerable resources based on configuration data, allowing the subsequent active scanning to be targeted only at legitimate attack paths rather than random probing, thus maintaining production environment availability.

Inventive Principle:
Principle #10Preliminary action

4Measurement precision

If active scanning targets production environment resources, then real vulnerability data is obtained, but network bandwidth and system resources are consumed

Engineering Contradiction:
Improvevulnerability assessment accuracyVSAvoidnetwork bandwidth availability
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent segments the scanning process into static analysis (configuration-based path identification) and active scanning (validated path testing). The static analysis phase processes configuration data without consuming network bandwidth, identifying potential attack paths. The active scanning phase then tests only these pre-identified paths with minimal traffic, maintaining vulnerability assessment accuracy while preserving network bandwidth availability for production workloads.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12443720B2Techniques for detecting applications paths utilizing exposure analysis
Publication Date: 2025.10.14 WIZ INC
  • US12443720B2 patent drawing
  • US12443720B2 patent drawing
  • US12443720B2 patent drawing

AI summary

A system and method for detecting an application path utilizing active inspection of a cloud computing environment, includes selecting a reachable resource having at least one network path to access the reachable resource, wherein the reachable resource is a cloud object deployed in the cloud computing environment, and accessible from a network which is external to the cloud computing environment; selecting a second resource having a second network path based on the network path of the reachable resource; and actively inspecting the second network path to determine if the second resource is accessible through the second network path from the reachable resource.