Cloud Application Path Detection With Targeted Active Inspection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing active scanning methods for detecting vulnerabilities in cloud environments generate excessive network traffic and risk service disruptions, providing incomplete information about actual accessible paths.
Innovation Solution
A method utilizing static analysis to determine reachable resources and network paths, followed by active inspection to validate accessibility, reducing resource consumption and ensuring a more accurate assessment of security risks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If active scanning is used to discover external attack surface, then vulnerability detection capability is improved, but network traffic volume increases causing congestion and potential service disruption
Solution Approach 1:
The patent applies preliminary action by performing static analysis of cloud environment configurations, security group rules, and network path definitions before conducting active scanning. This pre-processing step identifies potential attack paths and vulnerable resources without generating network traffic, allowing the subsequent active scanning to be targeted and minimized rather than broad and exhaustive.
Solution Approach 2:
The patent introduces an intermediary layer that acts as a mediator between the active scanner and the cloud environment. This intermediary uses static analysis results to filter and prioritize scan targets, translating comprehensive configuration data into a focused set of high-risk paths for active scanning. This intermediary processing reduces the overall scan volume while maintaining detection effectiveness.
2Loss of information
If comprehensive active scanning is performed to map all network paths, then complete vulnerability picture is achieved, but resource consumption and network bandwidth usage increase
Solution Approach 1:
The patent segments the vulnerability assessment process into two distinct phases: static analysis phase and active scanning phase. The static analysis phase processes configuration data, security group rules, and network path definitions to identify potential attack surfaces without resource-intensive network operations. The active scanning phase then focuses only on the segmented high-risk paths identified in the first phase, reducing overall resource consumption while maintaining comprehensive coverage of actual vulnerabilities.
3Adaptability or versatility
If random port and domain scanning is used to discover cloud environment vulnerabilities, then external attack surface is mapped, but network congestion and service disruption risk increase
Solution Approach 1:
The patent performs preliminary static analysis of cloud environment configurations, security group rules, and network path definitions before conducting active scanning. This pre-processing step identifies actual accessible paths and vulnerable resources based on configuration data, allowing the subsequent active scanning to be targeted only at legitimate attack paths rather than random probing, thus maintaining production environment availability.
4Measurement precision
If active scanning targets production environment resources, then real vulnerability data is obtained, but network bandwidth and system resources are consumed
Solution Approach 1:
The patent segments the scanning process into static analysis (configuration-based path identification) and active scanning (validated path testing). The static analysis phase processes configuration data without consuming network bandwidth, identifying potential attack paths. The active scanning phase then tests only these pre-identified paths with minimal traffic, maintaining vulnerability assessment accuracy while preserving network bandwidth availability for production workloads.
Data Source
AI summary
A system and method for detecting an application path utilizing active inspection of a cloud computing environment, includes selecting a reachable resource having at least one network path to access the reachable resource, wherein the reachable resource is a cloud object deployed in the cloud computing environment, and accessible from a network which is external to the cloud computing environment; selecting a second resource having a second network path based on the network path of the reachable resource; and actively inspecting the second network path to determine if the second resource is accessible through the second network path from the reachable resource.


