External Cloud Data Security Scanning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional cloud-based information security methods often require computationally intensive security scanning within cloud computing instances, which can negatively impact the performance of primary applications.

Innovation Solution

Performing security scans on data stored by cloud computing instances from external computing systems, rather than within the instances, to minimize performance impact on primary applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security scans are performed within cloud computing instances, then information security is ensured, but performance of primary applications deteriorates due to computational intensity

Engineering Contradiction:
Improveinformation securityVSAvoidperformance of primary applications
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The security scanning function is extracted from the cloud computing instances and relocated to external computing systems. The security scan is performed on data volumes outside the instance boundaries, removing the computational burden from the primary application environment while maintaining security scanning capabilities.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

An external computing system acts as an intermediary between the cloud computing service and the security scanning process. This intermediary performs the computationally intensive security scans on behalf of the cloud instances, preventing direct resource competition while ensuring security requirements are met.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If security scans are performed on all data volumes, then comprehensive security coverage is achieved, but resource consumption increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidresource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The security scanning approach is customized based on local characteristics of each data volume and cloud computing instance. Scanning parameters, frequency, and depth are adjusted according to the specific owner, data type, and security requirements, avoiding uniform resource-intensive scanning of all data volumes.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

Instead of scanning all data volumes with equal intensity, the system performs partial scanning focused on changed data blocks and prioritizes scans based on ownership and security policies. This selective approach achieves adequate security coverage with reduced resource consumption.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9104859B1Systems and methods for scanning data stored on cloud computing platforms
Publication Date: 2015.08.11 CA TECH INC
  • US9104859B1 patent drawing
  • US9104859B1 patent drawing
  • US9104859B1 patent drawing

AI summary

A computer-implemented method for scanning data stored on cloud computing platforms may include (1) identifying a cloud computing service that hosts a plurality of cloud computing instances and a plurality of data volumes that store data for the plurality of cloud computing instances, (2) determining that a data volume within the plurality of data volumes that stores data for a cloud computing instance within the plurality of cloud computing instances is subject to a security scan, (3) detecting a computing system that is external to the cloud computing instance, and (4) performing the security scan on the data volume from the computing system that is external to the cloud computing instance instead of performing the security scan from within the cloud computing instance. Various other methods, systems, and computer-readable media are also disclosed.