External Cloud Data Security Scanning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Traditional cloud-based information security methods often require computationally intensive security scanning within cloud computing instances, which can negatively impact the performance of primary applications.
Innovation Solution
Performing security scans on data stored by cloud computing instances from external computing systems, rather than within the instances, to minimize performance impact on primary applications.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security scans are performed within cloud computing instances, then information security is ensured, but performance of primary applications deteriorates due to computational intensity
Solution Approach 1:
The security scanning function is extracted from the cloud computing instances and relocated to external computing systems. The security scan is performed on data volumes outside the instance boundaries, removing the computational burden from the primary application environment while maintaining security scanning capabilities.
Solution Approach 2:
An external computing system acts as an intermediary between the cloud computing service and the security scanning process. This intermediary performs the computationally intensive security scans on behalf of the cloud instances, preventing direct resource competition while ensuring security requirements are met.
2Reliability
If security scans are performed on all data volumes, then comprehensive security coverage is achieved, but resource consumption increases
Solution Approach 1:
The security scanning approach is customized based on local characteristics of each data volume and cloud computing instance. Scanning parameters, frequency, and depth are adjusted according to the specific owner, data type, and security requirements, avoiding uniform resource-intensive scanning of all data volumes.
Solution Approach 2:
Instead of scanning all data volumes with equal intensity, the system performs partial scanning focused on changed data blocks and prioritizes scans based on ownership and security policies. This selective approach achieves adequate security coverage with reduced resource consumption.
Data Source
AI summary
A computer-implemented method for scanning data stored on cloud computing platforms may include (1) identifying a cloud computing service that hosts a plurality of cloud computing instances and a plurality of data volumes that store data for the plurality of cloud computing instances, (2) determining that a data volume within the plurality of data volumes that stores data for a cloud computing instance within the plurality of cloud computing instances is subject to a security scan, (3) detecting a computing system that is external to the cloud computing instance, and (4) performing the security scan on the data volume from the computing system that is external to the cloud computing instance instead of performing the security scan from within the cloud computing instance. Various other methods, systems, and computer-readable media are also disclosed.


