Incremental Cloud Infrastructure Change Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Cloud environments face challenges in efficiently analyzing and updating their security posture due to the complexity and scale of their infrastructure, leading to latency and inaccurate vulnerability identification.

Innovation Solution

A system and method for incremental change detection in cloud infrastructure, which involves detecting triggering criteria for update scans, invoking an incremental change detector, and updating the cloud infrastructure graph based on detected changes, thereby streamlining analysis and reducing latency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If full cloud infrastructure scanning is performed regularly, then security vulnerability identification is comprehensive, but processing time and latency increase significantly

Engineering Contradiction:
Improvesecurity vulnerability identification accuracyVSAvoidprocessing latency
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent segments the cloud infrastructure scanning process into incremental change detection and full scanning components. The incremental change detector identifies only modified resources since the last scan, separating this from the complete infrastructure graph scanning. This segmentation allows the system to perform frequent, low-latency incremental scans while maintaining the option for periodic comprehensive scans, thus resolving the contradiction between comprehensive vulnerability identification and processing latency.

Inventive Principle:
Principle #1Segmentation

2Reliability

If comprehensive infrastructure scanning is performed, then all security vulnerabilities are identified, but computational resources and processing bandwidth are overwhelmed

Engineering Contradiction:
Improvesecurity posture analysis reliabilityVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent implements partial action by using incremental change detection to scan only the portions of cloud infrastructure that have changed since the last scan, rather than performing excessive full infrastructure scanning. The incremental change detector identifies modified resources and triggers selective re-scanning of affected components, reducing computational resource consumption while maintaining security posture analysis reliability through targeted updates of the infrastructure graph.

Inventive Principle:
Principle #16Partial or excessive action

3Loss of information

If frequent full scans are conducted, then infrastructure posture data remains up-to-date, but system performance and latency deteriorate

Engineering Contradiction:
Improveinfrastructure posture data currencyVSAvoidsystem processing efficiency
Core Design Contradiction:
Loss of informationVSProductivity

Solution Approach 1:

The patent applies preliminary action through event monitoring that detects changes in cloud infrastructure resources in real-time. When changes are detected, the system preliminarily identifies affected resources and triggers incremental re-scanning only for those specific components. This preliminary detection mechanism ensures infrastructure posture data remains current without requiring frequent full scans, thereby maintaining data currency while preserving system processing efficiency.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250039208A1Cloud data scanning based on incremental infrastructure detection
Publication Date: 2025.01.30 PROOFPOINT INC
  • US20250039208A1 patent drawing
  • US20250039208A1 patent drawing
  • US20250039208A1 patent drawing

AI summary

The technology disclosed relates to analysis of security posture of a cloud environment that invokes an incremental change detector to perform an infrastructure scan of the cloud environment and return a scan result that identifies one or more changes to one or more infrastructure assets in the cloud environment. The scan result includes, for each particular change in the one or more changes, first information indicative of the particular change. A data scan is constrained to the one or more infrastructure assets having the one or more changes and second information associated with the one or more changes is obtained based on the data scan. A cloud infrastructure graph is updated based on one or more of the first information or the second information. The cloud infrastructure graph defines nodes that represent resources in the cloud environment and edges, between the nodes, that represent relationships between the resources.