Cloud Resource Inspection Paths for Low-Traffic Sensitive Data Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing active scanning methods for detecting vulnerabilities in cloud computing environments generate excessive network traffic, risking congestion and service disruptions, which is detrimental to maintaining a production environment's operational state.

Innovation Solution

A method and system for active inspection of cloud environments that utilize network paths and reachability parameters to access resources, detect sensitive data indicators, and initiate mitigation actions, employing techniques like optical character recognition and security graph updates to minimize exposure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If active scanning is used to discover external attack surface, then vulnerability detection capability is improved, but network traffic volume increases causing congestion and service disruptions

Engineering Contradiction:
Improvevulnerability detection capabilityVSAvoidnetwork traffic volume
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent extracts the essential inspection function from traditional active scanning by using predefined network paths and reachability parameters. Instead of sending random packets across the entire network, the system extracts only the necessary paths to reach cloud objects, significantly reducing network traffic while maintaining vulnerability detection capability.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs preliminary actions by pre-defining network paths and reachability parameters before actual inspection. The cloud environment configuration is analyzed in advance to identify valid access paths, so that subsequent vulnerability scanning only traverses known legitimate routes, avoiding random traffic that causes congestion.

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If random port scanning is performed to access network resources, then accessibility testing is improved, but risk of service disruption increases

Engineering Contradiction:
Improveaccessibility testingVSAvoidproduction environment operational state
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent applies local quality by making the inspection process adaptive to specific cloud object configurations. Instead of uniform random scanning across all ports, the system tailors inspection to each cloud object's actual network path and reachability parameters, testing only relevant accessibility while avoiding disruption to production services.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system introduces an intermediary layer of cloud environment configuration analysis between the scanner and target resources. This intermediary layer translates cloud object metadata into safe, validated access instructions, mediating between accessibility testing needs and production environment stability requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If comprehensive network inspection is conducted to detect sensitive data, then security risk detection is improved, but network bandwidth consumption increases

Engineering Contradiction:
Improvesensitive data detection accuracyVSAvoidnetwork bandwidth consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent segments the network inspection process into discrete, targeted operations based on predefined cloud object paths. Instead of comprehensive brute-force scanning, the system divides inspection into specific segments corresponding to individual cloud objects and their accessible network paths, reducing overall bandwidth consumption while maintaining detection accuracy.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20250343808A1System and method for detecting sensitive data in active inspection of cloud computing resources
Publication Date: 2025.11.06 WIZ INC
  • US20250343808A1 patent drawing
  • US20250343808A1 patent drawing
  • US20250343808A1 patent drawing

AI summary

A system and method for performing active inspection of a cloud computing environment to detect exposed sensitive data. The method also includes receiving at least one network path to access a first resource, where the first resource is a cloud object deployed in the cloud computing environment, and potentially accessible from a network which is external to the cloud computing environment; and generating a first instruction to access the first resource based on a plurality of reachability parameters designated in the at least one network path; causing execution of the generated first instruction to access the first resource; receiving an output, the output generated in response to execution of the generated first instruction; detecting in the output a predetermined sensitive data indicator; and initiating a mitigation action in response to detecting the sensitive data indicator in the output.