Cloud Resource Inspection Paths for Low-Traffic Sensitive Data Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing active scanning methods for detecting vulnerabilities in cloud computing environments generate excessive network traffic, risking congestion and service disruptions, which is detrimental to maintaining a production environment's operational state.
Innovation Solution
A method and system for active inspection of cloud environments that utilize network paths and reachability parameters to access resources, detect sensitive data indicators, and initiate mitigation actions, employing techniques like optical character recognition and security graph updates to minimize exposure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If active scanning is used to discover external attack surface, then vulnerability detection capability is improved, but network traffic volume increases causing congestion and service disruptions
Solution Approach 1:
The patent extracts the essential inspection function from traditional active scanning by using predefined network paths and reachability parameters. Instead of sending random packets across the entire network, the system extracts only the necessary paths to reach cloud objects, significantly reducing network traffic while maintaining vulnerability detection capability.
Solution Approach 2:
The system performs preliminary actions by pre-defining network paths and reachability parameters before actual inspection. The cloud environment configuration is analyzed in advance to identify valid access paths, so that subsequent vulnerability scanning only traverses known legitimate routes, avoiding random traffic that causes congestion.
2Ease of operation
If random port scanning is performed to access network resources, then accessibility testing is improved, but risk of service disruption increases
Solution Approach 1:
The patent applies local quality by making the inspection process adaptive to specific cloud object configurations. Instead of uniform random scanning across all ports, the system tailors inspection to each cloud object's actual network path and reachability parameters, testing only relevant accessibility while avoiding disruption to production services.
Solution Approach 2:
The system introduces an intermediary layer of cloud environment configuration analysis between the scanner and target resources. This intermediary layer translates cloud object metadata into safe, validated access instructions, mediating between accessibility testing needs and production environment stability requirements.
3Measurement precision
If comprehensive network inspection is conducted to detect sensitive data, then security risk detection is improved, but network bandwidth consumption increases
Solution Approach 1:
The patent segments the network inspection process into discrete, targeted operations based on predefined cloud object paths. Instead of comprehensive brute-force scanning, the system divides inspection into specific segments corresponding to individual cloud objects and their accessible network paths, reducing overall bandwidth consumption while maintaining detection accuracy.
Data Source
AI summary
A system and method for performing active inspection of a cloud computing environment to detect exposed sensitive data. The method also includes receiving at least one network path to access a first resource, where the first resource is a cloud object deployed in the cloud computing environment, and potentially accessible from a network which is external to the cloud computing environment; and generating a first instruction to access the first resource based on a plurality of reachability parameters designated in the at least one network path; causing execution of the generated first instruction to access the first resource; receiving an output, the output generated in response to execution of the generated first instruction; detecting in the output a predetermined sensitive data indicator; and initiating a mitigation action in response to detecting the sensitive data indicator in the output.


