Cloud Resource Exposure Detection via Authorization-Based Active Inspection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing active scanning technologies for detecting exposure in cloud environments generate excessive network traffic, potentially causing congestion and malfunctions, and do not provide clear reasons for access success or failure.

Innovation Solution

A method for authorization-based active inspection of network paths for cloud resources, which involves receiving network paths, actively inspecting them to determine accessibility and authorization requirements, and generating access instructions to test these paths.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If active scanning is used to discover external attack surface, then vulnerability detection capability is improved, but network traffic volume increases causing congestion and potential malfunctions

Engineering Contradiction:
Improvevulnerability detection capabilityVSAvoidnetwork traffic volume
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The system performs preliminary identification of network paths and resources before conducting active scanning. By pre-mapping the network topology and identifying accessible resources through authorization-based inspection, the system avoids random probing that generates excessive traffic. The scanning process is guided by pre-established knowledge of the network structure, reducing unnecessary traffic while maintaining detection effectiveness.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces an intermediary authorization-based inspection mechanism between the scanner and target resources. Instead of direct active scanning that generates high traffic, the intermediary process first determines accessibility and authorization requirements, then guides subsequent scanning actions. This intermediary layer filters and directs traffic efficiently, preventing network congestion while maintaining vulnerability detection capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Adaptability or versatility

If active scanning attempts random domains and ports, then exposure detection coverage is improved, but network resource consumption increases

Engineering Contradiction:
Improveexposure detection coverageVSAvoidnetwork resource consumption
Core Design Contradiction:
Adaptability or versatilityVSUse of energy by moving object

Solution Approach 1:

The system applies local quality by tailoring the scanning approach to specific network paths and resources based on their authorization requirements. Instead of uniform random scanning across all domains and ports, the system adapts its scanning behavior to local network characteristics and access control mechanisms, optimizing resource usage while maintaining comprehensive coverage where needed.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically changes scanning parameters such as target selection, probe types, and inspection depth based on authorization-based accessibility determination. By adjusting these parameters according to network path characteristics and resource types, the system achieves comprehensive exposure detection coverage while minimizing network resource consumption through intelligent parameter adaptation.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If traditional active scanning is used, then accessibility testing is performed, but clear reasons for access success or failure are not provided

Engineering Contradiction:
Improveaccessibility testingVSAvoidaccess reason information
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system implements feedback mechanisms that provide detailed information about access success or failure reasons. The authorization-based inspection process collects and reports specific information about why certain paths are accessible or blocked, including authorization requirements, network path characteristics, and resource accessibility status. This feedback loop eliminates information loss by delivering actionable insights to users.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS20250202898A1Techniques for detecting resources without authentication using exposure analysis
Publication Date: 2025.06.19 WIZ INC
  • US20250202898A1 patent drawing
  • US20250202898A1 patent drawing
  • US20250202898A1 patent drawing

AI summary

A system and method for performing authorization based active inspection of network paths for a resource, deployed in a cloud computing environment, includes receiving at least one network path to access the resource, wherein the resource is a cloud object deployed in the cloud computing environment, and potentially accessible from a network which is external to the cloud computing environment; and actively inspecting the at least one network path to determine if the resource is accessible through the at least one network path from a network external to the cloud computing environment and requires access authorization.