Cloud Workload Malware Detection via SideScanning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing cloud security scanning systems are inefficient and resource-intensive, failing to provide comprehensive visibility and detection of vulnerabilities, malware, and misconfigurations within cloud workloads due to reliance on agents and scanners that require installation and network connectivity, leading to incomplete coverage and high operational costs.
Innovation Solution
The implementation of a 'SideScanning' technology that uses an out-of-band process to reach cloud workloads through the runtime storage layer, combining metadata from cloud provider APIs to provide instant-on, workload-level visibility without the need for agents or network scanners, enabling detection of risks and previously missed assets across all layers of cloud infrastructure.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If agents and scanners are installed on cloud workloads to detect security risks, then detection capabilities are improved, but device complexity and operational costs increase
Solution Approach 1:
The patent introduces a secondary system that acts as an intermediary to perform security scanning by mounting filesystem snapshots rather than installing agents directly on workloads. This mediator approach enables comprehensive security detection while avoiding the complexity of agent deployment and management across dynamic cloud environments.
Solution Approach 2:
The system creates a copy of the workload's filesystem through snapshots and mounts them on the secondary system for scanning. This copying mechanism allows thorough security inspection of the original workload without requiring any software installation or network connectivity on the target system, thereby maintaining detection capabilities while eliminating deployment complexity.
2Loss of information
If agents are deployed on cloud workloads for security scanning, then visibility into vulnerabilities is improved, but resource usage and operational costs increase
Solution Approach 1:
The scanning process is segmented into distinct phases: creating filesystem snapshots, mounting them on the secondary system, performing security scans, and cleaning up. This segmentation allows scanning operations to be performed on isolated copies rather than on the live workload, reducing resource contention and processor cycle usage on production systems while maintaining comprehensive security visibility.
Solution Approach 2:
The system performs security scanning through periodic snapshot creation and mounting operations rather than continuous agent-based monitoring. This periodic approach reduces overall resource consumption by concentrating scanning activities in discrete time windows while maintaining up-to-date security visibility across cloud workloads.
3Measurement precision
If authenticated scans are performed using privileged accounts to access cloud hosts, then detection accuracy is improved, but security risks and system resource usage increase
Solution Approach 1:
The secondary system serves as a secure intermediary that mounts filesystem snapshots for scanning without requiring privileged account access or port opening on the original workload. This eliminates the security risks associated with authenticated scans while maintaining detection accuracy by providing full filesystem access through the mounted snapshot copies.
4Object-affected harmful factors
If unauthenticated scans are performed to avoid security risks, then security exposure is reduced, but detection precision and coverage deteriorate
Solution Approach 1:
By creating and mounting filesystem snapshots as copies, the system enables comprehensive security scanning with full detection precision while avoiding security exposure. The snapshot copies provide complete filesystem access for thorough malware and vulnerability detection without requiring any network connectivity or privileged access to the original workload, thus achieving both high detection precision and minimal security exposure.
Data Source
AI summary
A cyber security system for a cloud environment is disclosed. In some embodiments, a method is disclosed. The method comprises utilizing a cloud provider API to access a block storage volume of a workload maintained on a target account in a target system of a cloud storage environment, utilizing a scanner at a location of the block storage volume and on a secondary system other than the target system, scanning the block storage volume for malicious code using the secondary system, identifying malicious code based on the scan, and outputting a notification of a presence of malicious code in the target system from the secondary system.


