Cloud Workload Malware Detection via SideScanning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cloud security scanning systems are inefficient and resource-intensive, failing to provide comprehensive visibility and detection of vulnerabilities, malware, and misconfigurations within cloud workloads due to reliance on agents and scanners that require installation and network connectivity, leading to incomplete coverage and high operational costs.

Innovation Solution

The implementation of a 'SideScanning' technology that uses an out-of-band process to reach cloud workloads through the runtime storage layer, combining metadata from cloud provider APIs to provide instant-on, workload-level visibility without the need for agents or network scanners, enabling detection of risks and previously missed assets across all layers of cloud infrastructure.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If agents and scanners are installed on cloud workloads to detect security risks, then detection capabilities are improved, but device complexity and operational costs increase

Engineering Contradiction:
Improvedetection capabilitiesVSAvoidagent installation complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a secondary system that acts as an intermediary to perform security scanning by mounting filesystem snapshots rather than installing agents directly on workloads. This mediator approach enables comprehensive security detection while avoiding the complexity of agent deployment and management across dynamic cloud environments.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates a copy of the workload's filesystem through snapshots and mounts them on the secondary system for scanning. This copying mechanism allows thorough security inspection of the original workload without requiring any software installation or network connectivity on the target system, thereby maintaining detection capabilities while eliminating deployment complexity.

Inventive Principle:
Principle #26Copying

2Loss of information

If agents are deployed on cloud workloads for security scanning, then visibility into vulnerabilities is improved, but resource usage and operational costs increase

Engineering Contradiction:
Improvesecurity visibilityVSAvoidprocessor cycles for scanning
Core Design Contradiction:
Loss of informationVSUse of energy by moving object

Solution Approach 1:

The scanning process is segmented into distinct phases: creating filesystem snapshots, mounting them on the secondary system, performing security scans, and cleaning up. This segmentation allows scanning operations to be performed on isolated copies rather than on the live workload, reducing resource contention and processor cycle usage on production systems while maintaining comprehensive security visibility.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs security scanning through periodic snapshot creation and mounting operations rather than continuous agent-based monitoring. This periodic approach reduces overall resource consumption by concentrating scanning activities in discrete time windows while maintaining up-to-date security visibility across cloud workloads.

Inventive Principle:
Principle #19Periodic action

3Measurement precision

If authenticated scans are performed using privileged accounts to access cloud hosts, then detection accuracy is improved, but security risks and system resource usage increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidsecurity risks from port opening
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The secondary system serves as a secure intermediary that mounts filesystem snapshots for scanning without requiring privileged account access or port opening on the original workload. This eliminates the security risks associated with authenticated scans while maintaining detection accuracy by providing full filesystem access through the mounted snapshot copies.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Object-affected harmful factors

If unauthenticated scans are performed to avoid security risks, then security exposure is reduced, but detection precision and coverage deteriorate

Engineering Contradiction:
Improvesecurity exposureVSAvoiddetection precision
Core Design Contradiction:
Object-affected harmful factorsVSMeasurement precision

Solution Approach 1:

By creating and mounting filesystem snapshots as copies, the system enables comprehensive security scanning with full detection precision while avoiding security exposure. The snapshot copies provide complete filesystem access for thorough malware and vulnerability detection without requiring any network connectivity or privileged access to the original workload, thus achieving both high detection precision and minimal security exposure.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11943251B2Systems and methods for malware detection
Publication Date: 2024.03.26 ORCA SECURITY LTD
  • US11943251B2 patent drawing
  • US11943251B2 patent drawing
  • US11943251B2 patent drawing

AI summary

A cyber security system for a cloud environment is disclosed. In some embodiments, a method is disclosed. The method comprises utilizing a cloud provider API to access a block storage volume of a workload maintained on a target account in a target system of a cloud storage environment, utilizing a scanner at a location of the block storage volume and on a secondary system other than the target system, scanning the block storage volume for malicious code using the secondary system, identifying malicious code based on the scan, and outputting a notification of a presence of malicious code in the target system from the secondary system.