Cloud Workload Security via Agentless and Agent Collaboration
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current cloud workload protection systems face challenges in providing real-time detection, prevention, and remediation of security threats without disrupting business operations or impacting system performance.
Innovation Solution
The proposed solution combines agentless scanning technology, such as SideScanning, with agents to provide a collaborative method for real-time detection, prevention, and remediation. This involves periodic scans by agentless technology and real-time monitoring by agents, with agents performing active remediation actions.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If agents are used for cloud workload protection, then real-time detection and remediation capabilities are improved, but system complexity and maintenance requirements increase
Solution Approach 1:
The system segments protection functions into two distinct components: agentless scanners for periodic comprehensive scanning and agents for real-time monitoring. This segmentation allows each component to specialize in specific functions, reducing the complexity burden on any single system element while maintaining overall effectiveness.
Solution Approach 2:
The cloud provider's native APIs serve as intermediaries between the security system and cloud workloads. Instead of requiring direct installation and management of agents on all workloads, the system uses these APIs to facilitate communication and data exchange, thereby reducing system complexity and maintenance requirements.
2Ease of operation
If agentless scanning is used, then ease of deployment and system performance are improved, but real-time detection and prevention capabilities are reduced
Solution Approach 1:
The system divides security functions between agentless scanning (for ease of deployment and performance) and agents (for real-time detection). By segmenting these functions, the system can leverage the advantages of both approaches without compromising either ease of operation or real-time response capability.
Solution Approach 2:
The system merges agentless scanning and agent-based monitoring into a unified security architecture where both components work together. The agentless scanner provides comprehensive periodic scanning while agents provide real-time monitoring, and their combined output feeds into the remediation system, achieving both ease of deployment and real-time detection capabilities.
3Measurement precision
If comprehensive security scanning is performed, then detection accuracy is improved, but processing time and system resources increase
Solution Approach 1:
The system segments scanning operations into periodic comprehensive scans (agentless) and continuous monitoring (agents). This segmentation allows deep, accurate scanning to be performed periodically without continuously consuming system resources, thereby maintaining detection accuracy while reducing overall processing time and resource consumption.
Solution Approach 2:
The agentless scanning component performs comprehensive security scans at periodic intervals rather than continuously. This periodic action allows the system to allocate substantial processing resources for thorough scanning during scheduled windows while operating more lightly during continuous operation, thus balancing detection accuracy with processing time and resource consumption.
Data Source
AI summary
Embodiments of the present disclosure include a non-transitory computer readable medium that when executed by at least one processor cause the at least one processor to perform operations for dynamic cloud workload protection, the operations comprising: installing an agentless scanning system, the agentless scanning system being configured to scan a cloud server, the cloud server including a network and a memory; detecting, using a cloud provider application program interface (API), an installation of a new workload in the cloud server, the new workload including disks; scanning, using the agentless scanning system, the disks of the new workload; installing an agent on the new workload; monitoring, using the agent, the disks, the network, and the memory of the new workload; generating, using the agent, a notification when an interesting event occurs; scanning, using the agentless scanning system, the cloud server; and generating at least one command to perform one or more of a remediation or a policy update.


