Cloud Workload Security via Agentless and Agent Collaboration

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cloud workload protection systems face challenges in providing real-time detection, prevention, and remediation of security threats without disrupting business operations or impacting system performance.

Innovation Solution

The proposed solution combines agentless scanning technology, such as SideScanning, with agents to provide a collaborative method for real-time detection, prevention, and remediation. This involves periodic scans by agentless technology and real-time monitoring by agents, with agents performing active remediation actions.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If agents are used for cloud workload protection, then real-time detection and remediation capabilities are improved, but system complexity and maintenance requirements increase

Engineering Contradiction:
Improvereal-time detection and remediation capabilityVSAvoidsystem complexity and maintenance requirements
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system segments protection functions into two distinct components: agentless scanners for periodic comprehensive scanning and agents for real-time monitoring. This segmentation allows each component to specialize in specific functions, reducing the complexity burden on any single system element while maintaining overall effectiveness.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The cloud provider's native APIs serve as intermediaries between the security system and cloud workloads. Instead of requiring direct installation and management of agents on all workloads, the system uses these APIs to facilitate communication and data exchange, thereby reducing system complexity and maintenance requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Ease of operation

If agentless scanning is used, then ease of deployment and system performance are improved, but real-time detection and prevention capabilities are reduced

Engineering Contradiction:
Improveease of deployment and system performanceVSAvoidreal-time detection and prevention capability
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The system divides security functions between agentless scanning (for ease of deployment and performance) and agents (for real-time detection). By segmenting these functions, the system can leverage the advantages of both approaches without compromising either ease of operation or real-time response capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system merges agentless scanning and agent-based monitoring into a unified security architecture where both components work together. The agentless scanner provides comprehensive periodic scanning while agents provide real-time monitoring, and their combined output feeds into the remediation system, achieving both ease of deployment and real-time detection capabilities.

Inventive Principle:
Principle #5Merging (Combining)

3Measurement precision

If comprehensive security scanning is performed, then detection accuracy is improved, but processing time and system resources increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidprocessing time and system resources
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system segments scanning operations into periodic comprehensive scans (agentless) and continuous monitoring (agents). This segmentation allows deep, accurate scanning to be performed periodically without continuously consuming system resources, thereby maintaining detection accuracy while reducing overall processing time and resource consumption.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The agentless scanning component performs comprehensive security scans at periodic intervals rather than continuously. This periodic action allows the system to allocate substantial processing resources for thorough scanning during scheduled windows while operating more lightly during continuous operation, thus balancing detection accuracy with processing time and resource consumption.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS20250080574A1Systems and methods of agent and agentless collaboration in cloud infrastructure security
Publication Date: 2025.03.06 ORCA SECURITY LTD
  • US20250080574A1 patent drawing
  • US20250080574A1 patent drawing
  • US20250080574A1 patent drawing

AI summary

Embodiments of the present disclosure include a non-transitory computer readable medium that when executed by at least one processor cause the at least one processor to perform operations for dynamic cloud workload protection, the operations comprising: installing an agentless scanning system, the agentless scanning system being configured to scan a cloud server, the cloud server including a network and a memory; detecting, using a cloud provider application program interface (API), an installation of a new workload in the cloud server, the new workload including disks; scanning, using the agentless scanning system, the disks of the new workload; installing an agent on the new workload; monitoring, using the agent, the disks, the network, and the memory of the new workload; generating, using the agent, a notification when an interesting event occurs; scanning, using the agentless scanning system, the cloud server; and generating at least one command to perform one or more of a remediation or a policy update.