Cloud Workload Vulnerability Scanning via Inspectable Disk Copies

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current solutions for cloud workload vulnerability scanning are inefficient and incomplete, as they often require specialized agents that fail to scan containers and serverless applications, and snapshot-based scanning is limited in multi-tenant systems and complex cloud structures.

Innovation Solution

A method that generates an inspectable disk from a workload in a computing environment with applicable cybersecurity policies, detects cybersecurity objects, generates policy exceptions, and represents workloads and environments in a security database to apply policy exceptions across associated workloads and environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If agent-based scanning tools are deployed to scan cloud workloads, then vulnerability detection capability is improved, but device complexity and operational overhead increase

Engineering Contradiction:
Improvevulnerability detection capabilityVSAvoidoperational overhead
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent creates disk images (copies) of cloud storage volumes and analyzes them in isolated environments rather than deploying agents on production systems. This copying approach enables vulnerability scanning without the operational overhead of agent deployment, maintenance, and management on live systems.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The scanning process is segmented into distinct phases: creating disk images, mounting them in isolated environments, performing vulnerability analysis, and reporting results. This segmentation allows the scanning function to be separated from production systems, reducing operational complexity while maintaining detection capability.

Inventive Principle:
Principle #1Segmentation

2Device complexity

If snapshot-based scanning is used to scan cloud workloads, then agent deployment complexity is reduced, but applicability to multi-tenant systems and complex cloud structures is limited

Engineering Contradiction:
Improveagent deployment complexityVSAvoidapplicability to multi-tenant systems
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent creates a universal scanning platform that can analyze disk images from multiple cloud providers (AWS, Azure, GCP) and various workload types (containers, serverless, traditional applications) through a single isolated environment approach. This multi-functional capability extends applicability to multi-tenant systems and complex cloud structures without requiring provider-specific agents.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces disk images as an intermediary between the cloud workload and the vulnerability scanner. These images serve as a neutral medium that can be created from any cloud provider's storage volumes and analyzed in an isolated environment, bridging the gap between diverse cloud structures and the scanning platform.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If comprehensive vulnerability scanning is performed across all cloud environments, then security coverage is improved, but scanning time and resource consumption increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidscanning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by creating disk images and mounting them in isolated environments before actual vulnerability analysis begins. This preparation work is done upfront, allowing the scanning process to proceed efficiently without delays during the actual analysis phase, thus reducing overall scanning time while maintaining comprehensive coverage.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20250094208A1Detecting security exceptions across multiple compute environments
Publication Date: 2025.03.20 WIZ INC
  • US20250094208A1 patent drawing
  • US20250094208A1 patent drawing
  • US20250094208A1 patent drawing

AI summary

A system and method for applying cybersecurity policies across multiple computing environments is presented. The method includes: generating an inspectable disk from a disk of a first workload deployed in a first computing environment, the computing environment including a cybersecurity policy applicable to a cybersecurity object; detecting the cybersecurity object on the inspectable disk; generating a policy exception; generating a representation of the cybersecurity object and the first workload in a security database, wherein the security database includes a representation of the first computing environment and a representation of a second computing environment which is associated with the first computing environment; detecting in the representation of the second computing environment a representation of a second workload associated with the representation of the first workload; and applying the policy exception to the second workload based on detecting that the second workload is associated with the first workload.