Local Containerized Cloud Scanners for Real-Time Security Visibility

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in understanding and securing the data posture and access to sensitive data stored in cloud environments, as existing security infrastructures often fail to provide real-time visibility and control over data access, making it difficult to identify and remediate security vulnerabilities.

Innovation Solution

A cloud security posture analysis system that deploys serverless, containerized scanners locally within the cloud account to scan and analyze storage resources, identifying data patterns, access paths, and vulnerabilities, providing real-time visibility and control without extracting sensitive data, and generating metadata for analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If traditional cloud security scanning methods are used, then centralized control is maintained, but real-time visibility and detection speed are insufficient

Engineering Contradiction:
Improvedetection speedVSAvoidsystem architecture complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent segments the security scanning function by deploying multiple independent containerized scanners distributed across different cloud accounts and regions. Each scanner operates autonomously to scan its assigned storage resources, enabling parallel processing and real-time detection without requiring centralized control for every scanning operation. This segmentation resolves the contradiction by improving detection speed through distributed parallel scanning while maintaining manageable complexity through standardized containerized units.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transitions from a single centralized scanning dimension to a multi-dimensional distributed scanning architecture. Scanners are deployed across multiple cloud accounts, regions, and storage resources simultaneously, adding spatial and temporal dimensions to the scanning process. This dimensional expansion enables real-time visibility across the entire cloud environment while the containerized nature keeps each individual scanner unit simple and manageable.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If comprehensive data scanning is performed, then security coverage is improved, but data extraction and processing load increase

Engineering Contradiction:
Improvesecurity coverageVSAvoiddata volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts only the essential scanning and analysis functions from the data itself, performing security assessments without extracting or moving the actual sensitive data. The containerized scanners read metadata and perform pattern matching locally within the cloud environment, extracting only the security-relevant information needed for analysis while leaving the bulk of the data intact in its original storage locations. This approach improves security coverage through comprehensive scanning while minimizing data processing load.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces containerized scanners as intermediary components between the storage resources and the central management system. These intermediaries perform the heavy lifting of pattern matching and vulnerability detection locally, acting as a buffer that prevents direct processing of large volumes of sensitive data. The scanners serve as mediators that translate raw storage content into actionable security insights without requiring extensive data extraction or transfer.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If multiple scanners are deployed, then scanning throughput is improved, but coordination and management complexity increases

Engineering Contradiction:
Improvescanning throughputVSAvoidscanner management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent standardizes scanner deployment by changing the parameters of containerization, allowing multiple scanners to be instantiated with consistent configurations across different cloud environments. Each scanner unit has identical resource requirements, execution parameters, and operational characteristics, enabling automated deployment and management. This parameter standardization improves throughput through parallel scanning while preventing management complexity through uniformity and automation.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The containerized scanners are designed to be self-managing units that automatically scan their assigned storage resources, report findings, and update security postures without requiring manual intervention or complex coordination. Each scanner independently manages its own execution, error handling, and result reporting, transforming the management of multiple scanners from a complex centralized task to a simple deployment and monitoring process. This self-service capability enables high throughput while keeping management straightforward.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS20250280016A1Cloud content scanning using locally deployed containerized scanners
Publication Date: 2025.09.04 GOLDMAN SACHS BANK USA
  • US20250280016A1 patent drawing
  • US20250280016A1 patent drawing
  • US20250280016A1 patent drawing

AI summary

The technology disclosed herein relates to streamlined analysis of security posture of a cloud environment. In particular, the technology relates to computer-implemented method of content scanning that includes obtaining access to a cloud environment account for content scanning of storage resources, queuing objects in the cloud environment account, partitioning the objects into a number of object chunks, and initializing a number of serverless, containerized scanners based on the number of object chunks. Each serverless, containerized scanner, of the number of serverless, containerized scanners, is deployed locally on the cloud environment account and scans a corresponding object chunk to detect a plurality of different data patterns. The number of object chunks is at least one hundred times the number of serverless, containerized scanners.