Pre-Release Machine Image Scanning for Vulnerability Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Vulnerability assessment in machine images is typically performed after deployment, leaving systems vulnerable to attacks due to pre-existing vulnerabilities in machine instances for virtual environments.
Innovation Solution
A method for performing vulnerability scans on pre-release versions of machine images, involving a vulnerability management system that receives information from a software object development system, performs scans, and generates a report with scan results to be transmitted back to the development system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If vulnerability assessment is performed after deployment, then system deployment speed is improved, but system security is worsened due to pre-existing vulnerabilities
Solution Approach 1:
The patent applies preliminary action by performing vulnerability scans on machine images before they are deployed to production environments. The vulnerability management system scans pre-release machine images and provides reports to the software object development system, allowing vulnerabilities to be addressed prior to deployment. This resolves the contradiction by maintaining fast deployment speeds while ensuring security through advance vulnerability assessment.
2Reliability
If vulnerability scans are performed on pre-release machine images, then system security is improved, but development process complexity is worsened
Solution Approach 1:
The patent introduces an intermediary approach by implementing a vulnerability management system that acts as a mediator between the software object development system and the deployment process. This system receives machine image information, performs vulnerability scans, and provides structured reports, thereby improving security without significantly complicating the development process. The intermediary system handles the complexity of vulnerability assessment centrally.
3Reliability
If vulnerability assessment is performed before release, then system security is improved, but deployment time is worsened
Solution Approach 1:
The patent performs vulnerability assessment as a preliminary action during the machine image build process before deployment. By scanning pre-release versions and providing feedback reports, the system identifies and addresses vulnerabilities early in the development cycle. This approach improves security while minimizing impact on deployment time, as the scanning occurs during the build phase rather than blocking the deployment phase.
Data Source
AI summary
In an embodiment, a software object development system generates a pre-release version of a machine image of a software object, and transmits information associated with the pre-release version of the software object to a vulnerability management system. The vulnerability management system performs a vulnerability scan for known vulnerabilities(s) on the information associated with the pre-release version of the machine image of the software object. The vulnerability management system determines scan result(s) based on the vulnerability scan, and transmits, to the software object development system, a report comprising the scan result(s).


