Pre-Release Machine Image Scanning for Vulnerability Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Vulnerability assessment in machine images is typically performed after deployment, leaving systems vulnerable to attacks due to pre-existing vulnerabilities in machine instances for virtual environments.

Innovation Solution

A method for performing vulnerability scans on pre-release versions of machine images, involving a vulnerability management system that receives information from a software object development system, performs scans, and generates a report with scan results to be transmitted back to the development system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If vulnerability assessment is performed after deployment, then system deployment speed is improved, but system security is worsened due to pre-existing vulnerabilities

Engineering Contradiction:
Improvedeployment speedVSAvoidsystem security
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent applies preliminary action by performing vulnerability scans on machine images before they are deployed to production environments. The vulnerability management system scans pre-release machine images and provides reports to the software object development system, allowing vulnerabilities to be addressed prior to deployment. This resolves the contradiction by maintaining fast deployment speeds while ensuring security through advance vulnerability assessment.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If vulnerability scans are performed on pre-release machine images, then system security is improved, but development process complexity is worsened

Engineering Contradiction:
Improvesystem securityVSAvoiddevelopment process complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary approach by implementing a vulnerability management system that acts as a mediator between the software object development system and the deployment process. This system receives machine image information, performs vulnerability scans, and provides structured reports, thereby improving security without significantly complicating the development process. The intermediary system handles the complexity of vulnerability assessment centrally.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If vulnerability assessment is performed before release, then system security is improved, but deployment time is worsened

Engineering Contradiction:
Improvesystem securityVSAvoiddeployment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs vulnerability assessment as a preliminary action during the machine image build process before deployment. By scanning pre-release versions and providing feedback reports, the system identifies and addresses vulnerabilities early in the development cycle. This approach improves security while minimizing impact on deployment time, as the scanning occurs during the build phase rather than blocking the deployment phase.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12505224B2Vulnerability assessment of machine images in development phase
Publication Date: 2025.12.23 TENABLE INC
  • US12505224B2 patent drawing
  • US12505224B2 patent drawing
  • US12505224B2 patent drawing

AI summary

In an embodiment, a software object development system generates a pre-release version of a machine image of a software object, and transmits information associated with the pre-release version of the software object to a vulnerability management system. The vulnerability management system performs a vulnerability scan for known vulnerabilities(s) on the information associated with the pre-release version of the machine image of the software object. The vulnerability management system determines scan result(s) based on the vulnerability scan, and transmits, to the software object development system, a report comprising the scan result(s).