Microsegmented Vulnerability Scanning via Active Probes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current vulnerability scanning in cloud data centers is time-intensive and disruptive, often requiring scheduled downtime due to centralized scanning methods that affect service availability and cannot efficiently scan microsegmented environments without impacting neighboring workloads.

Innovation Solution

Implementing a system with microsegmented environments that include hypervisors, enforcement points, and active probe devices for localized vulnerability scanning, allowing scans to be executed within each environment without network disruption, enabling real-time scanning and parallel processing across multiple hypervisors.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized vulnerability scanning is used, then comprehensive security coverage is achieved, but service availability deteriorates due to network disruption and downtime requirements

Engineering Contradiction:
Improveservice availabilityVSAvoidscanning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent divides the centralized scanning system into distributed scanning agents deployed across multiple microsegmented environments. Each agent performs localized vulnerability scanning within its assigned microsegment, eliminating the need for centralized network traversal and allowing parallel execution across segments. This segmentation enables continuous service availability while maintaining comprehensive security coverage.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If scheduled downtime is implemented for vulnerability scanning, then scanning thoroughness is improved, but productivity deteriorates due to service interruption

Engineering Contradiction:
Improvescanning thoroughnessVSAvoidservice productivity
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent implements continuous vulnerability scanning through distributed agents that operate in real-time within microsegmented environments. The scanning process continues without interruption during peak hours because each agent independently scans its local environment without affecting network traffic or service delivery. This maintains both scanning thoroughness and service productivity simultaneously.

Inventive Principle:
Principle #20Continuity of useful action

3Productivity

If parallel scanning across multiple hypervisors is implemented, then scanning speed is improved, but network complexity increases

Engineering Contradiction:
Improvescanning speedVSAvoidnetwork complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent manages parallel scanning across multiple hypervisors by segmenting the scanning workload into isolated microsegments. Each scanning agent operates independently within its assigned microsegment, and the security controller coordinates agents across segments without requiring complex inter-agent communication. This segmentation approach enables fast parallel scanning while keeping network management simple through policy-based control.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS9438634B1Microsegmented networks that implement vulnerability scanning
Publication Date: 2016.09.06 GRYPHO5 LLC
  • US9438634B1 patent drawing
  • US9438634B1 patent drawing
  • US9438634B1 patent drawing

AI summary

Systems for providing vulnerability scanning within distributed microservices are provided herein. In some embodiments, a system includes a plurality of microsegmented environments that each includes a hypervisor, an enforcement point that has an active probe device, and a plurality of virtual machines that each implements at least one microservice. The system also has a cloud data center server coupled with the plurality of microsegmented environments over a network. The cloud data center server has a security controller configured to provide a security policy to each of the plurality of microsegmented environments and an active probe controller configured to cause the active probe device of the plurality of microsegmented environments to execute a vulnerability scan.