Microsegmented Vulnerability Scanning via Active Probes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current vulnerability scanning in cloud data centers is time-intensive and disruptive, often requiring scheduled downtime due to centralized scanning methods that affect service availability and cannot efficiently scan microsegmented environments without impacting neighboring workloads.
Innovation Solution
Implementing a system with microsegmented environments that include hypervisors, enforcement points, and active probe devices for localized vulnerability scanning, allowing scans to be executed within each environment without network disruption, enabling real-time scanning and parallel processing across multiple hypervisors.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If centralized vulnerability scanning is used, then comprehensive security coverage is achieved, but service availability deteriorates due to network disruption and downtime requirements
Solution Approach 1:
The patent divides the centralized scanning system into distributed scanning agents deployed across multiple microsegmented environments. Each agent performs localized vulnerability scanning within its assigned microsegment, eliminating the need for centralized network traversal and allowing parallel execution across segments. This segmentation enables continuous service availability while maintaining comprehensive security coverage.
2Measurement precision
If scheduled downtime is implemented for vulnerability scanning, then scanning thoroughness is improved, but productivity deteriorates due to service interruption
Solution Approach 1:
The patent implements continuous vulnerability scanning through distributed agents that operate in real-time within microsegmented environments. The scanning process continues without interruption during peak hours because each agent independently scans its local environment without affecting network traffic or service delivery. This maintains both scanning thoroughness and service productivity simultaneously.
3Productivity
If parallel scanning across multiple hypervisors is implemented, then scanning speed is improved, but network complexity increases
Solution Approach 1:
The patent manages parallel scanning across multiple hypervisors by segmenting the scanning workload into isolated microsegments. Each scanning agent operates independently within its assigned microsegment, and the security controller coordinates agents across segments without requiring complex inter-agent communication. This segmentation approach enables fast parallel scanning while keeping network management simple through policy-based control.
Data Source
AI summary
Systems for providing vulnerability scanning within distributed microservices are provided herein. In some embodiments, a system includes a plurality of microsegmented environments that each includes a hypervisor, an enforcement point that has an active probe device, and a plurality of virtual machines that each implements at least one microservice. The system also has a cloud data center server coupled with the plurality of microsegmented environments over a network. The cloud data center server has a security controller configured to provide a security policy to each of the plurality of microsegmented environments and an active probe controller configured to cause the active probe device of the plurality of microsegmented environments to execute a vulnerability scan.


