Mirror-Based Penetration Testing for Active Backup Validation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for testing production systems are inadequate as they often require deactivation of security measures, can cause system failure, and fail to identify vulnerabilities without disrupting the production environment.
Innovation Solution
A system and method for automated dynamic penetration testing on a mirror image of the production system, allowing for real-time replication and execution of system instructions without affecting the live system, using techniques like virtual machine mirroring, database replication, and dynamic scanning to identify vulnerabilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If penetration testing is performed on the production system, then security vulnerabilities can be identified, but system availability and security measures may be compromised
Solution Approach 1:
The patent creates a mirror copy of the production system that replicates its structure, files, and configuration. Penetration testing is performed on this mirror copy instead of the live production system, allowing thorough security validation without compromising system availability or triggering security alarms.
Solution Approach 2:
The mirror system acts as an intermediary between the testing process and the production system. It receives and executes test commands that would otherwise be directed at the production system, isolating the testing activities from the live environment while maintaining testing effectiveness.
2Measurement precision
If destructive testing is performed to identify vulnerabilities, then security defects can be detected, but system functionality may be disrupted
Solution Approach 1:
A mirror copy of the production system is created and maintained synchronously. Destructive and stress tests are executed on this mirror copy, allowing comprehensive vulnerability assessment and defect detection without any impact on the operational functionality of the production system.
Solution Approach 2:
The mirror system is prepared in advance as a testbed that mirrors the production environment. This preliminary setup allows aggressive testing to be performed beforehand or in parallel, so that security defects are identified before they could affect production operations.
3Productivity
If real-time testing is performed on the production system, then continuous security validation is achieved, but system performance may be degraded
Solution Approach 1:
The patent implements continuous replication of the production system to a mirror copy. This enables frequent or continuous penetration testing on the mirror without performance degradation to production, as the testing workload is completely isolated to the copied environment.
Solution Approach 2:
Testing can be performed periodically or continuously on the mirror system at intervals optimized for security validation needs, without imposing performance constraints on the production system. The mirror absorbs all testing overhead while staying synchronized with production state.
Data Source
AI summary
Systems and methods for verifying a production system automatically by testing a mirror copy of the production system on a testing computer. The system includes a mirror update transporter to deliver a mirror update from the production system to the mirror system, a mounting module to apply the mirror update to the mirror system, a testing computer on which the mirror system is running, a testing module to automatically execute a set of tests on the mirror system, and a communication module to communicate the results of the tests.


