Pinned Vulnerability Scanner for Virtual Machine Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In virtualized computing networks, administrators face challenges in dynamically receiving updates and performing vulnerability scans across virtual machines, leading to security risks and vulnerabilities that can impact multiple devices or resources, with existing systems lacking real-time security risk assessments and effective remediation.

Innovation Solution

A virtual asset tool interfaces with a virtualization manager to receive updates and metadata, pinning a vulnerability scanner to each physical machine to scan virtual machines for vulnerabilities, allowing for quick identification and remediation of security issues without network packet transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If vulnerability scanners are deployed across virtual machine networks to scan for security vulnerabilities, then security risk detection capability is improved, but network traffic increases and scanning speed decreases due to packet transmission requirements

Engineering Contradiction:
Improvesecurity risk detection capabilityVSAvoidscanning speed
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent extracts the vulnerability scanning function from the virtual machine network environment and relocates it to the physical host machine. By running the vulnerability scanner on the physical machine rather than through the virtual machine network, the system eliminates network packet transmission requirements, thereby maintaining security detection capability while significantly improving scanning speed and reducing network traffic.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a virtual asset tool as an intermediary component that bridges the vulnerability scanner and the virtual machine portfolio. This intermediary manages the scanning process by receiving updates about virtual machine changes, orchestrating scans on the physical host, and processing results, thereby enabling efficient local scanning without network overhead while maintaining comprehensive security coverage.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If vulnerability scanners are deployed across virtual machine networks, then comprehensive security coverage is improved, but network complexity and traffic overhead increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidnetwork complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent extracts the vulnerability scanning operation from the complex virtual machine network environment and consolidates it on the physical host machine. This eliminates the need for network packet transmission through virtual switches and physical networks, thereby reducing network complexity and traffic overhead while maintaining comprehensive security coverage through the virtual asset tool's coordination.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent makes the physical host machine serve multiple functions: it continues to run the hypervisor and manage virtual machines while also hosting the vulnerability scanner. The virtual asset tool provides universal coordination across multiple physical machines and virtual machine portfolios. This multi-functionality reduces overall system complexity by eliminating dedicated scanning infrastructure and network communication requirements.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If dynamic updates to virtual machines are implemented, then adaptability to security changes is improved, but difficulty in tracking and scanning updates increases

Engineering Contradiction:
Improveadaptability to security changesVSAvoidtracking complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements a feedback mechanism where the virtual asset tool subscribes to updates from virtualization managers about virtual machine changes. When updates occur, the system receives notifications, processes the change information, and automatically triggers appropriate vulnerability scanning actions. This feedback loop enables the system to adapt dynamically to security changes while automatically tracking updates, thereby reducing tracking complexity.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent performs preliminary actions by having the virtual asset tool continuously monitor and track virtual machine updates through subscriptions to virtualization managers. Before vulnerability scanning is needed, the system already has current information about virtual machine changes, enabling rapid response to security updates without complex tracking during the scanning process itself.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10437620B2Pinned vulnerability scanner for scanning virtual machines on a single machine
Publication Date: 2019.10.08 RAPID7 INC
  • US10437620B2 patent drawing
  • US10437620B2 patent drawing
  • US10437620B2 patent drawing

AI summary

Embodiments described herein relate to systems and methods for identifying virtual machines in a network. The systems and methods comprise a virtual asset tool that can interface with a virtualization manager to receive metadata identifying virtual machines hosted by a plurality of physical machines. The virtual asset tool can subscribe to updates associated with the virtual machines, such as changes to the virtual machines, or additions or deletions of virtual machines. In response to receiving an update, the virtual asset tool can modify an asset record associated with the virtual machines and any corresponding descriptions. In embodiments, the virtual asset tool can schedule vulnerability scans for any or all of the virtual machines.