Segmented Network Scanning with Active Probes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current vulnerability scanning in cloud data centers is time-intensive and disruptive, often requiring services to be taken offline, as centralized scanners must traverse the entire network, limiting parallel scanning and causing network disruptions, which can only be performed during non-peak times.
Innovation Solution
Implementing active probe devices within microsegmented environments, allowing for parallel and on-demand scanning without affecting neighboring workloads, as enforcement points intercept and analyze traffic directly within the secure virtual boundary, enabling real-time detection and remediation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If centralized scanners traverse the entire network to perform vulnerability scanning, then comprehensive security assessment is achieved, but scanning time increases and network disruption occurs
Solution Approach 1:
The patent segments the network into multiple microsegmented environments with individual enforcement points. Each enforcement point performs scanning locally within its segment, eliminating the need for centralized scanners to traverse the entire network. This segmentation enables parallel scanning across segments, reducing total scanning time while maintaining comprehensive security assessment.
2Reliability
If centralized scanners traverse the entire network, then comprehensive vulnerability detection is achieved, but network disruption and congestion occur
Solution Approach 1:
By dividing the network into isolated microsegments with enforcement points at each segment boundary, the patent enables local scanning that generates minimal network traffic. Each enforcement point scans only its local segment, preventing network congestion and disruption while maintaining accurate vulnerability detection through comprehensive local assessment.
3Measurement precision
If services are taken offline for scanning, then accurate vulnerability assessment is achieved, but service availability decreases
Solution Approach 1:
The patent implements continuous background scanning at enforcement points that operates proactively without requiring services to be taken offline. Vulnerability assessments are performed continuously in the background, enabling real-time detection and remediation while maintaining service availability and productivity.
4Device complexity
If parallel scanning is limited by centralized architecture, then network management is simplified, but scanning efficiency decreases
Solution Approach 1:
The patent distributes scanning capabilities to enforcement points at each microsegment, enabling parallel scanning across multiple segments simultaneously. This segmentation approach dramatically improves scanning efficiency while the centralized security controller maintains simplified management by coordinating enforcement points and consolidating scan results.
Data Source
AI summary
Systems for providing scanning within distributed services are provided herein. In some embodiments, a system includes a plurality of segmented environments that each includes an enforcement point that has an active probe device, and a plurality of workloads that each implements at least one service. The system also has a data center server coupled with the plurality of segmented environments over a network. The data center server has a security controller configured to provide a security policy to each of the plurality of segmented environments and an active probe controller configured to cause the active probe device of the plurality of segmented environments to execute a scan.


