Segmented Network Scanning with Active Probes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current vulnerability scanning in cloud data centers is time-intensive and disruptive, often requiring services to be taken offline, as centralized scanners must traverse the entire network, limiting parallel scanning and causing network disruptions, which can only be performed during non-peak times.

Innovation Solution

Implementing active probe devices within microsegmented environments, allowing for parallel and on-demand scanning without affecting neighboring workloads, as enforcement points intercept and analyze traffic directly within the secure virtual boundary, enabling real-time detection and remediation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized scanners traverse the entire network to perform vulnerability scanning, then comprehensive security assessment is achieved, but scanning time increases and network disruption occurs

Engineering Contradiction:
Improvesecurity assessment completenessVSAvoidscanning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the network into multiple microsegmented environments with individual enforcement points. Each enforcement point performs scanning locally within its segment, eliminating the need for centralized scanners to traverse the entire network. This segmentation enables parallel scanning across segments, reducing total scanning time while maintaining comprehensive security assessment.

Inventive Principle:
Principle #1Segmentation

2Reliability

If centralized scanners traverse the entire network, then comprehensive vulnerability detection is achieved, but network disruption and congestion occur

Engineering Contradiction:
Improvevulnerability detection accuracyVSAvoidnetwork disruption
Core Design Contradiction:
ReliabilityVSObject-generated harmful factors

Solution Approach 1:

By dividing the network into isolated microsegments with enforcement points at each segment boundary, the patent enables local scanning that generates minimal network traffic. Each enforcement point scans only its local segment, preventing network congestion and disruption while maintaining accurate vulnerability detection through comprehensive local assessment.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If services are taken offline for scanning, then accurate vulnerability assessment is achieved, but service availability decreases

Engineering Contradiction:
Improvevulnerability assessment accuracyVSAvoidservice availability
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent implements continuous background scanning at enforcement points that operates proactively without requiring services to be taken offline. Vulnerability assessments are performed continuously in the background, enabling real-time detection and remediation while maintaining service availability and productivity.

Inventive Principle:
Principle #10Preliminary action

4Device complexity

If parallel scanning is limited by centralized architecture, then network management is simplified, but scanning efficiency decreases

Engineering Contradiction:
Improvenetwork management complexityVSAvoidscanning efficiency
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The patent distributes scanning capabilities to enforcement points at each microsegment, enabling parallel scanning across multiple segments simultaneously. This segmentation approach dramatically improves scanning efficiency while the centralized security controller maintains simplified management by coordinating enforcement points and consolidating scan results.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10110636B2Segmented networks that implement scanning
Publication Date: 2018.10.23 GRYPHO5 LLC
  • US10110636B2 patent drawing
  • US10110636B2 patent drawing
  • US10110636B2 patent drawing

AI summary

Systems for providing scanning within distributed services are provided herein. In some embodiments, a system includes a plurality of segmented environments that each includes an enforcement point that has an active probe device, and a plurality of workloads that each implements at least one service. The system also has a data center server coupled with the plurality of segmented environments over a network. The data center server has a security controller configured to provide a security policy to each of the plurality of segmented environments and an active probe controller configured to cause the active probe device of the plurality of segmented environments to execute a scan.