Virtual Asset Tool Vulnerability Scanning on Virtual Machines

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

In virtualized computing networks, administrators face challenges in managing and securing virtual machines due to dynamic environments, resource limitations, and increased security risks, including vulnerabilities in hypervisors that can impact multiple devices or resources, with existing systems lacking real-time updates and effective vulnerability scanning capabilities.

Innovation Solution

A virtual asset tool interfaces with a virtualization manager to receive updates and metadata, automatically schedules vulnerability scans by instantiating a scanner on each physical machine, which scans virtual machines for vulnerabilities and provides results to the tool for remediation, thereby ensuring timely updates and security assessments without network packet transmission.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If vulnerability scans are performed on virtual machines in a virtualized network, then security risks and vulnerabilities can be detected, but network traffic and packet transmission increase

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidnetwork packet transmission
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent creates a virtual copy of the vulnerability scanner that runs inside the virtual machine itself rather than scanning from outside the virtualized environment. This virtual scanner copy performs all scanning operations locally without generating network traffic, eliminating the need for packet transmission while maintaining full security detection capabilities

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The virtual scanner acts as an intermediary component that bridges the gap between security assessment needs and network efficiency requirements. By embedding the scanner within the virtual machine environment, it mediates between the need for external security validation and the desire to minimize network overhead, performing scans without external network communication

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If multiple virtual machines are hosted on a single physical machine, then resource utilization increases, but managing and securing all virtual machines becomes more complex

Engineering Contradiction:
Improveresource utilizationVSAvoidvirtualization management complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

Each virtual machine is equipped with its own virtual scanner instance that autonomously performs vulnerability assessments without requiring external management intervention. The scanner automatically discovers other virtual machines on the same physical host and coordinates scanning efforts, eliminating the need for complex external management of security assessments across multiple VMs

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent merges the security scanning functionality directly into the virtual machine environment itself, combining what were previously separate functions (VM management and security scanning) into a unified system where the scanner is an integral part of the virtualized infrastructure rather than an external tool

Inventive Principle:
Principle #5Merging (Combining)

3Measurement precision

If vulnerability scanners are instantiated on each physical machine, then scanning coverage is improved, but resource consumption increases

Engineering Contradiction:
Improvevulnerability scan coverageVSAvoidscanner resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The virtual scanner is designed as a dynamic, lightweight process that can be quickly instantiated and terminated on demand. Rather than running continuously or requiring heavy resource allocation, the scanner dynamically activates only when scanning is needed and efficiently utilizes available resources, allowing multiple instances to coexist on the same physical host without excessive resource consumption

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8819832B2Systems and methods for performing vulnerability scans on virtual machines
Publication Date: 2014.08.26 RAPID7 INC
  • US8819832B2 patent drawing
  • US8819832B2 patent drawing
  • US8819832B2 patent drawing

AI summary

Embodiments described herein relate to systems and methods for performing vulnerability scans on virtual machines. The systems and methods comprise a virtual asset tool that can instantiate a vulnerability scanner on a physical machine hosting a set of virtual machines. The vulnerability scanner can scan the virtual machines to identify any vulnerabilities, security flaws, or other risks, and can provide a result of the scan to the virtual asset tool. In embodiments, the virtual asset tool can examine the result of the scan to identify any vulnerabilities resulting from the scan.