Virtual Asset Vulnerability Management via Testing Environment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current vulnerability management approaches for cloud-based infrastructures are inadequate as they lack comprehensive and proactive methods to identify and remediate vulnerabilities in virtual assets before deployment, leading to potential security breaches and irreparable damage, especially when connectivity restrictions change.

Innovation Solution

A method and system that involves creating a virtual asset testing environment distinct from the production environment, where virtual assets are analyzed for vulnerabilities using a designated test virtual asset created from a template, allowing for vulnerability identification and remediation before deployment, ensuring security across various connectivity and operational scenarios.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If comprehensive vulnerability analysis is performed in the production computing environment with connectivity restrictions, then the virtual assets can be verified for security under restricted conditions, but vulnerabilities that only appear under different connectivity scenarios cannot be detected

Engineering Contradiction:
Improvesecurity verification completenessVSAvoidconnectivity scenario coverage
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent applies preliminary action by creating and configuring a testing computing environment before deploying virtual assets to production. This environment is set up with various connectivity configurations (restricted, unrestricted, different network topologies) to perform vulnerability analysis in advance. The testing environment includes test virtual assets that are configured with different connectivity scenarios before the actual virtual assets are deployed to production, allowing comprehensive security verification across multiple connectivity conditions without affecting production systems.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If vulnerability management is performed after deployment in production environment, then real-world vulnerabilities can be identified, but the cost and resource requirements become prohibitively expensive and resource intensive

Engineering Contradiction:
Improvevulnerability detection accuracyVSAvoidhardware and software requirements
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies copying by creating a test virtual asset that replicates the configuration and connectivity characteristics of the production virtual asset. This copy is then subjected to comprehensive vulnerability analysis in the testing computing environment. The testing environment mirrors production conditions sufficiently to identify real vulnerabilities while using significantly fewer resources, as only one or a few test instances need to be analyzed rather than every production asset continuously.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent performs vulnerability analysis in advance in the testing environment before deployment to production. This preliminary action identifies and allows remediation of vulnerabilities while the virtual asset template is still being configured, rather than after deployment when changes are more costly and complex.

Inventive Principle:
Principle #10Preliminary action

3Ease of repair

If ad-hoc vulnerability management is performed manually after vulnerabilities arise, then individual issues can be addressed, but the process lacks comprehensiveness and coordination

Engineering Contradiction:
Improvevulnerability remediation capabilityVSAvoidsystematic management level
Core Design Contradiction:
Ease of repairVSExtent of automation

Solution Approach 1:

The patent implements feedback by automatically analyzing vulnerability scan results and using that information to update and refine virtual asset templates. The system continuously monitors for vulnerabilities in the testing environment, feeds this information back to the template configuration, and automatically applies remediations. This creates a closed-loop system where vulnerability management becomes systematic and automated rather than manual and ad-hoc.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent performs vulnerability management actions in advance by analyzing and remediating vulnerabilities in the testing environment before production deployment. This preliminary remediation ensures that virtual asset templates are hardened against known vulnerabilities before they are instantiated in production, preventing issues rather than reacting to them.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10121007B2Method and system for providing a robust and efficient virtual asset vulnerability management and verification service
Publication Date: 2018.11.06 INTUIT INC
  • US10121007B2 patent drawing
  • US10121007B2 patent drawing
  • US10121007B2 patent drawing

AI summary

A virtual asset testing environment is provided that is distinct from a production computing environment. A virtual asset creation template associated with a class of virtual assets to be verified is identified, each virtual asset of the class of virtual assets being created using the virtual asset creation template. A designated test virtual asset is generated using the virtual asset creation template that is deployed in the virtual asset testing environment. The designated test virtual asset is then analyzed in the virtual asset testing environment to identify any vulnerabilities in the designated test virtual asset. If a vulnerability is identified in the designated test virtual asset, a remedy to the vulnerability is applied to the virtual asset creation template, and/or virtual assets created by the virtual asset creation template deployed in the production environment.