Virtual Instance State Recovery via Delta Archiving

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Modern cloud-based and virtual computing environments lack effective solutions for fully auditing and controlling dynamic resources, leading to the loss of information from deallocated virtual machines and containers, which cannot be searched, recovered, or reinstantiated, and existing solutions fail to provide oversight during the development process, compromising security and efficiency.

Innovation Solution

The system enables the recovery of deactivated virtual computing instances by archiving environment properties and activities, allowing for reinstantiation to a previous state, and performs live checks and audits on dynamic resources, storing delta data for security analysis and remediation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If virtual computing instances are dynamically spun up and down in cloud environments, then resource utilization and productivity are improved, but information from deallocated resources is lost and cannot be recovered

Engineering Contradiction:
Improveresource utilizationVSAvoidinformation from deallocated resources
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The system performs preliminary archiving of environment properties and activity chains before virtual computing instances are deallocated. By capturing and storing this information in advance in an audit warehouse, the system ensures that no information is lost when instances are dynamically terminated, thus resolving the contradiction between high resource utilization and information preservation.

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If traditional on-premises computer networks are replaced with cloud-based virtual networks, then scalability and adaptability are improved, but control and audit capabilities over dynamic resources are reduced

Engineering Contradiction:
Improvescalability of virtual environmentsVSAvoidcontrol and audit capabilities
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The system implements comprehensive feedback mechanisms by continuously monitoring and archiving environment properties, configuration data, and activity chains of virtual computing instances. This feedback loop provides full visibility and control over dynamic cloud resources, enabling audit capabilities that match the scalability benefits of virtualized environments.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The audit warehouse serves as an intermediary layer between the dynamic virtual computing environment and the control/audit systems. By storing archived environment properties and activity chains in this intermediate storage layer, the system enables comprehensive oversight of cloud resources without interfering with their dynamic operation and scalability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Loss of energy

If security checks are performed after production deployment, then system overhead is reduced, but security vulnerabilities and malicious activities cannot be prevented early

Engineering Contradiction:
Improvesystem overheadVSAvoidsecurity prevention capability
Core Design Contradiction:
Loss of energyVSReliability

Solution Approach 1:

The system performs security analysis and audits on archived environment properties and activity chains before virtual computing instances are deployed to production. By conducting these security checks in advance using the archived data, the system prevents malicious activities and vulnerabilities from reaching production environments without imposing significant overhead on running systems.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20230205571A1Recovery of state, configuration, and content for virtualized instances
Publication Date: 2023.06.29 CYBER ARK SOFTWARE LTD
  • US20230205571A1 patent drawing
  • US20230205571A1 patent drawing
  • US20230205571A1 patent drawing

AI summary

Disclosed embodiments relate to systems and methods for analysis of data associated with software instances. Techniques include obtaining data associated with a software instance; archiving delta data associated with software instance; analyzing one more previous states of the software instance based on the archived delta data; and performing a security action based on the analysis of the one or more previous states of the software instance based on the archived delta data.