Virtual Machine Backup Scanning for Low-Latency Security Assessment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security risk assessment systems for data management platforms face challenges such as increased latency and resource overhead due to the execution of security scanning agents on production environments, and require significant configuration efforts for virtual machines.
Innovation Solution
Processing backup snapshots in a separate system, such as a virtual machine management system or storage appliance, rather than executing agents on virtual machines, to reduce resource utilization and configuration requirements at the production environment.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security scanning agents are executed on production environments, then security vulnerabilities can be identified, but system latency increases and processing resources are consumed
Solution Approach 1:
The system separates security scanning operations from the production environment by creating a dedicated backup and recovery environment. The production environment is segmented into backup creation (using backup I/O devices) and backup processing (using processing resources in the backup environment), allowing security scanning to occur independently without impacting production latency.
Solution Approach 2:
Backup data serves as an intermediary medium that carries information about the production environment state. Instead of directly scanning the production environment, the system creates backups and processes them in a separate environment, using the backup data as a mediator to identify security vulnerabilities without direct interference with production systems.
2Reliability
If security scanning agents are executed on production environments, then security vulnerabilities can be identified, but processing resources are consumed
Solution Approach 1:
Processing resources are segmented and allocated to a dedicated backup environment rather than being shared with the production environment. This allows security scanning to utilize processing resources in the backup environment, preserving production processing resources for their primary functions while maintaining security monitoring capabilities.
Solution Approach 2:
Backup data acts as an intermediary that enables security analysis without requiring production processing resources. The backup environment processes security vulnerabilities by analyzing backup data, eliminating the need for production systems to allocate processing resources to security scanning operations.
3Reliability
If agents are configured for particular environments or virtual machines, then security scanning accuracy is improved, but configuration complexity increases
Solution Approach 1:
The backup environment is designed with universal processing resources that can handle security scanning for multiple different production environments and virtual machines. Instead of requiring separate agent configurations for each environment, the backup processing system universally processes backup data from various sources, reducing configuration complexity while maintaining scanning accuracy.
Solution Approach 2:
The system creates copies of production environments in the form of backups, which can then be analyzed in the backup environment without requiring the original production environments to be modified or configured with scanning agents. This copying approach eliminates the need for complex agent configurations on each production system.
Data Source
AI summary
A virtual machine management system may support backup and recovery for virtual machines that support various applications. The virtual machine management system may process a backup snapshot of the virtual machine to identify security risks in the virtual machine. A cloud platform may communicate with the virtual machine management system to support backup processing. The cloud platform may identify security configuration information and transmit such information and transmit indications of the information to the virtual machine management system. The cloud platform may receive an indication of one or more security risks and generate notifications that indicate the security risks.


