Virtual Machine Image Lifecycle Scanning for Security Coverage

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large organizations face challenges in efficiently, effectively, and securely managing virtual machine images across internal and external computing platforms, particularly in cloud environments, due to the complexity of operations and the risk of malware exposure.

Innovation Solution

A system that continuously scans virtual machine images using a last-in, first-out (LIFO) stack to prioritize relevant images, removes obsolete or compromised images, and employs a provisioning queue for newly created or reactivated images, ensuring security through a reconciliation process and repository synchronization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all virtual machine images are scanned continuously for security, then security coverage is improved, but system resources and scanning time are excessively consumed

Engineering Contradiction:
Improvesecurity coverageVSAvoidscanning efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent segments the virtual machine image population into different priority groups based on usage characteristics. Active images are scanned frequently with high priority, while inactive or archived images are scanned less frequently or with lower priority. This segmentation allows the system to allocate scanning resources efficiently while maintaining security coverage across all images.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial action by performing comprehensive security scanning only on active and recently modified virtual machine images, while using lighter scanning or sampling approaches on inactive images. This partial action maintains security for critical images without the excessive resource consumption of scanning all images equally.

Inventive Principle:
Principle #16Partial or excessive action

2Ease of operation

If virtual machine images are managed uniformly across all platforms, then management consistency is improved, but system complexity increases

Engineering Contradiction:
Improvemanagement consistencyVSAvoidsystem complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The patent implements a universal image management system that can operate across multiple virtualization platforms and cloud environments through a single interface. The system provides multi-functional capabilities including image creation, storage, scanning, provisioning, and lifecycle management that work consistently across different underlying platforms, thereby achieving management consistency without proportionally increasing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Adaptability or versatility

If obsolete virtual machine images are retained for potential future use, then adaptability is improved, but security risk and storage space increase

Engineering Contradiction:
Improveimage availabilityVSAvoidsecurity risk
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent performs preliminary security scanning and validation on virtual machine images before they are archived or stored for future use. Images are scanned for malware and security vulnerabilities prior to being moved to archival storage, ensuring that even retained images do not pose security risks. This preliminary action allows the system to maintain adaptable image availability while mitigating security risks from obsolete images.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12380207B2Virtual machine image management system
Publication Date: 2025.08.05 BANK OF AMERICA CORP
  • US12380207B2 patent drawing
  • US12380207B2 patent drawing
  • US12380207B2 patent drawing

AI summary

Virtual machine images may be constantly scanned using background process, to identify current and evolving security risks, such as by optimizing the image scanning a last-in, first-out (LIFO) stack to prioritize most relevant images. Older and/or non-relevant image are removed from the scanning process and removed from use. Virtual machines image prioritization is based on each virtual machine image's current and/or potential usage requirement, where the LIFO stack prioritizes the scanning order. Newly created virtual machine images and/or newly re-activated virtual machine images are placed onto a provisioning queue (first-in, first out) before activation. The virtual machine images active within a host computing environment are processed via a reconciliation process to scan for indications of security vulnerabilities and/or threats to network security. Obsolete or otherwise irrelevant virtual machine images are removed from use via a repository synchronization process.