Virtual Machine Image Prioritization for Security Scanning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large organizations face challenges in efficiently, effectively, and securely managing virtual machine images across internal and external computing platforms, particularly in cloud environments, due to the risk of malware exposure and difficulty in prioritizing relevant images for scanning and removal of compromised or obsolete ones.

Innovation Solution

A system that employs a last-in, first-out (LIFO) stack to prioritize virtual machine image scanning, continuously identifies and removes obsolete or irrelevant images, and uses a reconciliation process to ensure active images remain secure, optimizing the scanning process based on usage requirements and applying real-time security rules.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If all virtual machine images are scanned for security threats, then security coverage is improved, but scanning time and computational resources are excessively consumed

Engineering Contradiction:
Improvesecurity coverageVSAvoidscanning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the virtual machine image population into different priority groups (critical, standard, low) based on their importance to the organization. This segmentation allows the scanning system to focus resources on high-priority images first, ensuring security coverage for critical systems while reducing scanning time for less critical images.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements preliminary actions by maintaining an approved virtual machine image repository that is pre-scanned and verified for security threats. New virtual machine images are scanned and approved before being added to this repository, preventing compromised images from entering the system in the first place, thereby reducing the need for continuous scanning of all images.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If virtual machine images are continuously monitored and scanned, then security detection capability is improved, but system performance and resource usage deteriorate

Engineering Contradiction:
Improvesecurity detection capabilityVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements periodic scanning instead of continuous scanning of all virtual machine images. Critical images are scanned more frequently according to their priority level, while standard and low-priority images are scanned less frequently. This periodic action maintains security detection capability while reducing overall system resource consumption and improving performance.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent creates and maintains an approved copy/repository of virtual machine images that have already been scanned and verified for security. This approved repository serves as a reference that reduces the need to re-scan identical or similar images, thereby maintaining security detection capability while reducing redundant scanning operations and improving system performance.

Inventive Principle:
Principle #26Copying

3Adaptability or versatility

If obsolete virtual machine images are retained in the system, then availability of historical images is improved, but security risk from compromised images increases

Engineering Contradiction:
Improveavailability of historical imagesVSAvoidsecurity risk from compromised images
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The patent extracts and separates obsolete or deprecated virtual machine images from the active approved repository into a historical archive. This extraction maintains the availability of historical images for reference and recovery purposes while removing them from the active security management cycle, thereby reducing the security risk associated with maintaining compromised images in the production environment.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent implements a process where obsolete virtual machine images are discarded from the active approved repository but recovered and preserved in a historical archive. This allows the organization to maintain availability of historical images when needed while systematically removing compromised or outdated images from active use, reducing security risks.

Inventive Principle:
Principle #34Discarding and recovering

Data Source

PatentUS20250348582A1Virtual Machine Image Management System
Publication Date: 2025.11.13 BANK OF AMERICA CORP
  • US20250348582A1 patent drawing
  • US20250348582A1 patent drawing
  • US20250348582A1 patent drawing

AI summary

Virtual machine images may be constantly scanned using background process, to identify current and evolving security risks, such as by optimizing the image scanning a last-in, first-out (LIFO) stack to prioritize most relevant images. Older and/or non-relevant image are removed from the scanning process and removed from use. Virtual machines image prioritization is based on each virtual machine image's current and/or potential usage requirement, where the LIFO stack prioritizes the scanning order. Newly created virtual machine images and/or newly re-activated virtual machine images are placed onto a provisioning queue (first-in, first out) before activation. The virtual machine images active within a host computing environment are processed via a reconciliation process to scan for indications of security vulnerabilities and/or threats to network security. Obsolete or otherwise irrelevant virtual machine images are removed from use via a repository synchronization process.