Virtual Machine Launch Scanning via Segmented Network Configurations

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

There is no effective mechanism for scanning virtual machines or applications before they are made available in a cloud environment, leaving them vulnerable to security threats until periodic scans are conducted.

Innovation Solution

Implementing a scanning component that allows virtual machines or applications to be launched in a restricted network configuration, where vulnerability scans can be performed before granting full access to a second network configuration, with policies defining the scanning process and criteria for secure operation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Speed

If virtual machines are launched directly into the production network, then deployment speed is improved, but security vulnerability increases

Engineering Contradiction:
Improvedeployment speedVSAvoidsecurity vulnerability
Core Design Contradiction:
SpeedVSReliability

Solution Approach 1:

The network environment is segmented into two distinct configurations: a restricted first network configuration for scanning and a second network configuration for production. Virtual machines are launched in the restricted environment first, allowing security scans to be performed before deployment to the production network, thus resolving the contradiction between deployment speed and security vulnerability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Security scanning is performed as a preliminary action before virtual machines are deployed to the production network. The system launches virtual machines in a restricted first network configuration, conducts vulnerability scans, and only after successful scanning does it enable access to the second network configuration, ensuring security checks occur before full deployment.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If vulnerability scanning is performed before deployment, then security reliability is improved, but deployment time increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoiddeployment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system dynamically adjusts network configuration based on scan results. Virtual machines are launched in a restricted first network configuration that can be dynamically changed to a second network configuration once scanning is complete. This dynamic reconfiguration allows security scanning to be performed without permanently extending deployment time, as the network state changes based on scan completion.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The network configuration parameters are changed from a restricted first configuration to a permissive second configuration based on scan results. By changing the network access parameters rather than the virtual machine deployment itself, the system achieves security scanning with minimal impact on overall deployment time.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If all virtual machine launches are scanned, then security coverage is improved, but processing overhead increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidprocessing overhead
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system uses a template-based approach where a virtual machine image is copied and launched in a restricted first network configuration for scanning. This copying mechanism allows the same image to be scanned multiple times in the restricted environment without requiring unique full deployments each time, reducing processing overhead while maintaining security coverage.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The first network configuration serves multiple functions: it acts as both a launch environment and a scanning environment. By making the restricted network configuration multi-functional, the system avoids creating separate dedicated scanning infrastructure, thereby reducing overall processing overhead while maintaining comprehensive security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10542005B2Connection control for virtualized environments
Publication Date: 2020.01.21 AMAZON TECH INC
  • US10542005B2 patent drawing
  • US10542005B2 patent drawing
  • US10542005B2 patent drawing

AI summary

The launching of new software code, virtual machines, and other such instances can undergo one or more scans before being fully available in an electronic environment. One or more policies may apply to such a launch, which can cause the launch to first be performed under a first network configuration, wherein the instance may not be granted access to resources other than scanning infrastructure. After one or more scans are performed, the results can be compared against the policies and, if the results pass, the instance can be caused to operate in a second network configuration, whether launching a new instance in a production environment, altering the configuration of the network, or other such tasks. The policies can be set by a provider of the relevant resources, an administrator of one or more affected resources, an administrator of the instance, or another appropriate party.