Virtual Machine Launch Scanning via Segmented Network Configurations
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is no effective mechanism for scanning virtual machines or applications before they are made available in a cloud environment, leaving them vulnerable to security threats until periodic scans are conducted.
Innovation Solution
Implementing a scanning component that allows virtual machines or applications to be launched in a restricted network configuration, where vulnerability scans can be performed before granting full access to a second network configuration, with policies defining the scanning process and criteria for secure operation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Speed
If virtual machines are launched directly into the production network, then deployment speed is improved, but security vulnerability increases
Solution Approach 1:
The network environment is segmented into two distinct configurations: a restricted first network configuration for scanning and a second network configuration for production. Virtual machines are launched in the restricted environment first, allowing security scans to be performed before deployment to the production network, thus resolving the contradiction between deployment speed and security vulnerability.
Solution Approach 2:
Security scanning is performed as a preliminary action before virtual machines are deployed to the production network. The system launches virtual machines in a restricted first network configuration, conducts vulnerability scans, and only after successful scanning does it enable access to the second network configuration, ensuring security checks occur before full deployment.
2Reliability
If vulnerability scanning is performed before deployment, then security reliability is improved, but deployment time increases
Solution Approach 1:
The system dynamically adjusts network configuration based on scan results. Virtual machines are launched in a restricted first network configuration that can be dynamically changed to a second network configuration once scanning is complete. This dynamic reconfiguration allows security scanning to be performed without permanently extending deployment time, as the network state changes based on scan completion.
Solution Approach 2:
The network configuration parameters are changed from a restricted first configuration to a permissive second configuration based on scan results. By changing the network access parameters rather than the virtual machine deployment itself, the system achieves security scanning with minimal impact on overall deployment time.
3Reliability
If all virtual machine launches are scanned, then security coverage is improved, but processing overhead increases
Solution Approach 1:
The system uses a template-based approach where a virtual machine image is copied and launched in a restricted first network configuration for scanning. This copying mechanism allows the same image to be scanned multiple times in the restricted environment without requiring unique full deployments each time, reducing processing overhead while maintaining security coverage.
Solution Approach 2:
The first network configuration serves multiple functions: it acts as both a launch environment and a scanning environment. By making the restricted network configuration multi-functional, the system avoids creating separate dedicated scanning infrastructure, thereby reducing overall processing overhead while maintaining comprehensive security coverage.
Data Source
AI summary
The launching of new software code, virtual machines, and other such instances can undergo one or more scans before being fully available in an electronic environment. One or more policies may apply to such a launch, which can cause the launch to first be performed under a first network configuration, wherein the instance may not be granted access to resources other than scanning infrastructure. After one or more scans are performed, the results can be compared against the policies and, if the results pass, the instance can be caused to operate in a second network configuration, whether launching a new instance in a production environment, altering the configuration of the network, or other such tasks. The policies can be set by a provider of the relevant resources, an administrator of one or more affected resources, an administrator of the instance, or another appropriate party.


