Virtual Machine Security Assessment via Volume Image Duplication

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security assessment systems for virtualized computing environments face challenges such as resource allocation issues, unavailability of resources during assessments, complexity in installation and monitoring, and the need for costly and time-consuming evaluations, especially in distributed computing environments where targets may change and require secure software modules for internal assessments.

Innovation Solution

A scanning system that captures a snapshot of the target virtual machine's state, allowing for a duplicate virtual machine instance to be created either within or outside the original environment, enabling a secure and efficient security assessment without impacting the original system, by allocating necessary resources and performing the assessment on the duplicate instance.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security assessment is performed on the original virtual machine instance, then security vulnerabilities can be identified, but the original system's performance degrades and downtime increases

Engineering Contradiction:
Improvesecurity assessment accuracyVSAvoidsystem performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent creates a duplicate virtual machine instance from a volume image copy of the original virtual machine. This copy serves as a testbed for security assessments, allowing thorough vulnerability scanning and analysis without impacting the performance or availability of the original production system. The duplicate instance is provisioned with identical software and configuration to enable accurate security evaluation.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system separates the security assessment function from the original virtual machine by creating an independent duplicate instance. This segmentation allows security assessments to be performed in isolation, preventing resource contention and performance degradation on the original system while maintaining assessment integrity.

Inventive Principle:
Principle #1Segmentation

2Reliability

If security assessment resources are allocated within the original environment, then assessment can be performed, but resource availability conflicts occur

Engineering Contradiction:
Improvesecurity assessment capabilityVSAvoidresource availability
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

Instead of competing for resources within the original environment, the system creates a duplicate virtual machine instance that can be provisioned with dedicated assessment resources. This copy approach enables simultaneous operation of the original production system and security assessment activities without resource conflicts.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent introduces a volume image as an intermediary that enables the creation of a duplicate instance. This intermediary mechanism allows the security assessment to be performed on a copy of the original system's state, facilitating resource isolation while maintaining assessment fidelity.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If complex installation and monitoring procedures are implemented for security assessment, then comprehensive security analysis is achieved, but system complexity increases

Engineering Contradiction:
Improvesecurity analysis comprehensivenessVSAvoidinstallation and monitoring complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

By creating a duplicate virtual machine instance, the system provides an isolated environment where comprehensive security assessments can be performed without affecting the original system. This approach simplifies the overall process by eliminating the need for complex installation procedures on production systems while maintaining thorough security analysis capabilities.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The duplicate instance can be independently provisioned and configured for security assessment purposes, reducing the need for complex manual installation and monitoring procedures on the original system. The self-contained nature of the duplicate instance allows for streamlined assessment workflows.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS11216563B1Security assessment of virtual computing environment using logical volume image
Publication Date: 2022.01.04 AMAZON TECH INC
  • US11216563B1 patent drawing
  • US11216563B1 patent drawing
  • US11216563B1 patent drawing

AI summary

Systems for performing a security assessment of a target computing resource, such as a virtual machine or an instance of a virtual machine, include a scanning service that facilitates duplication of all or a portion of the target computing resource, and then performs the security assessment on the duplicate computing resource to avoid consuming processing time, processing power, and storage space of the target computing resource. A snapshot of the target computing resource, containing the data necessary to reproduce the portion to be assessed, is captured and used to implement the duplicate computing resource in newly allocated resources. The snapshot can be an image of a logical volume implementing the target computing resource. To reproduce a target virtual machine, the snapshot may include a configuration used to instantiate the target virtual machine; the scanning service may implement a duplicate virtual machine that is instantiated with the same configuration.