Virtual Machine Disk Snapshot Scanning for Agentless Threat Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cyber-security solutions for virtual machines in cloud computing environments are inadequate due to limitations in traffic inspection, network scanner inefficiencies, and the cumbersome nature of agent-based vulnerability management, which fail to accurately detect vulnerabilities and require significant IT resources.

Innovation Solution

A security system that analyzes snapshots of virtual machine disks to detect potential cyber threats without requiring agents or cooperation from the virtual machine, using techniques such as binary comparison, cryptographic hashing, and sandbox execution to identify vulnerabilities and anomalies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traffic inspection is performed by a network device, then security monitoring is achieved, but accurate indication of server security status cannot be obtained due to encryption and data exposure limitations

Engineering Contradiction:
Improvesecurity status detection accuracyVSAvoidinspection capability limitations
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces a security scanner as an intermediary component that operates between the network device and the server. This scanner captures traffic flows and performs deep inspection including decryption and vulnerability scanning, acting as a mediator that overcomes the limitations of traditional network device inspection while maintaining system architecture integrity.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If a network scanner is deployed out of path to query the server, then vulnerability detection is possible, but the server may not respond to all queries or expose necessary data due to network configuration and credential requirements

Engineering Contradiction:
Improvevulnerability detection capabilityVSAvoidserver responsiveness to scanner queries
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The security scanner serves as an intermediary that captures server responses passively from traffic flows rather than requiring active server cooperation. This allows the scanner to obtain vulnerability information without being blocked by network configurations or credential requirements that would prevent traditional active scanning approaches.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates copies of traffic flows containing server responses and analyzes these copies to extract vulnerability information. This copying approach allows comprehensive inspection without requiring the server to be directly accessible or responsive to scanner queries, as the analysis is performed on captured traffic copies.

Inventive Principle:
Principle #26Copying

3Productivity

If a traffic monitor is used to detect cyber threats based on traffic volume, then some threats are detectable, but misconfiguration and software vulnerabilities cannot be detected

Engineering Contradiction:
Improvethreat detection efficiencyVSAvoidcomprehensive vulnerability detection capability
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent merges multiple detection approaches by combining traffic monitoring capabilities with deep packet inspection and vulnerability scanning functions in the security scanner. This unified approach maintains the efficiency of traffic-based monitoring while adding the precision of detailed vulnerability analysis that traffic volume monitoring alone cannot provide.

Inventive Principle:
Principle #5Merging (Combining)

4Measurement precision

If agents are installed in each server for vulnerability management, then comprehensive security assessment is achieved, but IT resource management becomes cumbersome and installation takes months in large data centers

Engineering Contradiction:
Improvesecurity assessment comprehensivenessVSAvoidagent deployment complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts the security scanning functionality from the server environment by implementing it as a separate network-based security scanner. This eliminates the need to install agents within servers, removing the complexity of agent deployment, management, and updates while maintaining comprehensive security assessment capabilities through passive traffic flow analysis.

Inventive Principle:
Principle #2Taking out (Extraction)

5Measurement precision

If agents are installed in each server, then vulnerability detection is comprehensive, but significant IT resources are required for installation and management

Engineering Contradiction:
Improvevulnerability detection accuracyVSAvoidIT resources for agent management
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The security scanning functionality is extracted from the server environment and implemented as a standalone network-based security scanner. This eliminates the need for numerous agent installations across servers, significantly reducing IT resource requirements for deployment, management, and maintenance while maintaining comprehensive vulnerability detection through traffic flow analysis.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20250328373A1Techniques for securing virtual machines
Publication Date: 2025.10.23 ORCA SECURITY LTD
  • US20250328373A1 patent drawing
  • US20250328373A1 patent drawing
  • US20250328373A1 patent drawing

AI summary

A system and method for securing virtual cloud assets in a cloud computing environment against cyber threats. The method includes: determining a location of a snapshot of at least one virtual disk of a protected virtual cloud asset, wherein the virtual cloud asset is instantiated in the cloud computing environment; accessing the snapshot of the virtual disk based on the determined location; analyzing the snapshot of the protected virtual cloud asset to detect potential cyber threats risking the protected virtual cloud asset; and alerting detected potential cyber threats based on a determined priority.