IP Library Granted Patent US 9,479,527
Granted Patent B2
US 9,479,527 · App. 14/884,163 · Granted Oct 25, 2016

Methods and systems for automated network scanning in dynamic virtualized environments

Inventors: Kevin McGinley (San Francisco, CA); Rich Tener (San Francisco, CA)
Assignee: Zynga Inc.
H04L63/1433G06F21/00G06F21/53G06F21/577G06F2221/2149
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,479,527
App. No.
14/884,163
Granted
Oct 25, 2016
Kind
B2
Abstract

Systems and methods for managing jobs to be scanned based on existence of processing nodes are described. One of the methods includes obtaining identification information regarding operation of a first set of the processing nodes from an inventory and creating a job for scanning the processing nodes of the first set for security vulnerability. The job includes the identification information. The method further includes verifying the inventory to determine the first identifying information of the first set of processing nodes for removal from the job and loading the job having second identifying information for a second set of processing nodes that remain after the verifying operation.

Claims (42)

1. A method comprising:

accessing, by a microprocessor, identifying information regarding a plurality of processing nodes of a cloud system from an inventory;

creating, by the microprocessor, a job bundle including the identifying information regarding the processing nodes, the job bundle including a number of blocks having the identifying information regarding the processing nodes to be scanned for vulnerability to attacks;

after creating the job bundle, determining, by the processor, that one of the processing nodes is modified within the cloud system;

updating, by the microprocessor, the job bundle to remove a portion of the identifying information regarding the one of the processing nodes that is modified to generate an updated job bundle; and

loading, by the microprocessor, the updated job bundle to a vulnerability scanner for scanning the updated job bundle for vulnerability to attacks.

2. The method of claim 1 , wherein the identifying information regarding the plurality of processing nodes includes identification of each of the processing nodes and the identification distinguishes each of the processing nodes from remaining of the processing nodes.

3. The method of claim 1 , wherein the inventory is an index that lists the identifying information regarding the plurality of processing nodes, wherein the inventory is updated with a change in one or more of the processing nodes within the cloud system, wherein when the one of the processing nodes is modified, the inventory is updated to remove the portion of the identifying information regarding the one of the processing nodes.

4. The method of claim 1 , wherein the blocks are marked pending before being loaded to the vulnerability scanner, wherein the blocks are marked complete after being scanned by the vulnerability scanner.

5. The method of claim 1 , wherein each of the processing nodes is vulnerable to attacks when each of the processing nodes does not have a security software to prevent hackers, or viruses, or malware from accessing each of the processing nodes.

6. The method of claim 1 , wherein the one of the processing nodes is modified when the one of the processing nodes is terminated.

7. The method of claim 1 , wherein the portion is removed so that the one of the processing nodes is not scanned by the vulnerability scanner for vulnerability to security attacks to reduce an amount of time of scan by the vulnerability scanner.

8. The method of claim 1 , wherein loading the updated job bundle to the vulnerability scanner is performed after marking the blocks as pending, wherein the vulnerability scanner is a vulnerability scanner node.

9. The method of claim 1 , wherein the cloud system includes a network that couples the processing nodes with each other, wherein each of the processing nodes is a virtual machine, wherein the virtual machine includes an operating system and an application, wherein the application and the operating system are executed by one or more servers of the cloud system.

10. A system comprising:

a memory device configured to store identifying information regarding a plurality of processing nodes;

a microprocessor coupled to the memory device, the microprocessor including:

a job creator module for accessing the identifying information regarding the plurality of processing nodes from the memory device,

wherein the job creator module is configured to create a job bundle including the identifying information regarding the processing nodes, wherein the job bundle includes a number of blocks having the identifying information regarding the processing nodes to be scanned for vulnerability to attacks,

a job loader module for receiving the job bundle from the job creator module, wherein the job loader module is configured to determine that one of the processing nodes is modified,

wherein the job loader module is configured to update the job bundle to remove a portion of the identifying information regarding the one of the processing nodes that is modified to generate an updated job bundle, and

wherein the job loader module is configured to load the updated job bundle to a vulnerability scanner for scanning the updated job bundle for vulnerability to attacks.

11. The system of claim 10 , wherein the identifying information regarding the plurality of processing nodes includes identification of each of the processing nodes and the identification distinguishes each of the processing nodes from remaining of the processing nodes.

12. The system of claim 10 , wherein the memory device includes an inventory, wherein the inventory is an index that lists the identifying information regarding the plurality of processing nodes, wherein the inventory is updated with a change in one or more of the processing nodes within a cloud network.

13. The system of claim 10 , wherein the job loader module determines that the one of the processing nodes is modified upon determining that the portion of the identifying information is deleted from an inventory.

14. The system of claim 10 , wherein each of the processing nodes is vulnerable to attacks when each of the processing nodes does not have a security software to prevent hackers, or viruses, or malware from accessing each of the processing nodes.

15. The system of claim 10 , wherein the portion is removed so that the one of the processing nodes is not scanned by the vulnerability scanner for vulnerability to security attacks to reduce an amount of time of scan by the vulnerability scanner.

16. A system comprising:

a cloud network including a plurality of processing nodes;

an inventory for storing identifying information regarding the plurality of processing nodes;

a vulnerability scanner node; and

a controller coupled to the cloud network, the inventory, and to the vulnerability scanner node, wherein the controller includes:

a job creator module for accessing the identifying information regarding the plurality of processing nodes from the inventory,

wherein the job creator module is configured to create a job bundle including the identifying information regarding the processing nodes, wherein the job bundle includes a number of blocks having the identifying information regarding the processing nodes to be scanned for vulnerability to attacks, and

a job loader module for receiving the job bundle from the job creator module,

wherein the job loader module is configured to determine that one of the processing nodes is modified,

wherein the job loader module is configured to update the job bundle to remove a portion of the identifying information regarding the one of the processing nodes that is modified to generate an updated job bundle, and

wherein the job loader module is configured to load the updated job bundle to the vulnerability scanner for scanning the updated job bundle for vulnerability to attacks.

17. The system of claim 16 , wherein the portion is removed so that the one of the processing nodes is not scanned by the vulnerability scanner for vulnerability to security attacks to reduce an amount of time of scan by the vulnerability scanner.

18. The system of claim 16 , wherein the job creator module is configured to mark the blocks as pending before loading the blocks to the vulnerability scanner, wherein the job loader module is configured to mark the blocks as complete after being scanned by the vulnerability scanner.

19. The system of claim 16 , wherein each of the processing nodes is vulnerable to attacks when each of the processing nodes does not have a security software to prevent hackers, or viruses, or malware from accessing each of the processing nodes.

20. The system of claim 16 , wherein the job loader module determines that the one of the processing nodes is modified upon determining that the portion of the information is deleted from an inventory, wherein the one of the processing nodes is modified when the one of the processing nodes is terminated.

Assignments (5)
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded May 23, 2022
From: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
To: ZYNGA INC.
Reel/Frame 060163/0437 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 8, 2021
From: MCGINLEY, KEVIN; TENER, RICH
To: ZYNGA INC.
Reel/Frame 058046/0235 →
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Dec 14, 2020
From: ZYNGA INC.
To: BANK OF AMERICA, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 054719/0490 →
TERMINATION AND RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 11, 2020
From: BANK OF AMERICA, N.A., AS LENDER
To: ZYNGA INC.
Reel/Frame 054701/0393 →
NOTICE OF GRANT OF SECURITY INTEREST IN PATENTS Recorded Dec 21, 2018
From: ZYNGA INC.
To: BANK OF AMERICA, N.A., AS LENDER
Reel/Frame 049147/0546 →
Continuity (4)
Continuation 14296338 · Jun 4, 2014
Continuation 13438688 · Apr 3, 2012
Provisional Application 61543795 · Oct 5, 2011
Related Publication 20160036847A1 · Feb 4, 2016