IP Library › Granted Patent US 12,743,518
Granted Patent B1
US 12,743,518 · App. 18/901,520 · Granted Sep 22, 2026

Scanning of files in a customer account of a cloud service for cybersecurity

Inventor: Brendan M. Johnson (Irving, TX)
Assignee: Trend Micro Incorporated
G06F21/568G06F21/552G06F21/565
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,743,518
App. No.
18/901,520
Granted
Sep 22, 2026
Kind
B1
Abstract

A cloud computing infrastructure hosts a web service with customer accounts. In a customer account, files of the customer account are listed in an index. Files indicated in the index are arranged in groups, with files in each group being scanned using scanning serverless functions in the customer account. The files in the customer account include a compressed tar archive of a software container. Member files of a compressed tar archive in a customer account are randomly-accessed by way of locators that indicate a tar offset, a logical offset, and a decompressor state for a corresponding member file. A member file is accessed by seeking to the tar offset in the compressed tar archive, restoring a decompressor to the decompressor state, decompressing the compressed tar archive using the decompressor, and moving to the logical offset in the decompressed data in memory.

Claims (26)

1 . A cloud computing infrastructure that is accessible over the Internet, the cloud computing infrastructure comprising a memory and at least one processor, the memory storing instructions that when executed by the at least one processor cause the cloud computing infrastructure to:

host a cloud service;

provide a plurality of scanning serverless functions in a customer account of the cloud service, the plurality of scanning serverless functions being stateless and ephemeral;

identify a plurality of files of the customer account;

store a listing of the plurality of files of the customer account in a first storage of the customer account;

group the plurality of files indicated in the listing into a plurality of groups; and

in the customer account, for each group of the plurality of groups, scan files that belong to the group for cybersecurity using scanning serverless functions of the plurality of scanning serverless functions.

2 . The cloud computing infrastructure of claim 1 , wherein the instructions stored in the memory, when executed by the at least one processor, cause the cloud computing infrastructure to:

in the customer account, create a snapshot of a second storage of the customer account that stores the plurality of files, the snapshot being a point-in-time copy of the second storage; and

in the customer account, parse the snapshot to identify the plurality of files.

3 . The cloud computing infrastructure of claim 2 , wherein the first storage is an object-level storage provided as a service by the cloud service, and the second storage is a block-level storage provided as a service by the cloud service.

4 . The cloud computing infrastructure of claim 1 , wherein files that belong to each group of the plurality of groups are scanned in sequence, and scanning of files in a group of the plurality of groups is performed in parallel with scanning of files in another group of the plurality of groups.

5 . The cloud computing infrastructure of claim 1 , wherein the instructions stored in the memory, when executed by the at least one processor, cause the cloud computing infrastructure to send a report from the customer account to a cybersecurity account in the cloud service, the report indicating a result of scanning the plurality of files using the plurality of scanning serverless functions.

6 . A method of scanning a plurality of files of a customer account of a cloud service for cybersecurity, the method comprising:

providing a plurality of scanning serverless functions in the customer account, the plurality of scanning serverless functions being stateless and ephemeral;

identifying the plurality of files of the customer account;

storing a listing of the plurality of files of the customer account in a first storage of the customer account;

grouping the plurality of files indicated in the listing into a plurality of groups; and

for each group of the plurality of groups, scanning files that belong to the group for cybersecurity using scanning serverless functions of the plurality of scanning serverless functions.

7 . The method of claim 6 , further comprising:

creating a snapshot of a second storage of the customer account that stores the plurality of files, the snapshot being a point-in-time copy of the second storage; and

parsing the snapshot to identify the plurality of files.

8 . The method of claim 7 , wherein the first storage is an object-level storage provided as a service by the cloud service, and the second storage is a block-level storage provided as a service by the cloud service.

9 . The method of claim 6 , wherein files that belong to each group of the plurality of groups are scanned in sequence, and scanning of files in a group of the plurality of groups is performed in parallel with scanning of files in another group of the plurality of groups.

10 . The method of claim 6 , further comprising:

sending a report from the customer account to a cybersecurity account in the cloud service, the report indicating a result of scanning the plurality of files using the plurality of scanning serverless functions.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 1, 2024
From: JOHNSON, BRENDAN M.
To: TREND MICRO INCORPORATED
Reel/Frame 068759/0891 →
Continuity (1)
Division 17967647 · Oct 17, 2022
References Cited (23)
US 10721311B1 · McDonald · 2020 [cited by applicant]
US 10740149B2 · Bogineni et al. · 2020 [cited by applicant]
US 10853183B2 · Natanzon et al. · 2020 [cited by applicant]
US 10884807B2 · Shimamura et al. · 2021 [cited by applicant]
US 10915382B2 · Zhang et al. · 2021 [cited by applicant]
US 10938677B2 · Shimamura et al. · 2021 [cited by applicant]
US 11704408B1 · Ciubotariu · 2023 [cited by examiner]
US 20190312899A1 · Shulman · 2019 [cited by examiner]
US 20190332366A1 · Natanzon · 2019 [cited by examiner]
US 20190332781A1 · Natanzon · 2019 [cited by examiner]
US 20210117549A1 · Mandagere et al. · 2021 [cited by applicant]
US 20220164120A1 · Kannan et al. · 2022 [cited by applicant]
US 20230008968A1 · Pabón · 2023 [cited by examiner]
Leveraging the Serverless Architecture for Securing Linux Containers, by Bila et al., published 2017. (Year: 2017). [cited by examiner]
Kisller, Edward, “A Beginner's Guide to Understanding and Building Docket Images”, https://jfrog.com/knowledge-base/a-beginners-guide-to-understanding-and-building-docker-images/, JFrog Ltd, 2022. [cited by applicant]
“Amazon EBS Volumes”, https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/ebs-volumes.html, Amazon Web Services, Inc., 2022. [cited by applicant]
“What are Serverless Functions?” https://www.splunk.com/en_us/data-insider/what-are-serverless-functions.html, Splunk, Sep. 1, 2019. [cited by applicant]
“What is Amazon EC2”, https://docs.aws.amazon.com/AWSEC2/latest/UserGuide/concepts.html, Amazon Web Services, Inc., 2022. [cited by applicant]
Containerization, IBM Cloud Education, https://www.ibm.com/topics/containerization, Jun. 23, 2021. [cited by applicant]
Gzip, https://en.wikipedia.org/wiki/Gzip, last edited Sep. 11, 2022. [cited by applicant]
Serverless Computing, https://en.wikipedia.org/wiki/Serverless_computing, last edited Aug. 29, 2022. [cited by applicant]
Tar (computing), https://en.wikipedia.org/wiki/Tar_(computing), last edited Sep. 1, 2022. [cited by applicant]
Use container to Build, Share and Run our application Containerized Applications, https://www.docker.com/resources/what-container/, 2022. [cited by applicant]