US 12,277,216 B2
Techniques for improved virtual instance inspection utilizing disk cloning
Daniel Hershko Shemesh, Givat-Shmuel (IL); Yarin Miran, Rishon Lezion (IL); Roy Reznik, Tel Aviv (IL); Ami Luttwak, Binyamina (IL); and Yinon Costica, Tel Aviv (IL)
Assigned to Wiz, Inc., New York, NY (US)
Filed by Wiz, Inc., New York, NY (US)
Filed on Aug. 28, 2023, as Appl. No. 18/456,942.
Application 18/456,942 is a continuation of application No. 17/664,508, filed on May 23, 2022.
Prior Publication US 2023/0418931 A1, Dec. 28, 2023
Int. Cl. G06F 21/53 (2013.01); G06F 3/06 (2006.01); G06F 9/455 (2018.01)
CPC G06F 21/53 (2013.01) [G06F 3/067 (2013.01); G06F 2009/45562 (2013.01)] 23 Claims
OG exemplary drawing
 
1. A method for inspecting virtual instances in a cloud computing environment for cybersecurity threats, comprising:
selecting a live virtual instance in a production environment of a cloud computing environment, wherein the live virtual instance includes a disk having a disk descriptor with an address in a cloud storage system;
generating an instruction to clone the disk of the virtual instance, the instruction when executed causes generation of a cloned disk descriptor, the cloned disk descriptor having a data field including the address of the disk of the virtual instance wherein a cloned disk becomes substantially immediately available for inspection in its entirety upon its creation by the execution of the instruction without any copying of data of the disk of the virtual instance, the cloned disk not being associated for operation of any live virtual instance in the production environment;
inspecting the cloned disk for a cybersecurity threat by an inspector in an inspection environment that is at least logically distinct from the cloud computing environment without requiring resources of the cloud computing environment other than the cloned disk descriptor and while the while the live virtual instance remains live and unperturbed; and
releasing the cloned disk in response to completing the inspection of the cloned disk.