-
1.
公开(公告)号:US11803766B1
公开(公告)日:2023-10-31
申请号:US16712242
申请日:2019-12-12
Applicant: Amazon Technologies, Inc.
Inventor: Preethi Srinivasan , Sreekanth Reddy Polaka , Christopher Wooram Yi , John David Backes , Everett Richard Anthony , Aparna Nagargadde , Mark Edward Stalzer
CPC classification number: G06N5/04 , G06F9/45558 , H04L63/1433 , H04L63/20 , G06F2009/45579
Abstract: An automated security assessment service of a service provider network may identify, and notify a customer of, misconfigured VM instances that can be access (e.g., via the Internet). A scanner tool may call an automated reasoning service to identify any VM instances of a customer that can be accessed, and may receive information from the automated reasoning service that is usable to exchange packets with those identified instances. The scanner tool can use the information to send requests to the identified instances. After receiving responses from the identified instances, the scanner tool can store, in storage of a network-based storage service, and in association with a customer account of the customer, encrypted data about the results of the scan (e.g., any VM instances that are vulnerable to attackers), and this encrypted data is thereby accessible to the customer with proper decrypt permissions.