A method for collective assessment and hardening of security vulnerabilities in network devices

The method addresses the inefficiencies in manual network device vulnerability detection and remediation by using SSH and Telnet protocols for automatic and customizable security hardening, achieving rapid and cost-effective vulnerability management across diverse devices.

WO2025144309A1PCT designated stage Publication Date: 2025-07-03SECHARD BILGI TEKNOLOJILERI LTD SIRKETI
View PDF 3 Cites 0 Cited by

Patent Information

Application Number
PCT/TR2024/051683
Authority / Receiving Office
WO · WO
Patent Type
Applications
Current Assignee / Owner
Filing Date
2024-12-23
Publication Date
2025-07-03

AI Technical Summary

Technical Problem

Large organizations face challenges in efficiently and cost-effectively detecting and remediating security vulnerabilities across a large number of network devices due to the complexity, time, and expertise required, leading to inefficiencies and potential errors in manual processes.

Method used

A method for collective assessment and hardening of security vulnerabilities using SSH and Telnet protocols, enabling automatic detection and remediation without manual intervention, supporting over 140 resource types and allowing customization for specific company needs.

Benefits of technology

Enables rapid and accurate detection and remediation of security vulnerabilities across diverse network devices, reducing time and cost, while minimizing human error and ensuring compliance with standards like CIS, with support for various protocols and customizable scripts.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure TR2024051683_03072025_PF_FP_ABST
    Figure TR2024051683_03072025_PF_FP_ABST
Patent Text Reader

Abstract

The invention is a method for assessing security vulnerabilities on network devices using protocols such as SSH and Telnet and ensuring that hardening operations are carried out collectively (remediation) without entering any commands, characterized by the fact that assessment and hardening processes are carried out by running codes / scripts created in accordance with the target network device on the target device.
Need to check novelty before this filing date? Find Prior Art

Description

[0001] DESCRIPTION

[0002] A METHOD FOR COLLECTIVE ASSESSMENT AND HARDENING OF SECURITY VULNERABILITIES IN NETWORK DEVICES

[0003] FIELD OF THE INVENTION

[0004] The invention is a method for assessing security vulnerabilities on network devices using SSH and Telnet protocols and ensuring that hardening operations are carried out collectively without entering any commands (remediation).

[0005] STATE OF THE ART

[0006] Nowadays, it is recommended that large companies or any other structure with a large network of network devices should scan, detect and fix / close vulnerabilities on each device connected to the network according to a certain standard. This security standard is called CIS (Center for Internet Security).

[0007] According to CIS, nearly 100 security settings may need to be changed on a network device running with default settings to have a secure operating system. If the necessary security vulnerabilities have not been detected and closed in accordance with these standards in the network device you are using, we can say that dozens of security settings are most likely missing. In a corporate network with hundreds or thousands of information technology (IT) assets / devices, identifying, closing and reporting all these deficiencies can be a process that will take years for IT teams.

[0008] Security hardening applications should be applied to network devices according to national and international standards, but it is often not known how to do this process, which requires expertise. When network device owners learn how to do this, they need expert support, they have to do manual progress and assessment operations, then they have to do the shutdown operations manually again, and many errors and problems can occur in this complex process. Even if all these operations are carried out correctly, the security provided will be eliminated with a small intervention made by anyone even after a long time. All technical problems can be avoided if the security hardening processes in network devices are done entirely from a centralized system and with a system where automatic assessment and automatic remediation processes are possible.

[0009] Today, companies can have a very rich asset inventory in terms of the types and numbers of resources they own and support. Especially companies with multisourcing demand security hardening specific to the type of resources they have. However, one of the main technical problems is the inability of companies to receive services according to all resource types, and the inability to meet company-specific and need-based requests and requirements.

[0010] Another technical problem is that companies do not have the manpower and qualified personnel to detect and remediate security hardening, and when they do, it takes a lot of time and effort at the expense of the company. To explain with an example; according to generally accepted hardening standards, approximately 100 definitions must be made on each network device. In a large bank or a telecom company with 10.000 devices, the number of identifications will be about 1.000.000. It is necessary to appoint a team of minimum 10 people for these operations, and this team must work for a minimum of 1 year to carry out the necessary work. This situation can be described as an impossible process for companies to sustain in terms of both time and cost.

[0011] Apart from international benchmarks, companies may also need to integrate their own benchmarks into their systems. Experienced specialists and a long period of time are required for the remediation operation. Some critical changes may cause unexpected results and problems.

[0012] Due to the abovementioned disadvantages and the insufficiency of the solutions regarding the subject matter, a development is required to be made in the relevant technical field. OBJECT OF THE INVENTION

[0013] In this context, the main object of the development subject to the invention is to ensure that the detection and hardening of security vulnerabilities can be carried out collectively for all network devices.

[0014] With the development subject to the invention, security vulnerabilities are detected according to the CIS and CBDDO assesment clauses and preventive actions can be taken fully automatically and without the use of any agents.

[0015] With the development subject to the invention, security hardening operations in network devices and cloud systems can be carried out for more than 140 different resources. With its flexible structure, the number of resources can be increased and made specific according to the demands of the companies.

[0016] There are more than 70 thousand special recipes for Switch, Router, Firewall, Load Balancer, Web Application Firewall, Wireless Controller, Windows Client, Windows Server, Linux Server, Web Server, Database Server, Mail Server, Virtualization, Microservice, Office Application, Web Browser and Cloud. Custom Benchmark, Custom Recipe features enable the creation and management of target asset-specific recipes and scripts for all resources that support Telnet, SSH, WinRM etc. protocols regardless of brand, model and version.

[0017] With the development subject to the invention, institutions can easily add their own control parameters and run them on thousands of different assets. In this way, special audit and automatic improvement lists can be produced for non-common technologies such as IOT, SCADA, swift, POS. It allows many different product concepts to be managed integrated with each other on a single platform. Thus, it saves companies with large network devices from having to use many different security products and provides a serious cost advantage.

[0018] With the development subject to the invention, detecting and rolling back security vulnerabilities in network device operating systems, which used to take hours or even days, can be carried out in minutes or even seconds. It allows organizations to carry out much more efficient and cost-effective operations by streamlining their system management processes. It allows network systems within an organization to function smoothly, minimizing security risks and enabling the organization to gain both in terms of process and cost.

[0019] In addition, since it is a product that is open to development, support can be given to all resource types by making business-specific improvements when necessary.

[0020] Some of the advantages of the invention are that it automatically performs security improvement in very short periods of time that can be expressed in seconds, eliminates all change risks without the need for in-depth knowledge, saves time and provides cost advantages.

[0021] Another advantage of the development subject to the invention is that it can reach target assets / network devices over the network because it can be positioned on the network owned by the companies that will perform security control.

[0022] Another advantage is that since it does not require the installation of an agent, these assessments are performed via standard protocols. (SSH, Telnet, WinRM, SQL etc.)

[0023] The structural and characteristic features of the present invention will be understood clearly by the following detailed description. Therefore the evaluation shall be made by taking this detailed description into consideration.

[0024] Figure

[0025] Figure 1 is the flow diagram of the assessment and remediation processes subject to the invention.

[0026] DETAILED DESCRIPTION OF THE INVENTION In this detailed description, the inventive method for “Ensuring Collective Security Hardening Processes on Network Devices” is described only for clarifying the subject matter in a manner such that no limiting effect is created.

[0027] Firstly, it would be appropriate to clarify some concepts in order to understand the subject more easily.

[0028] Network Devices: Systems such as switch, router, firewall, wireless controller, load balancer etc.

[0029] SSH: SSH, which stands for Secure Shell, is a remote management security protocol that allows users to control their servers over the internet and allows them to make various changes and edits on servers.

[0030] TELNET: Telnet is a type of client-server protocol that can be used to open a command line on a remote computer, typically a server.

[0031] The difference between SSH and TELNET is that TELNET is a network protocol that operates without a password, while SSH operates with an encryption method. Network devices that support Telnet and SSH protocols can be managed by creating special recipes and scripts. The main logic of the development subject to the invention is to prepare assessment and hardening scripts according to the technology used in the system in which network devices supporting SSH or TELNET protocols will be assessed and hardened. For example, in network devices, it generates code snippets in the language that the target system understands, sends these code snippets to the target system over this protocol, runs and checks them, detects security vulnerabilities, and gets the results. In order to rollback / harden these vulnerabilities, similarly closing codes / scripts are created in a language that the target entity understands, sent over the protocol, executed and the result is checked to ensure the correctness of the operation. The process sequence subject to the invention is carried out in two stages. Assessment and hardening / remediation / rollback. We can list the process steps as follows;

[0032] • Automatic or manual identification of network devices to the system (1001),

[0033] • Starting a periodic or user-initiated assessment process ( 1002),

[0034] • Accessing the network device using an authorized account configured appropriately for the network device, over the protocol (SSH / Telnet) supported by the network devices, (1003),

[0035] • Execution of codes / scripts created in accordance with the target network device on the target device (1004),

[0036] • Retrieving the transaction data with the rollback feature to be 100% sure of the accuracy of the assessment process, saving the same in the database, and performing 100% scoring / reporting (1005),

[0037] • Accessing the network device using an authorized account configured appropriately for the network device, over the protocol (SSH / Telnet) supported by the network devices, (1006),

[0038] • Execution of codes / scripts created in accordance with the target network device on the target device (1007),

[0039] • Retrieving the transaction data with the rollback feature to be 100% sure of the accuracy of the applied security hardening processes, saving the same in the database, and performing 100% scoring / reporting (1008).

[0040] Figure 1 shows the flow diagram of the assessment and hardening processes subject to the invention. The logic of the development subject to the invention is based on the assessment and hardening of the target device by running specially created codes / scripts suitable for the target network device on the target device. In addition, after the assessment and hardening operations, the transaction data is rolled back with the rollback feature to ensure the correctness of the applied transactions.

Claims

CLAIMS1. A method for assessing security vulnerabilities on network devices using SSH and Telnet protocols and ensuring that hardening operations are carried out collectively without entering any commands (remediation) comprising the process steps of;• Automatic or manual identification of network devices to the system (1001),• Starting a periodic or user-initiated assessment process ( 1002),• Accessing the network device using an authorized account configured appropriately for the network device, over the protocol (SSH / Telnet) supported by the network devices, (1003),• Accessing the network device to remediate detected security vulnerabilities, using an authorized account configured appropriately for the network device, over the protocol (SSH / Telnet) supported by the network devices, (1006), (remediation) characterized by comprising the process steps of;• Performing assessment with the execution of codes / scripts created in accordance with the target network device on the target device (1004),• Performing hardening with the execution of codes / scripts created in accordance with the target network device on the target device (1007).

2. A method according to claim 1, characterised by comprising the process step of retrieving the transaction data with the rollback feature to be 100% sure of the accuracy of the assessment process, saving the same in the database, and performing 100% scoring / reporting (1005) (rollback).

3. A method according to claim 1, characterised by comprising the process step of retrieving the transaction data with the rollback feature to be 100% sure of theaccuracy of the hardening process, saving the same in the database, and performing 100% scoring / reporting (1008) (rollback).

Citation Information

Patent Citations

  • Network audit and policy assurance system

    US20050257267A1

  • Cybersecurity Vulnerability Management System and Method

    US20180032736A1

  • Systems for network risk assessment including processing of user access rights associated with a network of devices

    US20180337940A1