ADC-Based Traffic Capture for Vulnerability Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security testing of web applications and web services is limited in its ability to detect vulnerabilities due to its inability to directly observe or elicit communications occurring through the system under test, and it lacks comprehensive understanding of the full scope of usage, leading to incomplete vulnerability assessments.

Innovation Solution

The system integrates a security management system with an Application Delivery Controller (ADC) to access and capture traffic flow information from internal applications, allowing for comprehensive vulnerability scanning and analysis without the need for additional hardware appliances, by leveraging cloud-based services and tunneling through the ADC to facilitate communication across firewalls.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional black box scanning or source code scanning is used to search for vulnerabilities, then vulnerability detection can be performed, but the ability to directly observe communications occurring through the system under test is limited, leading to incomplete vulnerability assessments

Engineering Contradiction:
Improvevulnerability detection completenessVSAvoidability to observe communications
Core Design Contradiction:
Measurement precisionVSDifficulty of detecting and measuring

Solution Approach 1:

The patent introduces an Application Delivery Controller (ADC) as an intermediary component positioned between the web applications and the network. The ADC captures traffic flow information including decrypted data, allowing the security assessment system to observe communications that would otherwise be inaccessible. This intermediary enables comprehensive vulnerability detection by providing direct observation capabilities of system communications without requiring modification of the applications themselves.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If additional hardware appliances are deployed to capture traffic flow information, then comprehensive vulnerability scanning can be achieved, but device complexity and cost increase

Engineering Contradiction:
Improvevulnerability scanning comprehensivenessVSAvoidhardware infrastructure complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent leverages the Application Delivery Controller (ADC) which serves multiple functions including load balancing, SSL termination, and now security assessment facilitation. By making the ADC's capabilities available to the security management system, the patent avoids adding dedicated hardware appliances solely for vulnerability scanning. The ADC's existing traffic capture and decryption capabilities are repurposed to enable comprehensive security assessment, reducing overall system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If firewalls are used to block malicious traffic, then security protection is provided, but the ability to assess vulnerabilities behind firewalls is limited

Engineering Contradiction:
Improvesecurity protection effectivenessVSAvoidaccessibility for vulnerability assessment
Core Design Contradiction:
ReliabilityVSDifficulty of detecting and measuring

Solution Approach 1:

The ADC acts as an intermediary that operates within the trusted network perimeter behind the firewall. It captures traffic flow information including decrypted data from web applications, enabling the security management system to assess vulnerabilities of internal applications without needing to penetrate the firewall. The ADC provides a secure bridge that allows comprehensive security assessment while maintaining the firewall's protective function.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS9544324B2System and method for managed security assessment and mitigation
Publication Date: 2017.01.10 TRUSTWAVE HOLDINGS INC
  • US9544324B2 patent drawing
  • US9544324B2 patent drawing
  • US9544324B2 patent drawing

AI summary

In an embodiment of the invention, a system for assessing vulnerabilities includes: a security management system; a network device in a system under test (SUT), wherein the network device is privy to traffic in the SUT; and wherein the SMS is privy to traffic that is known by the network device and/or to one or more traffic observations that is known by the network device.