Network Device Agentless Validation Using Baseline Checksums

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network monitoring and troubleshooting systems are monolithic, inflexible, and resource-intensive, failing to scale with next-generation networks and increasing complexity and computational costs, while traditional third-party agents impact device performance and introduce security vulnerabilities.

Innovation Solution

An agentless validation platform that collects and analyzes file and directory attributes, such as checksums, permissions, and ownership, to verify network device security posture without requiring dedicated appliances, using built-in capabilities of network operating systems to ensure compliance and integrity.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional third-party agents are deployed to monitor network devices, then security validation capability is improved, but device performance deteriorates and security vulnerabilities increase

Engineering Contradiction:
Improvesecurity validation capabilityVSAvoiddevice performance impact and security vulnerabilities
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The network device itself performs security validation by executing integrity check routines and comparing its own configuration files and software components against known good states, eliminating the need for external third-party agents that would impact device performance and introduce security vulnerabilities

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The security validation functionality is extracted from external agents and integrated directly into the network device's operating system, allowing the device to self-monitor and self-validate without requiring external probes that consume resources and introduce attack surfaces

Inventive Principle:
Principle #2Taking out (Extraction)

2Reliability

If parallel passive probe infrastructure is built to monitor network functions, then monitoring capability is improved, but resource consumption increases significantly

Engineering Contradiction:
Improvemonitoring capabilityVSAvoidnetwork resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The monitoring and validation functions are merged into the network device's native operating system processes, eliminating the need for separate parallel probe infrastructure that would consume additional network resources, while leveraging existing device resources for both operation and self-monitoring

Inventive Principle:
Principle #5Merging (Combining)

3Reliability

If real-time network traffic monitoring is implemented, then network security monitoring is improved, but computational cost and complexity increase

Engineering Contradiction:
Improvereal-time monitoring capabilityVSAvoidcomputational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

Instead of monitoring all network traffic comprehensively, the system performs targeted integrity checks on specific configuration files and software components using checksum validation, achieving sufficient security monitoring with minimal computational overhead by focusing only on critical validation points

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12462066B2Network device agentless validation
Publication Date: 2025.11.04 AT&T INTELLECTUAL PROPERTY I L P
  • US12462066B2 patent drawing
  • US12462066B2 patent drawing
  • US12462066B2 patent drawing

AI summary

A processing system may obtain baseline attributes associated with a plurality of representative files of a first type of network equipment, where the baseline attributes comprise a plurality of baseline checksums associated with the plurality of representative files, obtain snapshot attributes associated with a first plurality of files of a first device deployed in a communication network, where the first device is of the first type of network equipment, and where the first plurality of files is associated with at least a portion of the plurality of representative files, identify at least one file of the first plurality of files or at least one directory associated with the first plurality of files, for which a respective one of the snapshot attributes fails to match a respective one of the baseline attributes, and perform at least one remedial action in the communication network in response to the identifying.