Autonomous Vulnerability Agent Platform
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing compliance and security systems for enterprise environments are limited by monolithic Java agents that require continuous connection, lack plugins, prioritization, and disconnected operation, hindering effective monitoring and vulnerability management.
Innovation Solution
The development of autonomous or semi-autonomous agent platforms for vulnerability management, which reduce agent footprint, improve scalability, and enable semi-autonomous operation, allowing for vulnerability scanning, remediation, and reporting in networked environments, even without continuous network connections.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If monolithic Java agents are used for continuous monitoring, then system integrity detection capability is improved, but agent footprint and resource consumption increase
Solution Approach 1:
The patent divides the monolithic Java agent into smaller, specialized agents that can be deployed independently. Each agent focuses on specific monitoring tasks rather than attempting to perform all monitoring functions, thereby reducing the footprint of each individual agent while maintaining comprehensive system integrity detection capability through the collective action of multiple specialized agents.
Solution Approach 2:
The patent creates a universal agent platform that can perform multiple monitoring functions through a common core infrastructure. This allows a single agent framework to handle various types of system integrity checks, file monitoring, registry monitoring, and security events, reducing the need for multiple separate agents and thereby reducing overall agent footprint.
2Speed
If agents require continuous connection to server, then real-time reporting capability is improved, but network resource consumption and system scalability worsen
Solution Approach 1:
The patent implements periodic batch reporting where agents collect monitoring data locally and transmit it to the server in scheduled batches rather than maintaining continuous connections. This approach maintains real-time detection capability at the agent level while reducing network resource consumption by consolidating transmissions, thereby resolving the contradiction between real-time reporting and network energy loss.
3Reliability
If monolithic agent architecture is used, then comprehensive monitoring capability is improved, but system scalability and adaptability deteriorate
Solution Approach 1:
The patent segments the monolithic agent architecture into modular, independently deployable agent units. Each agent can be configured for specific monitoring requirements and can be added or removed from the system without affecting other agents. This modular approach maintains comprehensive monitoring capability through the combination of multiple specialized agents while significantly improving system scalability and adaptability.
4Extent of automation
If agents must be connected to server continuously, then centralized control capability is improved, but disconnected operation capability and autonomy worsen
Solution Approach 1:
The patent implements preliminary configuration where agents receive monitoring parameters, policies, and detection rules from the server before being deployed to disconnected environments. Agents execute these pre-configured monitoring tasks autonomously when disconnected and automatically synchronize results with the server when reconnected, thereby maintaining centralized control capability while enabling effective disconnected operation.
Data Source
AI summary
Apparatus and methods for analyzing vulnerabilities with an agent executing on a computer host using a vulnerability scanner and vulnerability server are disclosed. In one example a method comprises, with a vulnerability scanner, searching for data associated with a vulnerability test (for example, the command that initiates the test) to determine whether the data associated with the vulnerability is available or not available. When the data associated with the vulnerability test is available in a vulnerability scanner database, the vulnerability scanner provides prior scan results generated using one or more commands specified by the data to a vulnerability aggregation server. When the data associated with the vulnerability test is not available in the vulnerability scanner database, the vulnerability scanner performs a scan of the host to obtain results associated with the vulnerability test.


