Browser-Based Security Assessment Botnet for Continuous Vulnerability Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for assessing network security, such as tabletop exercises and penetration tests, are limited in effectiveness and often costly, infrequently conducted, and may not detect pervasive security holes or changes in the network's defensive posture due to their frequency and resource-intensive nature.

Innovation Solution

A security assessment system that uses executable program code to simulate security threat techniques, tactics, and practices on end devices within a network, allowing for continuous and on-demand assessment of security posture by simulating attacks like data exfiltration and lateral scans, with automatic deletion of the code after completion to minimize risk.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional penetration tests and tabletop exercises are used to assess network security, then security vulnerabilities can be detected, but the assessment frequency is low and resource consumption is high

Engineering Contradiction:
Improvesecurity vulnerability detection accuracyVSAvoidassessment frequency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent creates virtual copies of threat actors (bots) that simulate attack behaviors. These digital replicas can be deployed repeatedly without human intervention, enabling continuous security assessments while maintaining detection accuracy. The bots copy the methodology of penetration testing but automate it completely, allowing frequent executions.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The security assessment system is self-executing, with bots automatically launching attacks, collecting data, and reporting vulnerabilities without human intervention. This automation eliminates the need for human security professionals to manually conduct each test, enabling continuous assessment at scale while reducing resource consumption per assessment.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If manual penetration testing is performed, then comprehensive security assessment can be achieved, but the process is costly and time-consuming

Engineering Contradiction:
Improvesecurity assessment comprehensivenessVSAvoidassessment duration
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The botnet performs continuous security assessments without interruption. Multiple bots operate simultaneously and continuously monitor for vulnerabilities, eliminating the gaps between manual penetration tests. This continuous action maintains comprehensive coverage while dramatically reducing the time loss associated with scheduling and executing discrete manual tests.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system performs preliminary security assessments continuously in the background, so when manual intervention is needed, the work is already done or near-complete. Bots proactively identify and report vulnerabilities before they can be exploited, making the security assessment process ongoing rather than periodic.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If security assessment tools are deployed frequently, then real-time vulnerability detection is possible, but the complexity of managing assessment infrastructure increases

Engineering Contradiction:
Improvereal-time vulnerability detectionVSAvoidassessment infrastructure complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The botnet infrastructure is multi-functional, serving both as a simulated threat actor and as a security assessment tool. The same bots that simulate attacks also collect vulnerability data and report findings. This universal design eliminates the need for separate assessment infrastructure, reducing complexity while enabling real-time detection.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges the threat simulation function and the vulnerability assessment function into a single integrated system. The bots simultaneously perform attack simulations and security evaluations, combining what would traditionally require separate tools and infrastructure into one unified platform.

Inventive Principle:
Principle #5Merging (Combining)

4Adaptability or versatility

If simulated threat actors are used to assess security, then realistic attack scenarios can be tested, but the risk of actual security breaches during testing increases

Engineering Contradiction:
Improveattack scenario realismVSAvoidrisk of actual security breaches
Core Design Contradiction:
Adaptability or versatilityVSObject-affected harmful factors

Solution Approach 1:

The botnet acts as an intermediary between security testers and the target network. Rather than human attackers directly probing systems, automated bots perform the simulations with controlled, predictable behavior. This intermediary layer maintains realism while reducing risk through automated safety protocols and predefined attack vectors.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent converts the potential harm of simulated attacks into benefit by using the same attack vectors to both test security and improve it. The bots simulate realistic threats that would expose vulnerabilities, but their automated nature and controlled environment turn what could be harmful into a beneficial security enhancement process.

Inventive Principle:
Principle #22Blessing in disguise (Convert harm into benefit)

Data Source

PatentUS10826928B2System and method for simulating network security threats and assessing network security
Publication Date: 2020.11.03 RELIAQUEST HOLDINGS LLC
  • US10826928B2 patent drawing
  • US10826928B2 patent drawing
  • US10826928B2 patent drawing

AI summary

A system and method of security assessment of a network is described. The system may include one or more security assessment computers controlled by a security assessor, and connected to a network, and first executable program code for acting as an agent on a first end device on the network. The first executable program code is configured to be executed by a browser application of the first end device, and is configured to initiate a simulation by requesting information from at least a first security assessment computer of the one or more security assessment computers.