Centralized Controller for Vulnerable Network Service Probing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current vulnerability management programs face challenges in providing a unified, scalable, and non-intrusive solution for assessing and mitigating vulnerabilities across diverse network devices, operating systems, applications, databases, and web applications, leading to disjointed security management and increased costs.

Innovation Solution

A centralized controller system is employed for continuous monitoring and vulnerability assessment, using probe packets with special markers to identify vulnerabilities and generate policies, while lightweight agents on resources perform non-disruptive scanning and reporting, integrating with existing tools like Nessus, Nexpose, and Qualys for comprehensive vulnerability scoring and remediation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple stand-alone vulnerability management solutions are deployed to cover different aspects (assessment, mitigation, protection), then comprehensive vulnerability coverage is achieved, but system complexity and management difficulty increase

Engineering Contradiction:
Improvevulnerability coverageVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent combines multiple vulnerability management functions (vulnerability scanning, assessment, mitigation, and protection) into a single unified platform. The system integrates diverse scanning capabilities for different asset types (network devices, operating systems, applications, databases, web applications) and consolidates them under one management interface, eliminating the need for multiple separate tools while maintaining comprehensive coverage

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The unified vulnerability management platform performs multiple functions simultaneously: it conducts vulnerability assessments, generates risk scores, creates mitigation recommendations, and provides protection mechanisms all through a single system. The platform is designed to handle diverse asset types and vulnerability categories with a universal approach, making it adaptable to various enterprise environments without requiring specialized separate tools

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple stand-alone vulnerability management solutions are used, then comprehensive security assessment is achieved, but management ease and cost efficiency deteriorate

Engineering Contradiction:
Improvesecurity assessmentVSAvoidmanagement ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The system merges multiple vulnerability management operations into a single coordinated platform that provides unified management. Administrators can manage vulnerability assessments, mitigations, and protections across all asset types through one interface, significantly improving ease of operation while maintaining reliable security assessment capabilities

Inventive Principle:
Principle #5Merging (Combining)

3Measurement precision

If traditional vulnerability scanning methods are used, then vulnerability identification is achieved, but intrusiveness and operational disruption increase

Engineering Contradiction:
Improvevulnerability identificationVSAvoidoperational disruption
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

The system replaces traditional mechanical vulnerability scanning methods with a virtualized agent-based approach. Lightweight virtual agents are deployed on target systems to perform vulnerability assessments, replacing intrusive physical or network-based scanning mechanisms. This substitution enables precise vulnerability identification while minimizing operational disruption, as the virtual agents operate seamlessly within the existing system environment without causing significant performance impact or downtime

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10958556B2Probe and secure the vulnerable network services using a centralized controller
Publication Date: 2021.03.23 COLORTOKENS INC
  • US10958556B2 patent drawing
  • US10958556B2 patent drawing
  • US10958556B2 patent drawing

AI summary

A centralized controller for probing and securing vulnerable network resources is disclosed. A list of services hosted by a resource is received at the controller. A request to probe the list of services hosted on the resource is received by the controller. A probe candidate is determined by the controller. The probing is triggered by the controller based on a user scheduled time. The probing includes sending a probe packet that contains a special marker. The controller sends the list of resources to be probed for a set of port and protocol, to the probe candidate. A probe result generated as a result of the probing is received at the controller. The probe result includes vulnerable service information. A policy is computed based on the probe result and is enforced on the probed resources.