Runtime Vulnerability Detection via Cloud-Based Scanning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in detecting vulnerabilities in processes and packages in real-time within enterprise networks, requiring significant processing power and maintaining databases of Common Vulnerabilities and Exposures (CVEs) at endpoints, which can be inefficient and resource-intensive.

Innovation Solution

A mechanism that utilizes sensors to collect real-time process information and package information, which is then sent to a backend component for vulnerability identification using a database of vulnerabilities stored elsewhere, eliminating the need for endpoints to maintain CVE databases and enabling real-time vulnerability detection and fixing.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If scans of packages are performed to identify potential vulnerabilities, then vulnerability detection capability is improved, but processing power requirements increase significantly

Engineering Contradiction:
Improvevulnerability detection capabilityVSAvoidprocessing power
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts the vulnerability scanning function from the endpoint devices and relocates it to a centralized cloud-based vulnerability scanner. This allows the scanning operation to be performed externally, reducing the processing burden on local endpoint systems while maintaining comprehensive vulnerability detection capabilities through centralized resource allocation.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent introduces a cloud-based vulnerability scanner as an intermediary component between endpoint devices and vulnerability databases. This intermediary handles the computationally intensive scanning operations, acting as a mediator that processes vulnerability data centrally and returns results to endpoints, thereby distributing the processing load away from resource-constrained endpoint systems.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Speed

If CVE databases are maintained at endpoints for real-time vulnerability detection, then detection speed is improved, but device complexity and storage requirements increase

Engineering Contradiction:
Improvedetection speedVSAvoidendpoint complexity
Core Design Contradiction:
SpeedVSDevice complexity

Solution Approach 1:

The patent implements a centralized cloud-based vulnerability scanner that serves multiple endpoints simultaneously, providing a universal vulnerability detection service. This multi-functional system handles scanning, database management, and result distribution for numerous endpoint devices, reducing individual endpoint complexity while maintaining fast detection capabilities through shared resources.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent merges the vulnerability scanning functionality and CVE database storage into a centralized cloud-based system rather than distributing these resources across individual endpoints. This consolidation reduces device complexity at each endpoint while enabling real-time detection through centralized data access and processing capabilities.

Inventive Principle:
Principle #5Merging (Combining)

3Measurement precision

If comprehensive package information is collected and analyzed, then vulnerability identification accuracy is improved, but data processing time increases

Engineering Contradiction:
Improvevulnerability identification accuracyVSAvoiddata processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements preliminary actions by continuously collecting and organizing package information, process data, and vulnerability intelligence in the centralized scanner before actual vulnerability assessments are needed. This pre-processing and preparation of data structures enables rapid, accurate vulnerability identification when scanning is triggered, reducing the time required for comprehensive analysis while maintaining high detection accuracy.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11706239B2Systems and methods for detecting vulnerabilities in network processes during runtime
Publication Date: 2023.07.18 CISCO TECHNOLOGY INC
  • US11706239B2 patent drawing
  • US11706239B2 patent drawing
  • US11706239B2 patent drawing

AI summary

Systems, methods, and non-transitory computer-readable storage media are disclosed for detecting vulnerabilities in real-time during execution of a process or an application. In one example, a device may have one or more memories storing computer-readable instructions and one or more processors configured to execute the computer-readable instructions to obtain real-time process information associated with a process executing in an endpoint. The device can then determine package information for a package associated with the process based on the process information. The device can then identify at least one vulnerability associated with the package information using a database of vulnerabilities stored on a backend component of the network. The backend component may have a database of vulnerabilities for packages.