Cloud Vulnerability Scanner Using Reverse SSH Tunnels

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer network vulnerability scanning methods are inefficient and challenging for IT administrators, especially in large networks with numerous nodes, as they require extensive manual checks and struggle to identify vulnerabilities visible only from external perspectives, which are often obscured by internal scanning.

Innovation Solution

A cloud-based system establishes secure tunnels using reverse SSH protocols to enable communication between scanners in public networks and controllers in private networks, allowing for comprehensive vulnerability scanning by simulating external views of assets and detecting vulnerabilities that internal scans may miss.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If internal vulnerability scanning is performed within private networks, then scanning coverage is limited to internal perspectives, but vulnerabilities visible only from external perspectives remain undetected

Engineering Contradiction:
Improvevulnerability detection accuracyVSAvoidscanning perspective coverage
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent inverts the traditional scanning architecture by placing scanners in public networks instead of private networks. This allows the scanning function to view assets from external perspectives, detecting vulnerabilities that internal scanners cannot see. The scan controllers remain in private networks to maintain security, while scanners operate in public networks to provide external viewpoint coverage.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent introduces secure tunnels as intermediaries connecting scanners in public networks with scan controllers in private networks. These tunnels enable communication between the external scanning components and internal control systems without exposing the private network directly, thus maintaining security while enabling external perspective scanning.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If scanners are deployed in public networks, then external vulnerability perspectives can be detected, but secure communication with internal controllers becomes more complex

Engineering Contradiction:
Improveexternal vulnerability detectionVSAvoidcommunication infrastructure
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

Secure tunnels act as intermediaries that establish encrypted communication channels between scanners in public networks and scan controllers in private networks. This mediator approach enables secure data transmission without requiring direct network exposure or complex security infrastructure modifications.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system preemptively establishes secure tunnels before scanners need to communicate with controllers. This preliminary security setup prevents potential security issues from arising during operation, ensuring that all communication between public and private network components is protected from the outset.

Inventive Principle:
Principle #9Preliminary anti-action

3Measurement precision

If multiple vulnerability checks are performed across numerous network nodes, then comprehensive vulnerability identification is achieved, but scanning time and administrative overhead increase significantly

Engineering Contradiction:
Improvevulnerability identification completenessVSAvoidscanning duration
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent segments the vulnerability scanning system into distributed scanners operating in public networks, each capable of independently scanning different assets or asset groups. This segmentation allows parallel scanning operations, reducing total scanning time while maintaining comprehensive coverage through coordinated scanning efforts.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Scanners deployed in public networks can autonomously perform vulnerability checks without requiring constant administrative intervention. The scan controllers in private networks manage the scanning operations and process results automatically, reducing administrative overhead while maintaining comprehensive scanning coverage.

Inventive Principle:
Principle #25Self-service

Data Source

PatentEP2798768B1System and method for cloud based scanning for computer vulnerabilities in a network environment
Publication Date: 2020.04.15 MCAFEE LLC
  • EP2798768B1 patent drawingFigure 1
  • EP2798768B1 patent drawingFigure 2
  • EP2798768B1 patent drawingFigure 3~5

AI summary

A method in one embodiment includes establishing a first secure tunnel between a scanner and a configuration manager, and a second secure tunnel between the scanner and a scan controller, where the scanner is located in a public network and the configuration manager and the scan controller are located in a private network, communicating scanner configuration information between the scanner and the configuration manager over the first secure tunnel, and communicating scan information between the scanner and the scan controller over the second secure tunnel. The secure tunnels may be established from within the private network, by forwarding a first origination port and a second origination port to a first destination port and a second destination port, respectively. The first and second origination ports may be located in the public network, and the first and second destination ports may be located in the private network.