Cloud Vulnerability Scanner Using Reverse SSH Tunnels
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current computer network vulnerability scanning methods are inefficient and challenging for IT administrators, especially in large networks with numerous nodes, as they require extensive manual checks and struggle to identify vulnerabilities visible only from external perspectives, which are often obscured by internal scanning.
Innovation Solution
A cloud-based system establishes secure tunnels using reverse SSH protocols to enable communication between scanners in public networks and controllers in private networks, allowing for comprehensive vulnerability scanning by simulating external views of assets and detecting vulnerabilities that internal scans may miss.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If internal vulnerability scanning is performed within private networks, then scanning coverage is limited to internal perspectives, but vulnerabilities visible only from external perspectives remain undetected
Solution Approach 1:
The patent inverts the traditional scanning architecture by placing scanners in public networks instead of private networks. This allows the scanning function to view assets from external perspectives, detecting vulnerabilities that internal scanners cannot see. The scan controllers remain in private networks to maintain security, while scanners operate in public networks to provide external viewpoint coverage.
Solution Approach 2:
The patent introduces secure tunnels as intermediaries connecting scanners in public networks with scan controllers in private networks. These tunnels enable communication between the external scanning components and internal control systems without exposing the private network directly, thus maintaining security while enabling external perspective scanning.
2Measurement precision
If scanners are deployed in public networks, then external vulnerability perspectives can be detected, but secure communication with internal controllers becomes more complex
Solution Approach 1:
Secure tunnels act as intermediaries that establish encrypted communication channels between scanners in public networks and scan controllers in private networks. This mediator approach enables secure data transmission without requiring direct network exposure or complex security infrastructure modifications.
Solution Approach 2:
The system preemptively establishes secure tunnels before scanners need to communicate with controllers. This preliminary security setup prevents potential security issues from arising during operation, ensuring that all communication between public and private network components is protected from the outset.
3Measurement precision
If multiple vulnerability checks are performed across numerous network nodes, then comprehensive vulnerability identification is achieved, but scanning time and administrative overhead increase significantly
Solution Approach 1:
The patent segments the vulnerability scanning system into distributed scanners operating in public networks, each capable of independently scanning different assets or asset groups. This segmentation allows parallel scanning operations, reducing total scanning time while maintaining comprehensive coverage through coordinated scanning efforts.
Solution Approach 2:
Scanners deployed in public networks can autonomously perform vulnerability checks without requiring constant administrative intervention. The scan controllers in private networks manage the scanning operations and process results automatically, reducing administrative overhead while maintaining comprehensive scanning coverage.
Data Source
Figure 1
Figure 2
Figure 3~5
AI summary
A method in one embodiment includes establishing a first secure tunnel between a scanner and a configuration manager, and a second secure tunnel between the scanner and a scan controller, where the scanner is located in a public network and the configuration manager and the scan controller are located in a private network, communicating scanner configuration information between the scanner and the configuration manager over the first secure tunnel, and communicating scan information between the scanner and the scan controller over the second secure tunnel. The secure tunnels may be established from within the private network, by forwarding a first origination port and a second origination port to a first destination port and a second destination port, respectively. The first and second origination ports may be located in the public network, and the first and second destination ports may be located in the private network.