Cloud-Based Vulnerability Scanning for Remote Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current vulnerability scanning methods are inefficient and costly due to the need for multiple scanning tools, generate false positives, and are challenging in decentralized network architectures, particularly in environments with poor network connectivity.

Innovation Solution

A system that creates a cloned device in a service provider's cloud network based on configuration and context information of a remote device, allowing vulnerability scanning to be performed efficiently, reducing overheads and redundant scans, and filtering results to provide actionable insights.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple scanning tools are used to identify different types of vulnerabilities, then vulnerability detection capability is improved, but system complexity and cost increase

Engineering Contradiction:
Improvevulnerability detection capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple scanning tools into a unified vulnerability scanning system that manages and coordinates different scanning tools through a single interface, reducing system complexity while maintaining comprehensive vulnerability detection capabilities

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The vulnerability scanning system is designed to perform multiple scanning functions using a single unified platform that can select and deploy appropriate scanning tools based on the target device type, eliminating the need for separate dedicated systems for each vulnerability type

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If vulnerability scanning is performed directly on remote devices in decentralized networks, then scanning coverage is improved, but resource usage and network overhead increase

Engineering Contradiction:
Improvescanning coverageVSAvoidresource usage
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent introduces an intermediary vulnerability scanning system that acts as a mediator between the centralized service provider and remote devices, performing scanning operations remotely to reduce resource consumption and network overhead on the actual target devices

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system creates virtual representations or models of remote devices to perform vulnerability scanning on copies rather than directly on the original devices, reducing the impact on actual device resources and network bandwidth

Inventive Principle:
Principle #26Copying

3Reliability

If dedicated infrastructure is provided for vulnerability scanning in cloud networks, then scanning reliability is improved, but infrastructure cost and time consumption increase

Engineering Contradiction:
Improvescanning reliabilityVSAvoidinfrastructure resources
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The vulnerability scanning system is designed as a universal platform that can scan multiple device types and configurations using the same infrastructure, reducing the need for dedicated infrastructure resources for each scanning operation

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system dynamically adjusts scanning parameters and tool selection based on the target device characteristics, allowing the same infrastructure to adapt to different scanning scenarios without requiring dedicated resources for each case

Inventive Principle:
Principle #35Parameter changes

4Adaptability or versatility

If scanning tools are used in environments with poor network connectivity, then remote device scanning is enabled, but false positive results increase

Engineering Contradiction:
Improveremote scanning capabilityVSAvoidresult accuracy
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The system performs preliminary configuration and setup operations before the actual vulnerability scanning, including downloading necessary scanning databases and configuring tools appropriately for the target device, which helps reduce false positives even in poor network conditions

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The vulnerability scanning system implements feedback mechanisms that analyze scanning results to identify and filter false positives, using information from previous scans and device context to improve result accuracy

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11803646B2Vulnerability scanning
Publication Date: 2023.10.31 HEWLETT PACKARD ENTERPRISE DEV LP
  • US11803646B2 patent drawing
  • US11803646B2 patent drawing
  • US11803646B2 patent drawing

AI summary

Aspects of vulnerability scanning are disclosed. In one example, configuration and context information of a first device for which vulnerability scanning is to be performed is obtained. The configuration information includes telemetry data of the first device. A second device is provisioned based on the configuration information to create a cloned first device. The vulnerability scanning is performed on the cloned first device based on the context information to obtain a scan report.