Automated Ad Hoc CPE Bi-Directional Vulnerability Scanning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current vulnerability scanning of customer premise equipment (CPE) is time-consuming and labor-intensive due to the need for manual configuration and the complexity of managing multiple types of CPEs with varying makes, models, and firmware updates, especially when performing bi-directional scans across service provider and customer-facing networks.

Innovation Solution

An automated ad hoc bi-directional vulnerability scanning system that uses an auto provisioning server to receive CPE information, obtain telemetry data, configure VLAN channels, and initiate scans from both WAN and LAN sides using MAC addresses, enabling automated configuration verification and report generation for security certification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual configuration and setup is performed for vulnerability scanning, then scan accuracy and completeness can be ensured, but the process becomes time-consuming and labor-intensive

Engineering Contradiction:
Improvescan accuracyVSAvoidscan turnaround time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by automatically obtaining telemetry data from CMTS, pre-configuring VLAN channels, and pre-provisioning scanners with IP addresses before the actual vulnerability scan begins. This eliminates manual setup time while maintaining scan accuracy through automated configuration verification.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The vulnerability scanning system performs self-service by automatically provisioning itself with CPE information, configuring network paths, and executing scans without human intervention. The auto provisioning server handles all configuration tasks, including obtaining telemetry data, setting up VLAN channels, and coordinating between WAN and LAN scanners.

Inventive Principle:
Principle #25Self-service

2Reliability

If comprehensive bi-directional scanning is performed across both WAN and LAN sides, then security coverage is improved, but system complexity and configuration difficulty increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The auto provisioning server performs multiple functions including obtaining CPE information, retrieving telemetry data, configuring VLAN channels, provisioning IP addresses, and coordinating both WAN and LAN scanners. This multi-functional approach simplifies the overall system architecture while maintaining comprehensive bi-directional security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The auto provisioning server acts as an intermediary that coordinates between the CMTS, VLAN switches, WAN scanner, and LAN scanner. It manages the complexity of bi-directional scanning by centralizing configuration control and automatically establishing the necessary network paths and connections.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Manufacturing precision

If manual access and physical setup is required for each CPE device, then configuration accuracy can be verified, but the workload increases significantly for large volumes of devices

Engineering Contradiction:
Improveconfiguration accuracyVSAvoidtesting throughput
Core Design Contradiction:
Manufacturing precisionVSProductivity

Solution Approach 1:

The system replaces manual mechanical access to physical devices with automated electronic configuration. The auto provisioning server electronically provisions VLAN channels, obtains IP addresses programmatically, and coordinates scans remotely, eliminating the need for physical access to each CPE device while maintaining configuration accuracy through automated verification.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system creates virtual copies of network paths through VLAN channels, allowing remote access to CPE devices without physical connection. The LAN scanner obtains IP addresses and performs scans through virtual network interfaces, replicating the functionality of physical access in a virtualized environment.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11616802B2Methods and system for automated ad hoc customer premise equipment bi-directional vulnerability scanning
Publication Date: 2023.03.28 CHARTER COMM OPERATING LLC
  • US11616802B2 patent drawing
  • US11616802B2 patent drawing
  • US11616802B2 patent drawing

AI summary

Methods and systems for automated ad hoc customer premise equipment (CPE) bi-directional vulnerability scanning. A method includes an auto provisioning server receiving CPE information for a designated CPE to initiate a bi-directional vulnerability scan, obtaining telemetry data from a cable modem termination system (CMTS) based on the CPE information, configuring switches to form a virtual local area network channel between a LAN scanner and the designated CPE using the CPE information, provisioning the LAN scanner to obtain a LAN side Internet Protocol (IP) address from the designated CPE, initiating vulnerability scans at a wide area network (WAN) scanner and the LAN scanner using a stored WAN side IP address and a stored LAN side IP address, respectively, and generating a vulnerability scan report based on results from the WAN scanner and the LAN scanner. At least one network device can be configured based on the report.