Distributed Cybersecurity Data Collection via Traffic Masking

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity data collection methods face challenges in effectively gathering information due to increasing sophistication of network security measures, such as firewalls, which can block or misidentify scanning operations, and existing traffic masking technologies are not designed for high-speed scanning tasks, resulting in incomplete or inaccurate risk assessments.

Innovation Solution

A distributed cybersecurity data collection system that assigns node devices to logical groups based on geographic, geopolitical, or technical characteristics, using executable file packages with data collection agents to perform tasks like IP scanning and web crawling, while masking traffic using proxies or VPNs to evade detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If firewalls and network security measures are used to protect against scanning operations, then cybersecurity protection is improved, but data collection effectiveness deteriorates due to blocked or incorrect information

Engineering Contradiction:
Improvecybersecurity protectionVSAvoiddata collection effectiveness
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent employs proxies as intermediary devices that stand between the data collector and the target network. These proxies mask the original IP address and traffic patterns, allowing data collection operations to proceed without being directly blocked by firewalls. The intermediary enables information gathering while maintaining security protection.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system dynamically modifies traffic parameters such as IP addresses, port numbers, timing intervals, and data packet sizes to evade detection. By changing these parameters, the data collection traffic appears as legitimate user traffic rather than systematic scanning, allowing it to bypass security measures while maintaining collection effectiveness.

Inventive Principle:
Principle #35Parameter changes

2Adaptability or versatility

If existing traffic masking technologies like proxies or VPNs are used, then traffic masking capability is improved, but productivity deteriorates because they are not designed for high-speed scanning and data collection operations

Engineering Contradiction:
Improvetraffic masking capabilityVSAvoiddata collection speed
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The patent divides the data collection system into multiple distributed nodes spread across different networks. Each node performs a portion of the scanning and data collection tasks independently, allowing the system to handle high-speed operations by parallelizing work across multiple segments rather than relying on a single masked connection.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system dynamically selects and switches between different proxies and network routes based on real-time performance and availability. This dynamic adaptation allows the system to maintain high-speed data collection by choosing optimal paths while preserving traffic masking capabilities when needed.

Inventive Principle:
Principle #15Dynamics

3Device complexity

If data collection is performed from a single location with fixed parameters, then device complexity is reduced, but measurement precision deteriorates due to narrow snapshot of cybersecurity risks

Engineering Contradiction:
Improvedata collection system structureVSAvoidcybersecurity risk assessment accuracy
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent introduces multiple dimensions to the data collection approach by deploying nodes across different geographical locations, networks, and time periods. This multi-dimensional perspective allows the system to capture cybersecurity risks from various angles and contexts, significantly improving measurement precision without requiring overly complex centralized control.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

Each data collection node is configured with local characteristics such as specific IP addresses, network topologies, and traffic patterns appropriate to its location. This allows each node to perform data collection with high precision for its local context while the overall system aggregates these localized insights for comprehensive risk assessment.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS20240106850A1Distributed system for cybersecurity data collection and traffic masking
Publication Date: 2024.03.28 SECURITYSCORECARD INC
  • US20240106850A1 patent drawing
  • US20240106850A1 patent drawing
  • US20240106850A1 patent drawing

AI summary

The present disclosure provides a systems, methods, and computer-readable media for distributed cybersecurity data collection and traffic masking. According to some aspects, a system includes a server and multiple logical groups of node devices associated with respective characteristics. The characteristics may be related to different geographical or geopolitical locations, different scheduled operations, or the like. A first node device of a first logical group may execute a data collection agent based on first parameter values corresponding to characteristics of the logical first group to communicate first masked traffic to a network target to obtain first cybersecurity data. A second node device of a second logical group may execute the data collection agent based on second parameter values corresponding to characteristics of the second logical group to communicate second masked traffic to the network target to obtain second cybersecurity data. The node devices send the respective cybersecurity data to the server.