Distributed Network Scanning via Segmented Job Distribution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Scanning large networks for security vulnerabilities requires significant computing power and bandwidth, often exceeding the capabilities of a single computer, and may result in undetected vulnerabilities due to the complexity of managing multiple interconnected systems.

Innovation Solution

A distributed network scanning system comprising a master controller and multiple scanning nodes that divide the scanning task into job portions, allowing each node to perform a portion of the scan and combine results for a comprehensive view, utilizing cloud computing hardware for scalability and anonymization to avoid detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If a single computer performs the network scan, then the scanning process is simple to manage, but the computing power and bandwidth are insufficient to scan large networks adequately

Engineering Contradiction:
Improvescanning capabilityVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent divides the network scanning task into multiple job portions and distributes them across multiple scanning nodes. Each node scans a specific subset of network addresses, allowing the system to handle large networks that would be impossible for a single computer to scan adequately.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent combines the scanning results from multiple independent scanning nodes to produce a comprehensive view of the entire network. The master controller aggregates data from all nodes, providing complete network coverage while maintaining manageable individual node complexity.

Inventive Principle:
Principle #5Merging (Combining)

2Productivity

If multiple scanning nodes are used to scan large networks, then the scanning capability increases, but the complexity of managing the distributed system increases

Engineering Contradiction:
Improvescanning capabilityVSAvoidmanagement complexity
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent introduces a master controller as an intermediary that manages the distributed scanning nodes. The master controller assigns job portions to nodes, collects results, and coordinates the overall scanning process, simplifying management of the distributed system while maintaining high scanning capability.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Power

If distributed scanning is implemented, then the computational burden is reduced on individual systems, but the coordination and communication overhead increases

Engineering Contradiction:
Improvecomputational capacityVSAvoidcoordination complexity
Core Design Contradiction:
PowerVSDevice complexity

Solution Approach 1:

The patent segments the scanning workload into independent job portions that can be executed in parallel by multiple nodes. This segmentation reduces the computational burden on each individual system while the master controller manages coordination through simple job assignment and result collection protocols.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS12132754B2Distributed scanning
Publication Date: 2024.10.29 PALO ALTO NETWORKS INC
  • US12132754B2 patent drawing
  • US12132754B2 patent drawing
  • US12132754B2 patent drawing

AI summary

A distributed system of scanning nodes is provided job portions to collectively scan network systems numbering in the tens of thousands and beyond million across the Internet. A scanning controller creates the job portions to fulfill a scanning request. The scanning controller creates the job portions based on availability of scanning nodes and a size of the scanning request (i.e., number of network addresses indicated by the request). The scanning controller creates each job portion with scanning instructions for an available scanning node to execute on a selected set of the network addresses indicated in the request, with each job portion having a different set of addresses to scan and being independently executable.