Distributed Vulnerability Scanning with Centralized Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current computer network vulnerability analysis systems are inefficient due to long scan times, limited accuracy, and potential network crashes, and lack effective data management and communication between departments, leading to false positives and undetected threats.
Innovation Solution
A distributed security management system with multiple vulnerability scanners across the network, a centralized management system (Lightning Console), and the use of both active and passive scanners to reduce scan time, improve accuracy, and correlate intrusion events with vulnerabilities, providing executive reporting and notification.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If a single active scanner is used to scan the entire network, then comprehensive vulnerability detection is achieved, but scan time becomes excessively long (up to two weeks)
Solution Approach 1:
The network is divided into multiple segments or zones, with distributed scanners deployed in different segments. Each scanner handles a portion of the network, enabling parallel scanning operations that reduce total scan time while maintaining comprehensive coverage through centralized result aggregation.
Solution Approach 2:
Multiple distributed scanners are merged into a coordinated scanning system managed by a centralized console. The individual scanning operations are combined through centralized scheduling and result aggregation, achieving both the speed of parallel scanning and the comprehensiveness of unified network coverage.
2Measurement precision
If active scanning is performed across network switches by probing devices, then vulnerability detection is achieved, but network devices may crash
Solution Approach 1:
Scanners are deployed locally within network segments rather than scanning across the entire network from a single point. This local deployment allows scanning to be performed with reduced impact on distant network devices, while still achieving comprehensive vulnerability detection through coordinated scanning of all segments.
Solution Approach 2:
A centralized vulnerability management console acts as an intermediary that coordinates scanning operations across distributed scanners. It manages scan scheduling, aggregates results, and controls the scanning process to minimize disruption to network devices while maintaining detection accuracy.
3Ease of manufacture
If a single scanner is placed in one network subnet, then the scanning system is simple to deploy, but the scanner cannot scan behind firewalls resulting in limited accuracy
Solution Approach 1:
The network is segmented into multiple zones with scanners deployed in different subnets and behind different firewalls. This segmentation allows each scanner to access previously unreachable network segments, improving overall scan accuracy while maintaining relatively simple deployment of individual scanner units.
Solution Approach 2:
The distributed scanning system provides multi-functional capability to scan networks from multiple locations and behind multiple firewalls. The system can adapt to various network topologies and firewall configurations, achieving comprehensive coverage without requiring complex deployment of each individual scanner.
4Quantity of substance
If voluminous scan data is collected from multiple sources, then comprehensive vulnerability information is gathered, but data assimilation and interpretation become overwhelming
Solution Approach 1:
A centralized vulnerability management console serves as an intermediary that receives, normalizes, correlates, and presents scan data from multiple distributed scanners. It handles data assimilation and interpretation automatically, reducing the complexity burden on administrators while maintaining comprehensive vulnerability information.
Solution Approach 2:
The system transforms raw scan data into standardized vulnerability assessments by changing data parameters and formats. It converts voluminous raw data from multiple sources into normalized, correlated vulnerability information that is easier to interpret and act upon.
5Productivity
If events are filtered based on event name or variables without vulnerability context, then high priority events are identified, but false positives increase and true threats may be missed
Solution Approach 1:
The system uses feedback from the vulnerability model (created from scan results) to refine event filtering and prioritization. Scan results provide context about actual vulnerabilities present in the network, which feeds back into the event correlation process to improve filtering accuracy and reduce false positives.
Solution Approach 2:
Event filtering and vulnerability assessment are merged into a unified process. The system combines intrusion event data with vulnerability scan results to correlate events with actual vulnerabilities, improving both filtering efficiency and detection accuracy simultaneously.
Data Source
AI summary
Systems and methods to manage multiple vulnerability scanners distributed across one or more networks using a distributed security management system, herein called a Lightning Console. By distributing multiple scanners across a network, the work load of each scanner may be reduced to significantly reduce the impact on the network routing and switching infrastructure. In addition, scanners may be placed directly behind firewalls for more thorough scanning. Further, scanners may be placed closer to their scanned networks. By placing vulnerability scanners closer, the actual scanning traffic does not cross the core network switch and routing fabric, thereby avoiding potential network outages due to scanning activity. In addition, the closer distance of the scanners to the scanned targets speeds scan times by reducing the distance that the packets must traverse.


