Distributed Vulnerability Scanning with Centralized Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current computer network vulnerability analysis systems are inefficient due to long scan times, limited accuracy, and potential network crashes, and lack effective data management and communication between departments, leading to false positives and undetected threats.

Innovation Solution

A distributed security management system with multiple vulnerability scanners across the network, a centralized management system (Lightning Console), and the use of both active and passive scanners to reduce scan time, improve accuracy, and correlate intrusion events with vulnerabilities, providing executive reporting and notification.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If a single active scanner is used to scan the entire network, then comprehensive vulnerability detection is achieved, but scan time becomes excessively long (up to two weeks)

Engineering Contradiction:
Improvevulnerability detection completenessVSAvoidscan time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The network is divided into multiple segments or zones, with distributed scanners deployed in different segments. Each scanner handles a portion of the network, enabling parallel scanning operations that reduce total scan time while maintaining comprehensive coverage through centralized result aggregation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Multiple distributed scanners are merged into a coordinated scanning system managed by a centralized console. The individual scanning operations are combined through centralized scheduling and result aggregation, achieving both the speed of parallel scanning and the comprehensiveness of unified network coverage.

Inventive Principle:
Principle #5Merging (Combining)

2Measurement precision

If active scanning is performed across network switches by probing devices, then vulnerability detection is achieved, but network devices may crash

Engineering Contradiction:
Improvevulnerability detection accuracyVSAvoidnetwork device stability
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

Scanners are deployed locally within network segments rather than scanning across the entire network from a single point. This local deployment allows scanning to be performed with reduced impact on distant network devices, while still achieving comprehensive vulnerability detection through coordinated scanning of all segments.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

A centralized vulnerability management console acts as an intermediary that coordinates scanning operations across distributed scanners. It manages scan scheduling, aggregates results, and controls the scanning process to minimize disruption to network devices while maintaining detection accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of manufacture

If a single scanner is placed in one network subnet, then the scanning system is simple to deploy, but the scanner cannot scan behind firewalls resulting in limited accuracy

Engineering Contradiction:
Improvesystem deployment simplicityVSAvoidscan accuracy
Core Design Contradiction:
Ease of manufactureVSMeasurement precision

Solution Approach 1:

The network is segmented into multiple zones with scanners deployed in different subnets and behind different firewalls. This segmentation allows each scanner to access previously unreachable network segments, improving overall scan accuracy while maintaining relatively simple deployment of individual scanner units.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The distributed scanning system provides multi-functional capability to scan networks from multiple locations and behind multiple firewalls. The system can adapt to various network topologies and firewall configurations, achieving comprehensive coverage without requiring complex deployment of each individual scanner.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Quantity of substance

If voluminous scan data is collected from multiple sources, then comprehensive vulnerability information is gathered, but data assimilation and interpretation become overwhelming

Engineering Contradiction:
Improvevulnerability data volumeVSAvoiddata processing complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

A centralized vulnerability management console serves as an intermediary that receives, normalizes, correlates, and presents scan data from multiple distributed scanners. It handles data assimilation and interpretation automatically, reducing the complexity burden on administrators while maintaining comprehensive vulnerability information.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system transforms raw scan data into standardized vulnerability assessments by changing data parameters and formats. It converts voluminous raw data from multiple sources into normalized, correlated vulnerability information that is easier to interpret and act upon.

Inventive Principle:
Principle #35Parameter changes

5Productivity

If events are filtered based on event name or variables without vulnerability context, then high priority events are identified, but false positives increase and true threats may be missed

Engineering Contradiction:
Improveevent filtering efficiencyVSAvoidthreat detection accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The system uses feedback from the vulnerability model (created from scan results) to refine event filtering and prioritization. Scan results provide context about actual vulnerabilities present in the network, which feeds back into the event correlation process to improve filtering accuracy and reduce false positives.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

Event filtering and vulnerability assessment are merged into a unified process. The system combines intrusion event data with vulnerability scan results to correlate events with actual vulnerabilities, improving both filtering efficiency and detection accuracy simultaneously.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS7926113B1System and method for managing network vulnerability analysis systems
Publication Date: 2011.04.12 TENABLE INC
  • US7926113B1 patent drawing
  • US7926113B1 patent drawing
  • US7926113B1 patent drawing

AI summary

Systems and methods to manage multiple vulnerability scanners distributed across one or more networks using a distributed security management system, herein called a Lightning Console. By distributing multiple scanners across a network, the work load of each scanner may be reduced to significantly reduce the impact on the network routing and switching infrastructure. In addition, scanners may be placed directly behind firewalls for more thorough scanning. Further, scanners may be placed closer to their scanned networks. By placing vulnerability scanners closer, the actual scanning traffic does not cross the core network switch and routing fabric, thereby avoiding potential network outages due to scanning activity. In addition, the closer distance of the scanners to the scanned targets speeds scan times by reducing the distance that the packets must traverse.