Drone-Based Network Vulnerability Detection and Patching

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large and isolated networks, such as those found in college campuses, laboratories, and military bases, face challenges in identifying and resolving cyber security vulnerabilities due to their size and inaccessibility, making it inefficient for security personnel to physically visit these areas for detection and resolution.

Innovation Solution

A drone-based network vulnerability detection system that identifies and resolves network vulnerabilities by navigating preconfigured routes, detecting vulnerabilities using onboard tools, transmitting information to a command center, and applying resolutions autonomously or upon receipt from the center.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If security personnel physically visit large and isolated areas to detect and resolve vulnerabilities, then detection accuracy is improved, but time consumption and operational efficiency deteriorate

Engineering Contradiction:
Improvevulnerability detection accuracyVSAvoidtime consumption
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent replaces the mechanical system of physical security personnel visits with an automated drone-based system equipped with vulnerability detection tools. The drone autonomously navigates to target devices, transmits code to exploit vulnerabilities, and receives resolutions without human physical presence, thereby maintaining detection accuracy while dramatically reducing time consumption.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables self-service automation where the drone independently performs vulnerability detection, transmits exploitation code, receives resolutions from the server, and executes patching operations without requiring security personnel to physically visit each device. This automated workflow maintains detection effectiveness while eliminating manual intervention time.

Inventive Principle:
Principle #25Self-service

2Reliability

If security personnel manually detect and resolve vulnerabilities in isolated networks, then security reliability is improved, but operational complexity increases

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidoperational complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The drone is designed as a universal platform that integrates multiple functions: autonomous navigation to isolated devices, vulnerability detection through transmitted code, communication with external servers, and automated resolution application. This multi-functional design maintains security reliability while consolidating complex operations into a single automated system rather than requiring multiple separate manual processes.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The drone acts as an intermediary between the isolated network devices and the external command server. It transmits vulnerability detection code to devices, receives exploitation results, obtains resolutions from the server, and applies patches. This intermediary role maintains security reliability by ensuring proper communication and validation while simplifying operational complexity by automating the entire intermediary process without manual intervention.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If drones autonomously navigate and detect vulnerabilities, then productivity is improved, but system complexity increases

Engineering Contradiction:
Improvevulnerability resolution efficiencyVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system performs preliminary actions by pre-configuring the drone with vulnerability detection code and navigation capabilities before deployment. The server maintains a pre-established database of known vulnerabilities and their corresponding resolutions. This preliminary preparation enables the drone to autonomously execute high-productivity operations without requiring complex real-time decision-making, thereby improving productivity while managing system complexity through advance configuration.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements a feedback loop where the drone transmits vulnerability detection results to the server, receives validated resolutions, and executes patching. The server provides feedback by verifying vulnerabilities and supplying appropriate resolutions. This structured feedback mechanism improves productivity by automating the detection-resolution cycle while managing complexity through clear, rule-based communication protocols between the drone and server.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11522897B2Detecting and patching network vulnerabilities
Publication Date: 2022.12.06 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US11522897B2 patent drawing
  • US11522897B2 patent drawing
  • US11522897B2 patent drawing

AI summary

Embodiments of the present invention disclose a method, a computer program product, and a computer system for a drone-based network vulnerability detection system. According to embodiments of the present invention, a drone receives routes and protocols for detecting and resolving network vulnerabilities. The drone identifies one or more electronic devices connected to one or more networks within an area of interest and detects one or more network vulnerabilities of the one or more electronic devices. If the drone detects a vulnerability, the drone updates a command center and identifies a resolution to the one or more network vulnerabilities. The drone then resolves the one or more network vulnerabilities based on the identified resolution.