Endpoint Passive Scanners for Network Visibility via Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional passive network monitoring techniques are limited in visibility and miss local or remote network traffic, leading to incomplete asset discovery and vulnerability identification, especially in complex network environments with virtualization and cloud integration.

Innovation Solution

Deploying endpoint passive scanners across network endpoints to sniff and analyze network traffic, combining passive asset discovery with endpoint agent vulnerability scanning, providing a comprehensive view of assets and vulnerabilities that conventional methods may miss.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If passive network monitoring is used to discover assets and identify vulnerabilities, then the scanning process is non-intrusive and does not disrupt network operations, but the visibility is limited and local network traffic is missed

Engineering Contradiction:
Improvenon-intrusive scanningVSAvoidnetwork visibility
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The system divides the network monitoring function into two segments: external passive scanners that monitor traffic at network boundaries, and internal endpoint agents deployed on individual devices that monitor local traffic. This segmentation allows each component to focus on specific traffic paths, improving overall visibility without disrupting network operations.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Endpoint agents act as intermediaries between local network traffic and the central vulnerability management system. These agents capture and report local traffic information to external scanners, enabling comprehensive monitoring while maintaining the non-intrusive nature of passive scanning.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If endpoint agents are deployed on network devices, then local network traffic becomes visible and detection capability improves, but device complexity and deployment overhead increase

Engineering Contradiction:
Improvevulnerability detection capabilityVSAvoiddeployment complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The endpoint agent is designed as a universal, multi-functional component that can be deployed across diverse network devices (endpoints, servers, network equipment). It provides consistent vulnerability detection, asset discovery, and traffic monitoring capabilities regardless of the host device type, simplifying deployment across heterogeneous environments.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The endpoint agent is designed to be self-configuring and self-managing to the extent possible, reducing deployment complexity. It automatically discovers local network topology, identifies assets and services, and reports findings to the central system without requiring extensive manual configuration.

Inventive Principle:
Principle #25Self-service

3Productivity

If passive scanning is used, then network operations are not disrupted, but incomplete asset discovery occurs in complex network environments

Engineering Contradiction:
Improvenetwork operation continuityVSAvoidasset discovery completeness
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The system adds a new dimension to passive scanning by deploying monitoring capabilities at multiple levels: external network boundary scanners and internal endpoint agents on individual devices. This multi-dimensional approach captures traffic from different perspectives, completing asset discovery in complex networks while maintaining operational continuity.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Solution Approach 2:

Endpoint agents perform preliminary asset discovery and vulnerability identification locally before central scanners analyze the data. This preliminary action at the endpoint ensures that even traffic not visible to external scanners is captured and reported, improving completeness without disrupting network operations.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11930031B2Distributed network based vulnerability scanning via endpoint agent deployment
Publication Date: 2024.03.12 TENABLE INC
  • US11930031B2 patent drawing
  • US11930031B2 patent drawing
  • US11930031B2 patent drawing

AI summary

Techniques, methods and/or apparatuses are disclosed that enable passive scanning of a network. Through the disclosed techniques, methods and/or apparatuses, endpoint passive scanners are deployed at endpoints of the network to provide more comprehensive view of assets and asset information of the network. Also, this can enable better correlation of network data to location, and also enable improved vulnerability analysis for endpoint products.