Event-Driven Vulnerability Scanning System
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
System administrators face challenges in ensuring that all vulnerabilities are detected and fixed in internet-connected assets, as they may not be aware of every detail of every system under their watch, leading to undetected vulnerabilities and uncertainty about the effectiveness of system changes.
Innovation Solution
An event-driven query system that receives indications from client systems, determines and performs scanning queries based on these indications, and provides a network status display, including historical and real-time vulnerability information, to ensure comprehensive scanning and monitoring of internet-connected assets.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If system administrators manually monitor and check each system under their watch, then they can detect system vulnerabilities, but they cannot be aware of every detail of every system leading to undetected vulnerabilities
Solution Approach 1:
The patent introduces an automated vulnerability scanning system as an intermediary between system administrators and the numerous internet-connected assets. This intermediary automatically performs comprehensive vulnerability scans across all systems, generating detailed reports that administrators can review. The system includes vulnerability detection modules, scanning engines, and reporting mechanisms that bridge the gap between limited human capacity and the need for complete vulnerability assessment.
Solution Approach 2:
The vulnerability scanning system enables systems to self-report their vulnerability status through automated scanning and assessment. The system automatically identifies, scans, and reports vulnerabilities without requiring continuous manual intervention, allowing administrators to receive periodic comprehensive reports rather than needing to manually check each system. This self-service approach ensures complete coverage while reducing administrative burden.
2Reliability
If system administrators perform comprehensive vulnerability scanning of all systems, then they can detect all vulnerabilities, but it is difficult to have full confidence that system changes fixed all vulnerabilities and did not create new ones
Solution Approach 1:
The patent implements a feedback mechanism where vulnerability scanning results are continuously monitored and compared before and after system changes. The system performs baseline scans, tracks system changes, and then performs follow-up scans to verify whether vulnerabilities were fixed or new vulnerabilities were introduced. This closed-loop feedback system provides administrators with confidence that changes had the intended security effect, with automated comparison and reporting of vulnerability status changes over time.
Solution Approach 2:
The system performs preliminary vulnerability scanning before system changes are implemented, establishing a baseline vulnerability profile. This preliminary action allows administrators to compare post-change scan results against the pre-change baseline, making it easier to determine whether changes fixed vulnerabilities or introduced new ones. The system automatically captures and stores baseline data for future comparison.
3Productivity
If manual system monitoring is performed, then some vulnerabilities can be detected, but the process is time-consuming and vulnerabilities may go undetected
Solution Approach 1:
The patent replaces manual mechanical monitoring processes with automated electronic vulnerability scanning systems. Instead of administrators manually checking each system, the system uses automated scanning engines, network probes, and software agents that continuously or periodically scan all internet-connected assets. This substitution dramatically increases both the speed (productivity) and thoroughness (precision) of vulnerability detection, allowing comprehensive coverage of all systems without proportionally increasing administrative time investment.
Data Source
AI summary
A system for an event driven query includes an input interface and a processor. The input interface is configured to receive an indication from a client system. The processor is configured to determine a scanning query based at least in part on the indication; and perform the scanning query.


