Hybrid Network Security Assessment via Self and Remote Scanning
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current vulnerability assessment techniques in enterprise networks are limited, as they often rely on a single targeting and assessment mechanism, which can be evaded by 'risk assessment' savvy malware, and are less reliable for disconnected machines and transient connections, such as those in remote and mobile computers.
Innovation Solution
Implementing a hybrid model that allows clients capable of self-assessment to perform local scans and combines these results with remote assessments, using a security server to direct self-assessments and perform unauthenticated port scans, thereby creating a comprehensive data set of security risks and vulnerabilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Device complexity
If a single targeting and assessment mechanism is used, then the assessment process is simple, but the detection reliability deteriorates due to malware evasion
Solution Approach 1:
The patent combines multiple assessment mechanisms (self-assessment and remote assessment) into a unified vulnerability assessment system. The security server integrates results from both self-assessment agents and remote assessment agents, creating a comprehensive view of client vulnerabilities that cannot be evaded by single-mechanism malware evasion techniques.
Solution Approach 2:
The patent implements self-assessment where client computers perform their own vulnerability assessments using locally deployed agents. This allows clients to independently evaluate their security state without requiring continuous remote intervention, improving detection reliability while reducing the complexity of centralized assessment management.
2Reliability
If remote assessment is performed on all clients, then detection coverage is complete, but network resource consumption increases
Solution Approach 1:
The patent segments the client population into different groups based on their assessment capabilities. Clients with self-assessment agents deployed can perform local assessments independently, while clients without agents or with transient connections undergo remote assessment. This segmentation reduces network resource consumption by avoiding redundant remote assessments of clients capable of self-evaluation.
Solution Approach 2:
The patent applies partial remote assessment rather than comprehensive remote assessment of all clients. The security server selectively performs remote assessments only on clients that require it (those without self-assessment agents or with disconnected status), avoiding the excessive network resource consumption that would result from attempting to remotely assess every client regardless of their capabilities.
3Use of energy by moving object
If self-assessment is used for all clients, then network resource consumption is reduced, but detection accuracy deteriorates due to potential local assessment limitations
Solution Approach 1:
The patent implements a feedback mechanism where the security server compares and cross-checks assessment results from both self-assessment agents and remote assessment agents. This feedback loop allows the system to identify discrepancies between local and remote assessment results, improving detection accuracy by validating findings through multiple independent assessment mechanisms.
Solution Approach 2:
The patent merges self-assessment results with remote assessment results into a unified vulnerability profile for each client. The security server integrates data from both assessment types, using the combined information to produce more accurate and comprehensive vulnerability reports that overcome the limitations of either assessment method used in isolation.
4Adaptability or versatility
If external assessment is performed before network connection, then disconnected clients can be assessed, but the transient nature of connections makes assessment unreliable
Solution Approach 1:
The patent performs preliminary self-assessment actions on clients before they connect to the network. Clients with self-assessment agents can complete their vulnerability assessments locally in advance, so that when they connect, their assessment results are already available and can be immediately integrated into the network security profile without requiring redundant remote assessment.
Data Source
AI summary
Described is a technology for managing network security by having network clients that are capable of self-assessment assess themselves for security risks and/or security vulnerabilities. Other clients may be remotely assessed for security risks and/or security vulnerabilities. Assessments may include antimalware scans, vulnerability assessment, and/or port scans. The results of the self-assessments and remote assessments are combined into a data set (e.g., a view) indicative of the network security state. In this manner, for example, significant network resources are conserved by allowing those clients capable of self-assessment to assess themselves and thereafter only provide their self-assessment results. Clients capable of self-assessment may also be remotely assessed, to determine whether any discrepancies exist between their remote assessments and self-assessments. Clients may be discovered, along with their self-assessment capabilities, by network communication.


