Hybrid Network Security Assessment via Self and Remote Scanning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current vulnerability assessment techniques in enterprise networks are limited, as they often rely on a single targeting and assessment mechanism, which can be evaded by 'risk assessment' savvy malware, and are less reliable for disconnected machines and transient connections, such as those in remote and mobile computers.

Innovation Solution

Implementing a hybrid model that allows clients capable of self-assessment to perform local scans and combines these results with remote assessments, using a security server to direct self-assessments and perform unauthenticated port scans, thereby creating a comprehensive data set of security risks and vulnerabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If a single targeting and assessment mechanism is used, then the assessment process is simple, but the detection reliability deteriorates due to malware evasion

Engineering Contradiction:
Improveassessment mechanismVSAvoiddetection reliability
Core Design Contradiction:
Device complexityVSReliability

Solution Approach 1:

The patent combines multiple assessment mechanisms (self-assessment and remote assessment) into a unified vulnerability assessment system. The security server integrates results from both self-assessment agents and remote assessment agents, creating a comprehensive view of client vulnerabilities that cannot be evaded by single-mechanism malware evasion techniques.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent implements self-assessment where client computers perform their own vulnerability assessments using locally deployed agents. This allows clients to independently evaluate their security state without requiring continuous remote intervention, improving detection reliability while reducing the complexity of centralized assessment management.

Inventive Principle:
Principle #25Self-service

2Reliability

If remote assessment is performed on all clients, then detection coverage is complete, but network resource consumption increases

Engineering Contradiction:
Improvedetection coverageVSAvoidnetwork resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent segments the client population into different groups based on their assessment capabilities. Clients with self-assessment agents deployed can perform local assessments independently, while clients without agents or with transient connections undergo remote assessment. This segmentation reduces network resource consumption by avoiding redundant remote assessments of clients capable of self-evaluation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial remote assessment rather than comprehensive remote assessment of all clients. The security server selectively performs remote assessments only on clients that require it (those without self-assessment agents or with disconnected status), avoiding the excessive network resource consumption that would result from attempting to remotely assess every client regardless of their capabilities.

Inventive Principle:
Principle #16Partial or excessive action

3Use of energy by moving object

If self-assessment is used for all clients, then network resource consumption is reduced, but detection accuracy deteriorates due to potential local assessment limitations

Engineering Contradiction:
Improvenetwork resource consumptionVSAvoiddetection accuracy
Core Design Contradiction:
Use of energy by moving objectVSMeasurement precision

Solution Approach 1:

The patent implements a feedback mechanism where the security server compares and cross-checks assessment results from both self-assessment agents and remote assessment agents. This feedback loop allows the system to identify discrepancies between local and remote assessment results, improving detection accuracy by validating findings through multiple independent assessment mechanisms.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent merges self-assessment results with remote assessment results into a unified vulnerability profile for each client. The security server integrates data from both assessment types, using the combined information to produce more accurate and comprehensive vulnerability reports that overcome the limitations of either assessment method used in isolation.

Inventive Principle:
Principle #5Merging (Combining)

4Adaptability or versatility

If external assessment is performed before network connection, then disconnected clients can be assessed, but the transient nature of connections makes assessment unreliable

Engineering Contradiction:
Improveassessment accessibilityVSAvoidassessment reliability
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent performs preliminary self-assessment actions on clients before they connect to the network. Clients with self-assessment agents can complete their vulnerability assessments locally in advance, so that when they connect, their assessment results are already available and can be immediately integrated into the network security profile without requiring redundant remote assessment.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8302196B2Combining assessment models and client targeting to identify network security vulnerabilities
Publication Date: 2012.10.30 MICROSOFT TECHNOLOGY LICENSING LLC
  • US8302196B2 patent drawing
  • US8302196B2 patent drawing
  • US8302196B2 patent drawing

AI summary

Described is a technology for managing network security by having network clients that are capable of self-assessment assess themselves for security risks and/or security vulnerabilities. Other clients may be remotely assessed for security risks and/or security vulnerabilities. Assessments may include antimalware scans, vulnerability assessment, and/or port scans. The results of the self-assessments and remote assessments are combined into a data set (e.g., a view) indicative of the network security state. In this manner, for example, significant network resources are conserved by allowing those clients capable of self-assessment to assess themselves and thereafter only provide their self-assessment results. Clients capable of self-assessment may also be remotely assessed, to determine whether any discrepancies exist between their remote assessments and self-assessments. Clients may be discovered, along with their self-assessment capabilities, by network communication.