IP Security Control System with Risk-Based Port Scanning

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security control methods are inadequate in efficiently identifying and responding to cyber threats, particularly due to high false positive rates and the inability to effectively manage new and variant malicious codes, leading to increased costs and decreased security effectiveness.

Innovation Solution

A security control system that includes a server capable of scanning target IP addresses for risk levels, generating security reports, and identifying malicious codes and similar domains, allowing for preemptive action and reducing the burden of manual analysis.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network security method analyzes packets flowing into the network to identify malicious codes, then detection rate of malicious codes is improved, but false positive rate increases heavily due to numerous normal file packets

Engineering Contradiction:
Improvedetection rate of malicious codesVSAvoidfalse positive rate
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent segments the security analysis process into multiple specialized modules: URL analysis unit, malicious code detection unit, vulnerability detection unit, and security event correlation unit. Each module handles specific types of security threats independently, allowing the system to focus analysis on relevant data and reduce false positives from normal file packets.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a security event correlation unit that acts as an intermediary, collecting and correlating security events from multiple sources before generating alerts. This correlation layer filters out false positives by analyzing patterns across different security modules and only alerting on confirmed threat patterns.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of information

If vulnerability scanner is used to find and notify vulnerabilities, then number of vulnerabilities is identified, but administrator cannot obtain information on which vulnerability to solve first and manual analysis takes several weeks or months

Engineering Contradiction:
Improvenumber of vulnerabilities identifiedVSAvoidtime for manual analysis and prioritization
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent performs preliminary risk assessment and prioritization automatically through the security event correlation unit, which evaluates vulnerabilities based on multiple factors including exploit availability, impact severity, and asset criticality. This preliminary action provides administrators with pre-prioritized vulnerability lists, eliminating the need for time-consuming manual analysis.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system performs self-service vulnerability management by automatically scanning, detecting, correlating, and prioritizing vulnerabilities without requiring manual administrator intervention. The security event correlation unit autonomously generates actionable intelligence, allowing the system to serve itself in the vulnerability management process.

Inventive Principle:
Principle #25Self-service

3Reliability

If antivirus method is used to protect against presently known malicious codes, then protection against known threats is provided, but protection against new and variant malicious codes through forged websites is limited

Engineering Contradiction:
Improveprotection against known malicious codesVSAvoidprotection against new and variant malicious codes
Core Design Contradiction:
ReliabilityVSAdaptability or versatility

Solution Approach 1:

The patent performs preliminary security analysis on URLs and web content before users access potentially malicious sites. The URL analysis unit and malicious code detection unit proactively scan and evaluate web resources, identifying threats before they can infect user systems, thereby providing protection against both known and new malicious codes.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent adds new dimensions to security protection by incorporating URL analysis, domain reputation checking, and real-time web content scanning alongside traditional antivirus methods. This multi-dimensional approach enables detection of new and variant malicious codes through forged websites that traditional signature-based antivirus cannot detect.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS11811815B2IP-based security control method and system thereof
Publication Date: 2023.11.07 AI SPERA INC
  • US11811815B2 patent drawing
  • US11811815B2 patent drawing
  • US11811815B2 patent drawing

AI summary

The present disclosure relates to an IP-based security control method and a system thereof. According to the present disclosure, the method comprises: selecting a target IP address that is an IP address of a security control target; generating IP monitoring information by scanning a port of the target IP address; determining an IP risk level of the target IP address by using the IP monitoring information; and generating a security report including at least one of an IP list determined by a preset IP risk level and IP monitoring information of an IP included in the IP list, wherein the IP monitoring information includes at least one of an IP address of the target IP address, banner information, application information, security vulnerability information, a malicious code, and a similar domain.