Multi-Context Event Streaming Vulnerability Scanner

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional network vulnerability scanning tools are inadequate in efficiently assessing security postures in complex, dynamic networks with virtualization and cloud-computing technologies, as they often require sequential execution of test programs and lack adaptability to real-time context findings.

Innovation Solution

A multi-context event streaming network vulnerability scanner system that executes multiple test programs concurrently, adapts scan strategies based on real-time context findings, and uses a scanner engine to initiate and manage test programs, sending and receiving data across the network to identify vulnerabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If traditional network vulnerability scanning tools are used, then they can identify security vulnerabilities on the network, but they require sequential execution of test programs which increases scan time and reduces efficiency

Engineering Contradiction:
Improvescan efficiencyVSAvoidscan time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The scanner engine dynamically manages test program execution by allowing concurrent execution of multiple test programs based on real-time context findings. The system transitions from static sequential execution to dynamic concurrent execution, where test programs can be started, paused, or cancelled based on evolving network conditions and discovered vulnerabilities during the scan process.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system performs preliminary actions by initiating multiple test programs concurrently rather than waiting for each to complete sequentially. Test programs are launched in parallel based on initial context assessment, and the scanner engine continuously monitors and adjusts execution based on findings, effectively performing multiple scanning operations simultaneously to reduce total scan time.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If traditional network vulnerability scanning tools are used, then they can assess network security, but they lack adaptability to real-time context findings which reduces accuracy and relevance

Engineering Contradiction:
Improvevulnerability assessment accuracyVSAvoidadaptability to real-time context
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The scanner engine implements continuous feedback mechanisms where context findings from running test programs are immediately processed and used to influence subsequent test program execution. The system monitors findings in real-time and uses this feedback to dynamically adjust the scanning strategy, starting new test programs based on discovered vulnerabilities and modifying execution priorities to focus on high-risk areas identified during the scan.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The scanning system transitions from a static, pre-defined test sequence to a dynamic, adaptive process where test program execution is continuously adjusted based on real-time context findings. The scanner engine can modify which test programs run, when they run, and their execution priorities based on evolving network conditions and vulnerability discoveries, enhancing both accuracy and adaptability.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS8938531B1Apparatus, system and method for multi-context event streaming network vulnerability scanner
Publication Date: 2015.01.20 DIGITAL DEFENSE INC
  • US8938531B1 patent drawing
  • US8938531B1 patent drawing
  • US8938531B1 patent drawing

AI summary

An apparatus, systems, and methods for multi-context event streaming network vulnerability scanners. A method is disclosed for scanning a network by executing a first test program, receiving data from one or more devices on a network in response to the data sent by the first test program, determining one or more context findings from the first test program, and reporting the one or more context findings from the first test program to the scanner engine while the first test program is executing.