Multi-Perspective Scanning Engine for Internet Service Discovery
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current internet-wide network scanning methods are slow and difficult due to the vast number of IP addresses and ports, making it challenging to discover open ports and services on the Internet efficiently.
Innovation Solution
A scanning engine with multiple perspectives that uses multiple Internet Service Providers (ISPs) and geographic regions to initiate scans, employing discovery components and protocol detection components to efficiently discover open ports and services by attempting communication from different vantage points.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If brute force scanning of the entire Internet is attempted, then complete coverage of all IP addresses and ports is achieved, but the scanning time becomes excessively long (41,222 years)
Solution Approach 1:
The patent segments the Internet scanning task by dividing the IP address space into manageable subsets and using multiple scanning engines distributed across different locations. Each engine scans a specific portion of the Internet simultaneously, transforming the single massive task into many parallel smaller tasks that complete much faster while maintaining comprehensive coverage.
Solution Approach 2:
The patent introduces the dimension of spatial distribution by deploying scanning engines at multiple geographic locations and using multiple Internet Service Providers. This multi-dimensional approach allows simultaneous scanning from different vantage points, effectively parallelizing the scanning process and reducing total scanning time while maintaining complete Internet coverage.
2Reliability
If scanning is performed from a single location, then device complexity is minimized, but coverage is limited due to network routing and transient errors
Solution Approach 1:
The patent makes the scanning infrastructure universal by using multiple Internet Service Providers and geographic locations that can access different portions of the Internet. This multi-functional approach allows the scanning system to overcome network routing issues and transient errors by selecting alternative paths and vantage points, thereby improving coverage without requiring overly complex specialized equipment at each location.
Solution Approach 2:
The patent uses multiple Internet Service Providers as intermediaries between the scanning engines and the Internet. These ISPs act as mediators that provide alternative routing paths and access points, enabling the scanning system to bypass network blocks, routing issues, and transient errors while maintaining comprehensive Internet coverage.
3Reliability
If multiple Internet Service Providers and geographic regions are used, then coverage and error reduction are improved, but the scanning system becomes more complex
Solution Approach 1:
The patent segments the scanning function across multiple independent scanning engines located at different geographic positions and using different ISPs. Each segment operates independently but contributes to the overall scanning effort, improving accuracy through redundancy and multiple perspectives while managing complexity through modular architecture.
Solution Approach 2:
The patent merges the results from multiple scanning engines operating at different locations and using different ISPs into a unified scanning output. This combining approach aggregates the coverage and accuracy benefits of multiple perspectives while presenting a single consolidated result set, effectively managing the complexity of multi-perspective infrastructure.
Data Source
AI summary
Various embodiments of a scanning engine are described. In some embodiments, the scanning engine comprises discovery components associated with different Internet providers and/or protocol detection components associated with the different Internet providers. When a first discovery component associated with a first Internet provider does not receive a response from a port at an Internet address, then a second discovery component associated with a second Internet provider sends packets to that port at that Internet address to attempt to elicit a response. When a first protocol inspection component associated with a first Internet provider is not able to communicate with a port at an Internet address, then it provides information that can be obtained by a second protocol inspection component associated with a second Internet provider. That second protocol inspection component attempts to communicate with the port at the Internet address through the second Internet provider using various communication protocols.


