Network Asset Vulnerability Detection and Decoupling

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security management systems lack effective methods for detecting and mitigating vulnerabilities in network assets, leading to potential security breaches and instability in computer networks.

Innovation Solution

The implementation of network asset vulnerability detection techniques that generate vulnerability profiles for each network asset, including operating system designation, open ports list, and network functionality, and decouple vulnerable assets from the network based on connectivity profiles and vulnerability documentation repositories.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network asset vulnerability detection is performed using detailed vulnerability profiles and connectivity profiles, then network security and reliability are improved, but device complexity and processing requirements increase

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The vulnerability detection system is segmented into multiple independent components: vulnerability profile generation module, connectivity profile generation module, vulnerability documentation repository, and decoupling module. Each component handles a specific aspect of the detection process, allowing the system to maintain high reliability through comprehensive profiling while managing complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by pre-generating vulnerability profiles and connectivity profiles for network assets before actual security incidents occur. These profiles are stored in repositories and used for rapid comparison and decision-making during security events, eliminating the need for complex real-time analysis and reducing processing complexity when security threats are detected.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If vulnerability profiles including operating system designation, open ports list, and network functionality are generated for each network asset, then measurement precision of vulnerability detection is improved, but loss of time for data collection and processing increases

Engineering Contradiction:
Improvevulnerability detection precisionVSAvoiddata collection time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

Vulnerability profiles containing operating system designation, open ports list, and network functionality are generated in advance for all network assets and stored in a vulnerability documentation repository. This preliminary profiling allows the system to achieve high measurement precision during actual security detection without incurring time delays, as the profiling data is already available for immediate comparison and analysis.

Inventive Principle:
Principle #10Preliminary action

3Object-affected harmful factors

If vulnerable network assets are decoupled from the monitored computer network using connectivity profiles, then harmful factors affecting the network are reduced, but productivity and network availability may be impacted

Engineering Contradiction:
Improvesecurity threatsVSAvoidnetwork availability
Core Design Contradiction:
Object-affected harmful factorsVSProductivity

Solution Approach 1:

The system extracts or decouples vulnerable network assets from the monitored computer network by utilizing connectivity profiles to identify and isolate these assets. This extraction process removes the harmful security threats posed by vulnerable assets while minimizing impact on network productivity through targeted isolation rather than blanket network shutdowns, allowing secure continuation of non-vulnerable asset operations.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS11611562B2Network asset vulnerability detection
Publication Date: 2023.03.21 HONEYWELL INTERNATIONAL INC
  • US11611562B2 patent drawing
  • US11611562B2 patent drawing
  • US11611562B2 patent drawing

AI summary

There is a need for more effective and efficient network security coordination. This need can be addressed by, for example, techniques for network asset vulnerability detection. In one example, a method includes detecting network assets within a monitored computer network; and for each network asset: determining a vulnerability profile, determining a connectivity profile, determining a vulnerability designation based on the vulnerability profile for the network asset and a network vulnerability documentation repository, determining whether the vulnerability designation for the network asset indicates a positive vulnerability designation, and in response to determining that the vulnerability designation indicates the positive vulnerability designation, decoupling the network asset from the monitored computer network using the connectivity profile for the network asset.