Network Mapping Using Fingerprint Scanning for Vulnerability Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

System administrators often fail to detect and address security vulnerabilities in internet-connected assets due to the complexity and variety of configuration options, leading to undetected vulnerabilities.

Innovation Solution

A network mapping system using fingerprints that scans for specific identifying criteria such as open ports, services, encryption certificates, and text patterns to identify and store associated addresses in a client network database, enabling comprehensive network scanning and vulnerability detection.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If network scanning is performed manually by system administrators, then detailed inspection of each system is possible, but the complexity and variety of configuration options cause vulnerabilities to go undetected and time-consuming

Engineering Contradiction:
Improvevulnerability detection accuracyVSAvoidtime for vulnerability detection
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent creates digital fingerprints that copy and represent the essential characteristics of network systems (open ports, services, configurations). These fingerprints serve as simplified representations that can be rapidly compared against vulnerability databases, enabling automated detection without manual inspection of each system's full configuration complexity.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The system transforms the complex, variable configuration parameters of network systems into standardized fingerprint parameters (port lists, service types, configuration patterns). This parameter transformation allows consistent vulnerability matching across diverse systems while maintaining detection accuracy.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If comprehensive network scanning is performed to detect all vulnerabilities, then security coverage is improved, but the device complexity and difficulty of managing multiple configuration options increases

Engineering Contradiction:
Improvesecurity vulnerability detectionVSAvoidsystem configuration complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the complex task of comprehensive vulnerability scanning into discrete fingerprint components (open ports, service identifiers, configuration patterns). Each fingerprint element can be independently generated, stored, and matched, simplifying the overall system architecture while maintaining comprehensive detection capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The fingerprinting system serves multiple functions: system identification, vulnerability detection, and network mapping. A single fingerprint structure can represent various system types and configurations, making the solution universally applicable across diverse network environments without requiring separate tools for each system type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If detailed configuration information is collected from all network systems, then complete vulnerability assessment is achieved, but the quantity of data to be managed and analyzed increases significantly

Engineering Contradiction:
Improvevulnerability assessment completenessVSAvoiddata volume for network analysis
Core Design Contradiction:
Measurement precisionVSQuantity of substance

Solution Approach 1:

The patent extracts only the essential identifying characteristics from complete system configurations to create fingerprints. Instead of collecting and analyzing all configuration data, the system extracts key parameters (port configurations, service types, critical settings) that are sufficient for vulnerability detection, significantly reducing data volume while maintaining assessment completeness.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system performs preliminary fingerprint generation and storage before vulnerability scanning. By pre-processing and organizing system characteristics into standardized fingerprint formats, the data is ready for rapid matching and analysis, reducing the computational burden during actual vulnerability assessment.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10749857B2Network mapping using a fingerprint
Publication Date: 2020.08.18 PALO ALTO NETWORKS INC
  • US10749857B2 patent drawing
  • US10749857B2 patent drawing
  • US10749857B2 patent drawing

AI summary

A system for network mapping includes an interface and a processor. The interface is configured to receive an indication to scan a set of addresses using a fingerprint. The processor is configured to for an address of the set of addresses: receive a response associated with the address; determine whether the response matches the fingerprint; and store the address in a client network database in the event the response matches the fingerprint.