Network Asset Scanning Segmentation for Disruption Control

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Vulnerability scanning of network-connected assets often induces disruptions such as degraded performance, freezing, and crashes, particularly in compliance-regulated environments where scans must be frequent and cover a wide range of IP addresses or application replicas, leading to potential outages even with redundancy.

Innovation Solution

A system that partitions network-connected assets into groups based on their network characteristics, scans each asset sequentially, and halts further scanning if an asset's health is degraded, with an alert sent to owners, and optionally halts all scans if a threshold of assets show degraded health.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If vulnerability scanning is performed on network-connected assets, then security verification is improved, but network stability deteriorates due to degraded performance, freezing, and crashes

Engineering Contradiction:
Improvesecurity verificationVSAvoidnetwork stability
Core Design Contradiction:
ReliabilityVSStability of the object's composition

Solution Approach 1:

The patent divides the network-connected assets into multiple groups based on network characteristics such as IP address ranges, asset types, and criticality levels. Scanning is performed sequentially on one group at a time rather than simultaneously on all assets, which isolates the impact of scanning-induced disruptions to specific segments and prevents system-wide instability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements periodic scanning intervals between scanning different asset groups, allowing the network to stabilize and recover between scanning operations. This periodic action prevents continuous stress on the network infrastructure and reduces the likelihood of cumulative disruptions.

Inventive Principle:
Principle #19Periodic action

2Reliability

If comprehensive vulnerability scanning is performed across all network-connected assets, then security coverage is improved, but network disruptions increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidnetwork disruptions
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

Assets are segmented into groups based on network characteristics including IP address ranges, asset types, and operational criticality. This segmentation allows comprehensive scanning to be achieved over time while limiting disruptions to specific segments during each scanning interval.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different scanning strategies and intensity levels to different asset groups based on their specific characteristics and criticality. High-criticality assets receive more careful, monitored scanning with lower intensity, while less critical assets can tolerate more aggressive scanning, optimizing the balance between security coverage and disruption minimization.

Inventive Principle:
Principle #3Local quality

3Productivity

If multiple assets are scanned simultaneously, then scanning efficiency is improved, but the risk of widespread network failures increases

Engineering Contradiction:
Improvescanning efficiencyVSAvoidnetwork reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The patent divides assets into multiple isolated groups and scans one group at a time rather than scanning all assets simultaneously. This segmentation maintains productivity by enabling parallel processing of discrete groups while preventing cascading failures across the entire network.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

Before scanning each asset group, the system performs preliminary health checks and establishes baseline performance metrics. This preliminary action allows the system to detect scanning-induced degradation early and halt scanning before widespread failures can occur, maintaining network reliability while preserving scanning efficiency.

Inventive Principle:
Principle #10Preliminary action

4Loss of information

If scanning continues without interruption to complete security assessment, then scanning completeness is improved, but network asset stability deteriorates

Engineering Contradiction:
Improvescanning completenessVSAvoidasset stability
Core Design Contradiction:
Loss of informationVSStability of the object's composition

Solution Approach 1:

The patent implements continuous monitoring of asset health status during scanning operations. When degradation is detected, the system provides feedback to halt scanning temporarily, allowing assets to stabilize. Scanning then resumes after a recovery period, ensuring both asset stability and eventual scanning completeness through iterative cycles.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary health assessments before scanning and establishes baseline metrics. During scanning, continuous health monitoring compares current status against baselines, enabling early detection of stability issues and timely intervention to prevent complete asset failure while preserving scanning progress.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11870798B2Minimizing security scanning induced network disruptions
Publication Date: 2024.01.09 GOOGLE LLC
  • US11870798B2 patent drawing
  • US11870798B2 patent drawing
  • US11870798B2 patent drawing

AI summary

A method for minimizing scan disruptions includes receiving a scan request requesting to scan a set of network-connected assets. Each network-connected asset is associated with corresponding network characteristics. The method includes partitioning the set of network-connected assets into a plurality of groups based on the corresponding network characteristics. For each respective group, simultaneously, the method includes determining an ordered list for scanning each network-connected asset in the respective group, scanning a first network-connected asset of the respective group based on the ordered list, and, after scanning the first network-connected asset, determining a post-scan health status of the first network-connected asset. The method includes determining, using the post-scan health status, that a health of the first network-connected asset is degraded. The method also includes, in response to determining that the health of the first network-connected asset is degraded, halting scanning of further network-connected assets in the respective group.