Local Network Security Evaluation via External Penetration Testing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Local area networks, especially those with IoT devices, are vulnerable to hacking due to outdated firmware, default passwords, and unauthorized access, which compromises their security and IoT readiness score.

Innovation Solution

A system and method that conduct penetration tests on local area networks, identify security risks, update firmware, change default passwords, block unauthorized access, and calculate an IoT readiness score to improve network security and minimize vulnerabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If penetration testing and security interrogation of devices are conducted, then security risks are identified and security status is improved, but system complexity and resource consumption increase

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

An external server acts as an intermediary between the user and the local area network devices. The server conducts penetration testing and security interrogations centrally, eliminating the need for complex security testing software to be installed on each user device. This reduces local system complexity while maintaining comprehensive security assessment capabilities through the centralized server infrastructure.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system enables devices to self-assess their security status by automatically interrogating each device on the network. Devices report their own security configurations, firmware versions, and vulnerability states to the external server, which then provides automated remediation recommendations. This self-service approach reduces the need for manual security auditing while improving network security posture.

Inventive Principle:
Principle #25Self-service

2Reliability

If automated actions are taken to update firmware and change passwords, then security vulnerabilities are reduced, but device complexity and potential disruption increase

Engineering Contradiction:
Improvedevice securityVSAvoiduser control
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The external server performs preliminary security assessments and identifies vulnerabilities before implementing remediation actions. Firmware updates and password changes are prepared and approved in advance based on security risk analysis, ensuring that automated actions are taken only when necessary and with proper authorization. This preliminary action approach maintains user control while enabling timely security improvements.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements a feedback loop where security assessment results are communicated to users, who can then approve or reject automated remediation actions. The external server monitors the outcomes of firmware updates and password changes, and adjusts future security recommendations based on the effectiveness of previous actions. This feedback mechanism ensures user control is maintained while enabling automated security improvements.

Inventive Principle:
Principle #23Feedback

3Reliability

If comprehensive device interrogation is performed to identify security risks, then security status is improved, but time and resource consumption increase

Engineering Contradiction:
Improvesecurity assessment accuracyVSAvoidtesting duration
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The external server performs comprehensive security interrogation of all devices on the network, going beyond minimal security checks to include firmware version verification, default password detection, and unauthorized device identification. This excessive action approach ensures thorough security assessment and identifies even subtle vulnerabilities, with the trade-off of increased testing time being acceptable for comprehensive security evaluation.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

Security penetration testing and device interrogation are conducted periodically rather than continuously, allowing the system to assess security status at scheduled intervals. The external server can perform comprehensive checks at defined frequencies, balancing thorough security assessment with acceptable time consumption. Periodic action enables comprehensive security evaluation without requiring constant monitoring resources.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS11652840B1System for evaluating and improving the security status of a local network
Publication Date: 2023.05.16 UNITED SERVICES AUTOMOBILE ASSOCIATION (USAA)
  • US11652840B1 patent drawing
  • US11652840B1 patent drawing
  • US11652840B1 patent drawing

AI summary

A system and method for evaluating and improving the security of a local area network including an application residing on an external server configured to conduct a penetration test of the local area network by interrogating each of the devices on the local area network to identify vulnerabilities and risks associated with those devices, receiving a report listing all such identified vulnerabilities and risks, calculating an IoT readiness score for the local area network, and undertaking and/or recommending specific actions for improving the security of the local area network.