Network Vulnerability Assessment via Passive Device Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing vulnerability assessment products often fail to identify network vulnerabilities in previously unknown network devices, leading to compromised network security due to unawareness of new devices or segments within a network.

Innovation Solution

A method and system that utilize scan configuration data and network activity data to identify unknown devices by determining shared features with known devices, allowing for targeted scanning and updating of scan configurations to include new devices, using classifiers like random forests or support vector machines to classify devices for scanning.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If existing vulnerability assessment products scan only known devices, then scanning efficiency is maintained, but previously unknown devices are missed leading to compromised network security

Engineering Contradiction:
Improvenetwork securityVSAvoiddevice identification complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system enables unknown devices to self-identify through passive monitoring of network activity data. Devices automatically appear in the scan configuration when their network activity is detected, eliminating the need for manual device registration or complex discovery processes while ensuring complete device coverage for security scanning

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system continuously monitors network activity data and provides feedback to dynamically update the scan configuration. When new devices are detected through network activity, the system automatically feeds this information back into the vulnerability assessment process, ensuring that the scanning scope remains current without manual intervention

Inventive Principle:
Principle #23Feedback

2Reliability

If the system scans all detected devices including unknown devices, then comprehensive vulnerability coverage is achieved, but scanning time and resources increase

Engineering Contradiction:
Improvevulnerability assessment completenessVSAvoidscanning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system applies partial scanning action by initially focusing vulnerability scans on known devices while passively monitoring for unknown devices. When unknown devices are detected, they are added to the scan configuration progressively, allowing the system to balance comprehensive coverage with time-efficient scanning by prioritizing known devices and incrementally incorporating newly discovered devices

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system performs preliminary monitoring of network activity data before initiating full vulnerability scans. By pre-identifying and classifying devices through passive observation, the system prepares the scan configuration in advance, so that when scanning begins, all relevant devices are already identified and ready for assessment, reducing actual scanning time

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If manual updates to scan configuration are required for new devices, then scanning accuracy is maintained, but operational complexity and human intervention increase

Engineering Contradiction:
Improvedevice identification accuracyVSAvoidconfiguration management ease
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The system automatically performs device identification and classification by analyzing network activity data against known device profiles. Unknown devices are self-added to the scan configuration when their activity patterns match recognized device types, eliminating manual configuration updates while maintaining accurate device identification through automated feature comparison

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system dynamically changes the scan configuration parameters based on detected device features. By comparing network activity characteristics such as data volume, peer connections, and port activity against known device profiles, the system automatically adjusts the scan configuration to include or exclude devices based on their identified parameters, maintaining precision without manual intervention

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS11689554B2Machine learned network vulnerability assessment
Publication Date: 2023.06.27 RAPID7 INC
  • US11689554B2 patent drawing
  • US11689554B2 patent drawing
  • US11689554B2 patent drawing

AI summary

Methods and systems for identifying a network vulnerability. The system may gather data regarding a new or previously unknown network device, and compare the gathered data to one or more known devices that are scanned by a vulnerability assessment device. The vulnerability assessment device may then scan the previously unknown device upon a processor determining the previously unknown device shares at least one feature with a known device that is scanned.