Network Management via Vulnerability Probing and User Notification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network management systems face challenges in efficiently maintaining network integrity against viral infections due to difficulties in contacting users for patching, especially in dynamic networks with varying user autonomy and IP address changes, leading to unreliable communication and delayed or missed patching operations.

Innovation Solution

A method involving network probing to generate vulnerability logs, user identification, and data collection to facilitate user contact for convenient patching, including deferred patching and location determination, using databases to manage patching operations and handle dynamic IP addresses through detailed logging and user involvement.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network probing and vulnerability logging are implemented to identify vulnerable entities, then network security monitoring capability is improved, but system complexity and resource consumption increase

Engineering Contradiction:
Improvenetwork security monitoring capabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The system divides network management into separate functional modules: probing module for vulnerability detection, logging module for data storage, and notification module for user alerting. This segmentation allows each component to be independently optimized and managed, reducing overall system complexity while maintaining comprehensive security monitoring capability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary notification system that acts as a bridge between the vulnerability detection system and end users. This intermediary layer handles the complexity of contact management, message routing, and delivery tracking, thereby simplifying the core security monitoring function while improving user notification reliability.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If user contact information is collected and stored to enable patching notifications, then patching efficiency is improved, but user privacy and data security risks increase

Engineering Contradiction:
Improvepatching efficiencyVSAvoiddata security risks
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by collecting and storing user contact information in advance, before vulnerability patching is needed. This allows rapid notification and efficient patching deployment when security issues arise, while the data is stored securely with appropriate access controls to mitigate security risks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

Users are empowered to self-register and manage their own contact information and notification preferences through the system. This self-service approach reduces the need for centralized storage of sensitive data, as users control their own information, thereby improving patching communication efficiency while minimizing data security risks.

Inventive Principle:
Principle #25Self-service

3Reliability

If multiple notification methods are implemented for user contact, then communication reliability is improved, but system complexity and resource usage increase

Engineering Contradiction:
Improvecommunication reliabilityVSAvoidresource usage
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The notification system dynamically selects and activates communication methods based on current conditions, user preferences, and available resources. Rather than continuously using all notification channels, the system adapts its approach - for example, preferring electronic mail when available, or switching to alternative methods only when necessary - thereby improving communication reliability while optimizing resource consumption.

Inventive Principle:
Principle #15Dynamics

4Reliability

If manual patching processes are used to maintain network integrity, then security control is improved, but time consumption and operational overhead increase

Engineering Contradiction:
Improvenetwork integrityVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system implements automated feedback loops that continuously monitor network entities for vulnerabilities, automatically generate patching notifications, and track patching status. This feedback mechanism enables near-real-time detection and response to security issues, maintaining network integrity while dramatically reducing the time consumption associated with manual vulnerability assessment and patching coordination.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8392995B2Network management
Publication Date: 2013.03.05 WORKDAY INC
  • US8392995B2 patent drawing
  • US8392995B2 patent drawing
  • US8392995B2 patent drawing

AI summary

A method of operating a computing entity in a network having a log mapping computing entity network addresses to vulnerabilities, the method comprising the steps of: using the entity's network address, searching the log to establish what vulnerabilities the entity has; and if the log indicates the entity has a vulnerability, sending data identifying a user of the entity to an administrator of the network.