Network Management via Vulnerability Probing and User Notification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network management systems face challenges in efficiently maintaining network integrity against viral infections due to difficulties in contacting users for patching, especially in dynamic networks with varying user autonomy and IP address changes, leading to unreliable communication and delayed or missed patching operations.
Innovation Solution
A method involving network probing to generate vulnerability logs, user identification, and data collection to facilitate user contact for convenient patching, including deferred patching and location determination, using databases to manage patching operations and handle dynamic IP addresses through detailed logging and user involvement.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If network probing and vulnerability logging are implemented to identify vulnerable entities, then network security monitoring capability is improved, but system complexity and resource consumption increase
Solution Approach 1:
The system divides network management into separate functional modules: probing module for vulnerability detection, logging module for data storage, and notification module for user alerting. This segmentation allows each component to be independently optimized and managed, reducing overall system complexity while maintaining comprehensive security monitoring capability.
Solution Approach 2:
The patent introduces an intermediary notification system that acts as a bridge between the vulnerability detection system and end users. This intermediary layer handles the complexity of contact management, message routing, and delivery tracking, thereby simplifying the core security monitoring function while improving user notification reliability.
2Productivity
If user contact information is collected and stored to enable patching notifications, then patching efficiency is improved, but user privacy and data security risks increase
Solution Approach 1:
The system performs preliminary actions by collecting and storing user contact information in advance, before vulnerability patching is needed. This allows rapid notification and efficient patching deployment when security issues arise, while the data is stored securely with appropriate access controls to mitigate security risks.
Solution Approach 2:
Users are empowered to self-register and manage their own contact information and notification preferences through the system. This self-service approach reduces the need for centralized storage of sensitive data, as users control their own information, thereby improving patching communication efficiency while minimizing data security risks.
3Reliability
If multiple notification methods are implemented for user contact, then communication reliability is improved, but system complexity and resource usage increase
Solution Approach 1:
The notification system dynamically selects and activates communication methods based on current conditions, user preferences, and available resources. Rather than continuously using all notification channels, the system adapts its approach - for example, preferring electronic mail when available, or switching to alternative methods only when necessary - thereby improving communication reliability while optimizing resource consumption.
4Reliability
If manual patching processes are used to maintain network integrity, then security control is improved, but time consumption and operational overhead increase
Solution Approach 1:
The system implements automated feedback loops that continuously monitor network entities for vulnerabilities, automatically generate patching notifications, and track patching status. This feedback mechanism enables near-real-time detection and response to security issues, maintaining network integrity while dramatically reducing the time consumption associated with manual vulnerability assessment and patching coordination.
Data Source
AI summary
A method of operating a computing entity in a network having a log mapping computing entity network addresses to vulnerabilities, the method comprising the steps of: using the entity's network address, searching the log to establish what vulnerabilities the entity has; and if the log indicates the entity has a vulnerability, sending data identifying a user of the entity to an administrator of the network.


