Network Vulnerability Detection via Active Passive Scanning Fusion

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems rely heavily on active vulnerability scanners, which are limited by physical constraints, generate stale results over time, and can cause network disruptions, failing to detect real-time activity and comprehensive vulnerabilities, especially in large networks with complex configurations and firewalls.

Innovation Solution

A system and method that combines active and passive vulnerability discovery to identify remotely visible and exploitable services, client software, and trust relationships, simulating hacking via server-side exploits to enumerate remote network addresses that could potentially exploit identified weak points, using passive scanners to monitor traffic and active scanners to perform credentialed and uncredentialed scans, with a management console aggregating data for real-time visibility and security management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If active vulnerability scanners are used to audit network devices, then vulnerability detection capability is improved, but network disruption and instability increase

Engineering Contradiction:
Improvevulnerability detection capabilityVSAvoidnetwork stability
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The system segments the vulnerability scanning function into multiple distributed scanner agents deployed across different network locations. Each agent performs localized scanning tasks, distributing the scanning load and reducing the impact on any single network segment. This segmentation allows continuous vulnerability assessment without causing widespread network disruption.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system implements periodic scanning intervals and throttles scan intensity based on network conditions. Scans are performed in cycles rather than continuously, allowing the network to stabilize between scanning operations. The system can adjust scan frequency and intensity dynamically to balance detection needs with network stability requirements.

Inventive Principle:
Principle #19Periodic action

2Area of stationary object

If active vulnerability scanners traverse multiple routers to scan hosts, then network coverage is improved, but scanning time increases

Engineering Contradiction:
Improvenetwork coverageVSAvoidscanning time
Core Design Contradiction:
Area of stationary objectVSLoss of time

Solution Approach 1:

The system divides the network into multiple scanning zones or segments, each handled by dedicated scanner agents positioned strategically within those segments. This eliminates the need for a single scanner to traverse entire network paths, as each agent scans its local segment directly, dramatically reducing scanning time while maintaining comprehensive coverage through coordinated multi-agent operation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system introduces intermediary scanner agents deployed at strategic network positions (such as network perimeter, segment boundaries, or critical infrastructure locations) that act as local scanning authorities. These intermediaries perform scans on their local networks without requiring traversal through multiple routers, reducing scanning time while the central management system coordinates all intermediaries to achieve complete network coverage.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Reliability

If firewalls screen incoming and outgoing traffic, then network security is improved, but vulnerability scanning completeness deteriorates

Engineering Contradiction:
Improvenetwork securityVSAvoidvulnerability scanning completeness
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The system positions scanner agents as trusted intermediaries within network segments, allowing them to conduct scans without triggering firewall blocks. These intermediaries operate from authorized positions where they can reach targets through permitted communication paths, enabling complete vulnerability assessment while respecting firewall security policies.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system implements multiple scanning approaches that can adapt to different firewall configurations. Scanner agents can switch between active scanning methods, passive observation techniques, and credentialed authentication modes depending on firewall rules, ensuring comprehensive vulnerability detection across diverse network security architectures without compromising firewall effectiveness.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Speed

If passive scanners observe network traffic, then real-time detection capability is improved, but comprehensive vulnerability identification deteriorates

Engineering Contradiction:
Improvereal-time detection capabilityVSAvoidvulnerability identification completeness
Core Design Contradiction:
SpeedVSMeasurement precision

Solution Approach 1:

The system merges passive traffic observation capabilities with active scanning functions into a unified vulnerability assessment platform. Passive scanners continuously monitor network traffic for real-time anomaly detection, while active scanners periodically perform comprehensive vulnerability assessments. The system correlates data from both sources, using passive observations to guide active scanning priorities and combining results to achieve both real-time detection and complete vulnerability identification.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS9860265B2System and method for identifying exploitable weak points in a network
Publication Date: 2018.01.02 TENABLE INC
  • US9860265B2 patent drawing
  • US9860265B2 patent drawing
  • US9860265B2 patent drawing

AI summary

The system and method described herein may leverage passive and active vulnerability discovery to identify network addresses and open ports associated with connections that one or more passive scanners observed in a network and current connections that one or more active scanners enumerated in the network. The observed and enumerated current connections may be used to model trust relationships and identify exploitable weak points in the network, wherein the exploitable weak points may include hosts that have exploitable services, exploitable client software, and/or exploitable trust relationships. Furthermore, an attack that uses the modeled trust relationships to target the exploitable weak points on a selected host in the network may be simulated to enumerate remote network addresses that could compromise the network and determine an exploitation path that the enumerated remote network addresses could use to compromise the network.