Network Vulnerability Detection via Active Passive Scanning Fusion
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security systems rely heavily on active vulnerability scanners, which are limited by physical constraints, generate stale results over time, and can cause network disruptions, failing to detect real-time activity and comprehensive vulnerabilities, especially in large networks with complex configurations and firewalls.
Innovation Solution
A system and method that combines active and passive vulnerability discovery to identify remotely visible and exploitable services, client software, and trust relationships, simulating hacking via server-side exploits to enumerate remote network addresses that could potentially exploit identified weak points, using passive scanners to monitor traffic and active scanners to perform credentialed and uncredentialed scans, with a management console aggregating data for real-time visibility and security management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If active vulnerability scanners are used to audit network devices, then vulnerability detection capability is improved, but network disruption and instability increase
Solution Approach 1:
The system segments the vulnerability scanning function into multiple distributed scanner agents deployed across different network locations. Each agent performs localized scanning tasks, distributing the scanning load and reducing the impact on any single network segment. This segmentation allows continuous vulnerability assessment without causing widespread network disruption.
Solution Approach 2:
The system implements periodic scanning intervals and throttles scan intensity based on network conditions. Scans are performed in cycles rather than continuously, allowing the network to stabilize between scanning operations. The system can adjust scan frequency and intensity dynamically to balance detection needs with network stability requirements.
2Area of stationary object
If active vulnerability scanners traverse multiple routers to scan hosts, then network coverage is improved, but scanning time increases
Solution Approach 1:
The system divides the network into multiple scanning zones or segments, each handled by dedicated scanner agents positioned strategically within those segments. This eliminates the need for a single scanner to traverse entire network paths, as each agent scans its local segment directly, dramatically reducing scanning time while maintaining comprehensive coverage through coordinated multi-agent operation.
Solution Approach 2:
The system introduces intermediary scanner agents deployed at strategic network positions (such as network perimeter, segment boundaries, or critical infrastructure locations) that act as local scanning authorities. These intermediaries perform scans on their local networks without requiring traversal through multiple routers, reducing scanning time while the central management system coordinates all intermediaries to achieve complete network coverage.
3Reliability
If firewalls screen incoming and outgoing traffic, then network security is improved, but vulnerability scanning completeness deteriorates
Solution Approach 1:
The system positions scanner agents as trusted intermediaries within network segments, allowing them to conduct scans without triggering firewall blocks. These intermediaries operate from authorized positions where they can reach targets through permitted communication paths, enabling complete vulnerability assessment while respecting firewall security policies.
Solution Approach 2:
The system implements multiple scanning approaches that can adapt to different firewall configurations. Scanner agents can switch between active scanning methods, passive observation techniques, and credentialed authentication modes depending on firewall rules, ensuring comprehensive vulnerability detection across diverse network security architectures without compromising firewall effectiveness.
4Speed
If passive scanners observe network traffic, then real-time detection capability is improved, but comprehensive vulnerability identification deteriorates
Solution Approach 1:
The system merges passive traffic observation capabilities with active scanning functions into a unified vulnerability assessment platform. Passive scanners continuously monitor network traffic for real-time anomaly detection, while active scanners periodically perform comprehensive vulnerability assessments. The system correlates data from both sources, using passive observations to guide active scanning priorities and combining results to achieve both real-time detection and complete vulnerability identification.
Data Source
AI summary
The system and method described herein may leverage passive and active vulnerability discovery to identify network addresses and open ports associated with connections that one or more passive scanners observed in a network and current connections that one or more active scanners enumerated in the network. The observed and enumerated current connections may be used to model trust relationships and identify exploitable weak points in the network, wherein the exploitable weak points may include hosts that have exploitable services, exploitable client software, and/or exploitable trust relationships. Furthermore, an attack that uses the modeled trust relationships to target the exploitable weak points on a selected host in the network may be simulated to enumerate remote network addresses that could compromise the network and determine an exploitation path that the enumerated remote network addresses could use to compromise the network.


