Passive Network Scanner for Continuous Vulnerability Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network scanners are slow, disruptive, and often provide stale results due to their active scanning methods, which can inadvertently disrupt systems and fail to detect vulnerabilities behind firewalls, leading to a need for improved and continuous vulnerability scanning techniques.

Innovation Solution

A passive network scanning method that involves sniffing packets to build a network topology and detect vulnerabilities, using active and passive scanners distributed across the network to continuously monitor for changes and new vulnerabilities, with results forwarded to a centralized management system.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If active scanning is used to detect vulnerabilities, then vulnerability detection capability is improved, but scanning speed and continuity deteriorate due to physical network limitations

Engineering Contradiction:
Improvevulnerability detection capabilityVSAvoidscanning speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent inverts the traditional active scanning approach by using passive scanning. Instead of the scanner actively sending packets to targets, the system passively captures and analyzes packets already traversing the network. This inversion allows continuous monitoring without being bound by physical network limitations, resolving the contradiction between detection capability and scanning speed.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The patent introduces a passive scanner as an intermediary that captures network packets without directly interacting with target systems. This intermediary approach enables vulnerability detection by analyzing existing traffic patterns and responses, achieving both accurate detection and high scanning speed without disrupting network operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Loss of time

If active scanning is performed continuously, then vulnerability detection freshness is improved, but network disruption and system stability deteriorate

Engineering Contradiction:
Improveresults freshnessVSAvoidnetwork disruption
Core Design Contradiction:
Loss of timeVSObject-affected harmful factors

Solution Approach 1:

The patent inverts the scanning methodology from active to passive, allowing continuous monitoring without injecting traffic into the network. This eliminates the harmful effects of active probing while maintaining continuous vulnerability detection capability, as the passive scanner analyzes existing network traffic without disrupting system stability.

Inventive Principle:
Principle #13The other way round (Inversion)

Solution Approach 2:

The passive scanner utilizes network traffic that already exists and serves itself by analyzing packets as they naturally flow through the network. This self-service approach eliminates the need for the scanner to generate its own traffic, thereby avoiding network disruption while maintaining continuous monitoring capability.

Inventive Principle:
Principle #25Self-service

3Device complexity

If a single active scanner is used, then device simplicity is improved, but scanning comprehensiveness deteriorates due to firewall screening

Engineering Contradiction:
Improvescanner configurationVSAvoidscan comprehensiveness
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent segments the scanning function into multiple passive scanners distributed across different network locations. Each passive scanner captures and analyzes packets in its local segment, enabling comprehensive vulnerability detection across the entire network including behind firewalls, while maintaining relative simplicity in each individual scanner's configuration.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The passive scanner is designed with multi-functionality, capable of operating in various network configurations and locations. By placing multiple passive scanners strategically throughout the network, the system achieves comprehensive coverage including areas behind firewalls, while each scanner maintains a relatively simple universal design that can adapt to different network environments.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS7761918B2System and method for scanning a network
Publication Date: 2010.07.20 TENABLE INC
  • US7761918B2 patent drawing
  • US7761918B2 patent drawing
  • US7761918B2 patent drawing

AI summary

Systems and methods to passively scan a network are disclosed herein. The passive scanner sniffs a plurality of packets traveling across the network. The passive scanner analyzes information from the sniffed packets to build a topology of network devices and services that are active on the network. In addition, the passive scanner analyzes the information to detect vulnerabilities in network devices and services. Finally, the passive scanner prepares a report containing the detected vulnerabilities and the topology when it observes a minimum number of sessions. Because the passive scanner operates passively, it may operate continuously without burdening the network. Similarly, it also may obtain information regarding client-side and server side vulnerabilities.