Passive Network Scanner for Continuous Vulnerability Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional network scanners are slow, disruptive, and often provide stale results due to their active scanning methods, which can inadvertently disrupt systems and fail to detect vulnerabilities behind firewalls, leading to a need for improved and continuous vulnerability scanning techniques.
Innovation Solution
A passive network scanning method that involves sniffing packets to build a network topology and detect vulnerabilities, using active and passive scanners distributed across the network to continuously monitor for changes and new vulnerabilities, with results forwarded to a centralized management system.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If active scanning is used to detect vulnerabilities, then vulnerability detection capability is improved, but scanning speed and continuity deteriorate due to physical network limitations
Solution Approach 1:
The patent inverts the traditional active scanning approach by using passive scanning. Instead of the scanner actively sending packets to targets, the system passively captures and analyzes packets already traversing the network. This inversion allows continuous monitoring without being bound by physical network limitations, resolving the contradiction between detection capability and scanning speed.
Solution Approach 2:
The patent introduces a passive scanner as an intermediary that captures network packets without directly interacting with target systems. This intermediary approach enables vulnerability detection by analyzing existing traffic patterns and responses, achieving both accurate detection and high scanning speed without disrupting network operations.
2Loss of time
If active scanning is performed continuously, then vulnerability detection freshness is improved, but network disruption and system stability deteriorate
Solution Approach 1:
The patent inverts the scanning methodology from active to passive, allowing continuous monitoring without injecting traffic into the network. This eliminates the harmful effects of active probing while maintaining continuous vulnerability detection capability, as the passive scanner analyzes existing network traffic without disrupting system stability.
Solution Approach 2:
The passive scanner utilizes network traffic that already exists and serves itself by analyzing packets as they naturally flow through the network. This self-service approach eliminates the need for the scanner to generate its own traffic, thereby avoiding network disruption while maintaining continuous monitoring capability.
3Device complexity
If a single active scanner is used, then device simplicity is improved, but scanning comprehensiveness deteriorates due to firewall screening
Solution Approach 1:
The patent segments the scanning function into multiple passive scanners distributed across different network locations. Each passive scanner captures and analyzes packets in its local segment, enabling comprehensive vulnerability detection across the entire network including behind firewalls, while maintaining relative simplicity in each individual scanner's configuration.
Solution Approach 2:
The passive scanner is designed with multi-functionality, capable of operating in various network configurations and locations. By placing multiple passive scanners strategically throughout the network, the system achieves comprehensive coverage including areas behind firewalls, while each scanner maintains a relatively simple universal design that can adapt to different network environments.
Data Source
AI summary
Systems and methods to passively scan a network are disclosed herein. The passive scanner sniffs a plurality of packets traveling across the network. The passive scanner analyzes information from the sniffed packets to build a topology of network devices and services that are active on the network. In addition, the passive scanner analyzes the information to detect vulnerabilities in network devices and services. Finally, the passive scanner prepares a report containing the detected vulnerabilities and the topology when it observes a minimum number of sessions. Because the passive scanner operates passively, it may operate continuously without burdening the network. Similarly, it also may obtain information regarding client-side and server side vulnerabilities.


