Passive Network Scanning for Malware Detection Without Resident Agents

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems rely heavily on active vulnerability scanners, which are limited by physical constraints, lead to incomplete and stale audit results, and can cause network disruptions, while anti-malware solutions with resident agents consume resources and have gaps in coverage due to the need for continuous monitoring and signature updates.

Innovation Solution

A system and method that leverages active network scanning and passive monitoring to detect malware infections and botnet participation without requiring resident anti-virus agents, using cloud databases to aggregate malware signatures and passive scanners to monitor traffic for real-time vulnerabilities, enabling comprehensive security audits and improved network visibility.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If active vulnerability scanners are used to audit network devices, then network security vulnerabilities can be detected, but the scanners are limited by physical constraints and can only audit devices that can communicate with them, resulting in incomplete audit results

Engineering Contradiction:
Improveaudit completenessVSAvoidscanner accessibility
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent introduces passive scanners as intermediary devices that monitor network traffic to detect malware and vulnerabilities. These passive scanners act as mediators between the active scanners and the network devices, enabling detection of devices that cannot be directly accessed by active scanners. The passive scanners analyze traffic flows and device responses without requiring direct communication with target devices, thus overcoming the accessibility limitation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If active vulnerability scanners continuously scan the network to detect changes, then real-time security monitoring is achieved, but network disruptions and instability occur due to communication bottlenecks and processing overhead

Engineering Contradiction:
Improvereal-time detection capabilityVSAvoidnetwork disruption
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements periodic scanning intervals where active scanners conduct audits at predetermined time intervals rather than continuously. This periodic action allows the network to stabilize between scans, reducing communication bottlenecks and processing overhead. The system balances real-time detection needs with network stability by scheduling scans to occur during periods of lower network activity.

Inventive Principle:
Principle #19Periodic action

Solution Approach 2:

The patent maintains continuous security monitoring through a combination of periodic active scans and continuous passive traffic analysis. While active scanners operate periodically to avoid disruption, passive scanners continuously monitor network traffic flows, device responses, and communication patterns. This dual approach ensures uninterrupted security oversight without the harmful effects of continuous active scanning.

Inventive Principle:
Principle #20Continuity of useful action

3Measurement precision

If resident anti-virus agents are installed on hosts to detect malware, then local malware detection is improved, but resource consumption increases and coverage gaps remain due to signature update delays

Engineering Contradiction:
Improvemalware detection accuracyVSAvoidhost resource consumption
Core Design Contradiction:
Measurement precisionVSUse of energy by moving object

Solution Approach 1:

The patent extracts the malware detection function from resident agents on individual hosts and consolidates it into centralized passive scanners that analyze network traffic. Instead of each host running resource-intensive anti-virus software, the system extracts detection capabilities to external scanners that examine traffic patterns, file transfers, and communication behaviors. This extraction significantly reduces resource consumption on individual hosts while maintaining comprehensive detection coverage.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The passive scanners serve multiple functions: they monitor network traffic for malware indicators, analyze device responses to active scans, detect botnet activity, and identify vulnerabilities across the entire network. This multi-functionality replaces the need for separate resident agents on each host, reducing overall resource consumption while improving detection coverage through centralized analysis of all network communications.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Measurement precision

If manual inspection or network scans are used to detect network vulnerabilities, then security audits can be performed, but the audit results become stale over time as hosts are added or removed from the network

Engineering Contradiction:
Improvevulnerability detection accuracyVSAvoidaudit result freshness
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent implements feedback mechanisms where passive scanners continuously monitor network traffic and automatically detect when new hosts are added or existing hosts are removed. The system uses this feedback to dynamically update its monitoring scope and trigger targeted active scans of newly detected devices. This feedback loop ensures audit results remain current without requiring continuous full-network scanning, maintaining both accuracy and freshness.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11057422B2System and method for strategic anti-malware monitoring
Publication Date: 2021.07.06 TENABLE INC
  • US11057422B2 patent drawing
  • US11057422B2 patent drawing
  • US11057422B2 patent drawing

AI summary

The system and method described herein may leverage active network scanning and passive network monitoring to provide strategic anti-malware monitoring in a network. In particular, the system and method described herein may remotely connect to managed hosts in a network to compute hashes or other signatures associated with processes running thereon and suspicious files hosted thereon, wherein the hashes may communicated to a cloud database that aggregates all known virus or malware signatures that various anti-virus vendors have catalogued to detect malware infections without requiring the hosts to have a local or resident anti-virus agent. Furthermore, running processes and file system activity may be monitored in the network to further detect malware infections. Additionally, the network scanning and network monitoring may be used to detect hosts that may potentially be participating in an active botnet or hosting botnet content and audit anti-virus strategies deployed in the network.