Passive Network Scanning for Malware Detection Without Resident Agents
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security systems rely heavily on active vulnerability scanners, which are limited by physical constraints, lead to incomplete and stale audit results, and can cause network disruptions, while anti-malware solutions with resident agents consume resources and have gaps in coverage due to the need for continuous monitoring and signature updates.
Innovation Solution
A system and method that leverages active network scanning and passive monitoring to detect malware infections and botnet participation without requiring resident anti-virus agents, using cloud databases to aggregate malware signatures and passive scanners to monitor traffic for real-time vulnerabilities, enabling comprehensive security audits and improved network visibility.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If active vulnerability scanners are used to audit network devices, then network security vulnerabilities can be detected, but the scanners are limited by physical constraints and can only audit devices that can communicate with them, resulting in incomplete audit results
Solution Approach 1:
The patent introduces passive scanners as intermediary devices that monitor network traffic to detect malware and vulnerabilities. These passive scanners act as mediators between the active scanners and the network devices, enabling detection of devices that cannot be directly accessed by active scanners. The passive scanners analyze traffic flows and device responses without requiring direct communication with target devices, thus overcoming the accessibility limitation.
2Reliability
If active vulnerability scanners continuously scan the network to detect changes, then real-time security monitoring is achieved, but network disruptions and instability occur due to communication bottlenecks and processing overhead
Solution Approach 1:
The patent implements periodic scanning intervals where active scanners conduct audits at predetermined time intervals rather than continuously. This periodic action allows the network to stabilize between scans, reducing communication bottlenecks and processing overhead. The system balances real-time detection needs with network stability by scheduling scans to occur during periods of lower network activity.
Solution Approach 2:
The patent maintains continuous security monitoring through a combination of periodic active scans and continuous passive traffic analysis. While active scanners operate periodically to avoid disruption, passive scanners continuously monitor network traffic flows, device responses, and communication patterns. This dual approach ensures uninterrupted security oversight without the harmful effects of continuous active scanning.
3Measurement precision
If resident anti-virus agents are installed on hosts to detect malware, then local malware detection is improved, but resource consumption increases and coverage gaps remain due to signature update delays
Solution Approach 1:
The patent extracts the malware detection function from resident agents on individual hosts and consolidates it into centralized passive scanners that analyze network traffic. Instead of each host running resource-intensive anti-virus software, the system extracts detection capabilities to external scanners that examine traffic patterns, file transfers, and communication behaviors. This extraction significantly reduces resource consumption on individual hosts while maintaining comprehensive detection coverage.
Solution Approach 2:
The passive scanners serve multiple functions: they monitor network traffic for malware indicators, analyze device responses to active scans, detect botnet activity, and identify vulnerabilities across the entire network. This multi-functionality replaces the need for separate resident agents on each host, reducing overall resource consumption while improving detection coverage through centralized analysis of all network communications.
4Measurement precision
If manual inspection or network scans are used to detect network vulnerabilities, then security audits can be performed, but the audit results become stale over time as hosts are added or removed from the network
Solution Approach 1:
The patent implements feedback mechanisms where passive scanners continuously monitor network traffic and automatically detect when new hosts are added or existing hosts are removed. The system uses this feedback to dynamically update its monitoring scope and trigger targeted active scans of newly detected devices. This feedback loop ensures audit results remain current without requiring continuous full-network scanning, maintaining both accuracy and freshness.
Data Source
AI summary
The system and method described herein may leverage active network scanning and passive network monitoring to provide strategic anti-malware monitoring in a network. In particular, the system and method described herein may remotely connect to managed hosts in a network to compute hashes or other signatures associated with processes running thereon and suspicious files hosted thereon, wherein the hashes may communicated to a cloud database that aggregates all known virus or malware signatures that various anti-virus vendors have catalogued to detect malware infections without requiring the hosts to have a local or resident anti-virus agent. Furthermore, running processes and file system activity may be monitored in the network to further detect malware infections. Additionally, the network scanning and network monitoring may be used to detect hosts that may potentially be participating in an active botnet or hosting botnet content and audit anti-virus strategies deployed in the network.


