Passive Vulnerability Scanner for Encrypted Network Sessions

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems rely on active vulnerability scanners that are limited by their inability to detect real-time network activity, particularly encrypted and interactive sessions, leading to incomplete audits and potential network disruptions, as they can only access devices that communicate with them and fail to identify changes in the network over time.

Innovation Solution

A passive vulnerability scanner is distributed across the network to observe traffic, reconstruct sessions, and identify encrypted or interactive sessions by analyzing packet qualities such as randomness and timing, enabling real-time detection of vulnerabilities and changes without disrupting the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If active vulnerability scanners send packets to audit network devices, then they can obtain information about device configurations and vulnerabilities, but they cause network disruptions, communication bottlenecks, and processing overhead

Engineering Contradiction:
Improveaudit information completenessVSAvoidnetwork disruption
Core Design Contradiction:
Measurement precisionVSObject-affected harmful factors

Solution Approach 1:

A passive vulnerability scanner is introduced as an intermediary component that monitors network traffic without actively sending packets to target devices. This mediator captures and analyzes traffic flows, session information, and device responses passively, obtaining audit information without causing network disruptions or communication bottlenecks

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The active mechanical scanning approach (sending packets and waiting for responses) is replaced with a passive observation approach. The system substitutes the mechanical interaction model with a monitoring and analysis model that observes existing network traffic patterns, session establishment, and data flows without injecting additional traffic that could cause disruptions

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If active vulnerability scanners continuously audit the network, then they can detect changes in network topology and devices, but they increase network traffic and cause performance degradation

Engineering Contradiction:
Improvenetwork security monitoring accuracyVSAvoidnetwork performance
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system provides continuous network security monitoring by passively observing ongoing traffic flows and session patterns. Instead of periodic active scans that interrupt network operations, the passive scanner continuously analyzes traffic to detect topology changes, new devices, and security vulnerabilities without degrading network performance

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system leverages the network's own traffic and existing communication patterns as the source of audit information. By analyzing packets already traversing the network, session establishment sequences, and device responses that would occur anyway during normal operations, the system obtains security information without requiring additional network resources or causing performance degradation

Inventive Principle:
Principle #25Self-service

3Measurement precision

If active vulnerability scanners probe network hosts to identify vulnerabilities, then they can detect security issues, but they may trigger false positives and cause instability in the network

Engineering Contradiction:
Improvevulnerability detection accuracyVSAvoidnetwork stability
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The passive vulnerability scanner analyzes actual network traffic and device responses to understand normal behavior patterns. By establishing a baseline of legitimate traffic flows, session patterns, and device responses through continuous passive observation, the system can distinguish between normal operations and actual security vulnerabilities, reducing false positives while maintaining network stability

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8707440B2System and method for passively identifying encrypted and interactive network sessions
Publication Date: 2014.04.22 TENABLE INC
  • US8707440B2 patent drawing
  • US8707440B2 patent drawing
  • US8707440B2 patent drawing

AI summary

The system and method for passively identifying encrypted and interactive network sessions described herein may distribute a passive vulnerability scanner in a network, wherein the passive vulnerability scanner may observe traffic travelling across the network and reconstruct a network session from the observed traffic. The passive vulnerability scanner may then analyze the reconstructed network session to determine whether the session was encrypted or interactive (e.g., based on randomization, packet timing characteristics, or other qualities measured for the session). Thus, the passive vulnerability scanner may monitor the network in real-time to detect any devices in the network that run encrypted or interactive services or otherwise participate in encrypted or interactive sessions, wherein detecting encrypted and interactive sessions in the network may be used to manage changes and potential vulnerabilities in the network.