Network Reachability Mapping with Spoofed Protocol Probes

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Legacy cyber threat defense systems rely on pre-defined rules and signatures, failing to effectively address new threats and requiring human intervention for network defense mechanisms, which is inefficient and inadequate.

Innovation Solution

A cyber security appliance with a network reachability module that autonomously maps and tracks network reachability, using spoofed transmissions and response communications to identify reachable and unreachable network devices, enabling autonomous threat mitigation without human intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If traditional pre-defined rules and signatures are used for cyber threat defense, then the system can protect against known threats, but it fails to effectively address new threats and requires human intervention

Engineering Contradiction:
Improveability to address new threatsVSAvoidhuman intervention requirement
Core Design Contradiction:
Adaptability or versatilityVSExtent of automation

Solution Approach 1:

The system performs preliminary network mapping and reachability assessment before threats occur, building a baseline understanding of network topology and device accessibility. This advance preparation enables the autonomous response system to quickly evaluate new threats without requiring human operators to manually map the network each time a new threat emerges.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The cyber threat defense system autonomously maps network reachability, identifies vulnerable devices, and determines appropriate response actions without human intervention. The system serves itself by automatically gathering network intelligence, analyzing threats, and executing mitigation strategies, eliminating the need for human operators to manually investigate and respond to each threat.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If manual network testing is performed to confirm reachability, then accurate network mapping can be achieved, but the process is time-consuming and inefficient

Engineering Contradiction:
Improvenetwork reachability accuracyVSAvoidtime for network testing
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

Instead of performing comprehensive manual network testing continuously, the system implements periodic reachability assessments at strategically determined intervals. The system tests network device accessibility periodically and updates its model incrementally, achieving accurate network mapping over time without requiring constant manual intervention or consuming excessive time resources.

Inventive Principle:
Principle #19Periodic action

3Reliability

If comprehensive network mapping is performed to identify all reachable devices, then complete threat coverage is achieved, but disruption to legitimate traffic increases

Engineering Contradiction:
Improvethreat detection coverageVSAvoiddisruption to legitimate traffic
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs partial network mapping focused on critical devices and high-value targets rather than attempting to map every device in the network. By concentrating reachability assessment efforts on the most important assets, the system achieves sufficient threat coverage to protect critical infrastructure while minimizing the volume of probe traffic and reducing disruption to legitimate network operations.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS12413484B2Method, apparatus, and system to map network reachability
Publication Date: 2025.09.09 DARKTRACE HLDG LTD
  • US12413484B2 patent drawing
  • US12413484B2 patent drawing
  • US12413484B2 patent drawing

AI summary

The network reachability module maps and dynamically tracks network reachability of network addresses and/or devices. The network reachability module can map and dynamically track network reachability of a response-orchestrator engine, via communicating and cooperating with the response-orchestrator engine. The network reachability module has a tracking module to 1) monitor network traffic and 2) keep a list of known devices and/or known subnets on the network, which is dynamically tracked and updated as previously unknown devices and subnets on the network are detected. A trigger module generates a spoofed transmission and/or response communication, supported by a network protocol used by the network. The spoofed transmission and/or response communication can be used to map network reachability of i) network devices, ii) network addresses, and iii) any combination of both, which either 1) can receive or 2) cannot receive protocol communications from a host for the network reachability module in the network.