Network Reachability Mapping with Spoofed Protocol Probes
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Legacy cyber threat defense systems rely on pre-defined rules and signatures, failing to effectively address new threats and requiring human intervention for network defense mechanisms, which is inefficient and inadequate.
Innovation Solution
A cyber security appliance with a network reachability module that autonomously maps and tracks network reachability, using spoofed transmissions and response communications to identify reachable and unreachable network devices, enabling autonomous threat mitigation without human intervention.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If traditional pre-defined rules and signatures are used for cyber threat defense, then the system can protect against known threats, but it fails to effectively address new threats and requires human intervention
Solution Approach 1:
The system performs preliminary network mapping and reachability assessment before threats occur, building a baseline understanding of network topology and device accessibility. This advance preparation enables the autonomous response system to quickly evaluate new threats without requiring human operators to manually map the network each time a new threat emerges.
Solution Approach 2:
The cyber threat defense system autonomously maps network reachability, identifies vulnerable devices, and determines appropriate response actions without human intervention. The system serves itself by automatically gathering network intelligence, analyzing threats, and executing mitigation strategies, eliminating the need for human operators to manually investigate and respond to each threat.
2Measurement precision
If manual network testing is performed to confirm reachability, then accurate network mapping can be achieved, but the process is time-consuming and inefficient
Solution Approach 1:
Instead of performing comprehensive manual network testing continuously, the system implements periodic reachability assessments at strategically determined intervals. The system tests network device accessibility periodically and updates its model incrementally, achieving accurate network mapping over time without requiring constant manual intervention or consuming excessive time resources.
3Reliability
If comprehensive network mapping is performed to identify all reachable devices, then complete threat coverage is achieved, but disruption to legitimate traffic increases
Solution Approach 1:
The system performs partial network mapping focused on critical devices and high-value targets rather than attempting to map every device in the network. By concentrating reachability assessment efforts on the most important assets, the system achieves sufficient threat coverage to protect critical infrastructure while minimizing the volume of probe traffic and reducing disruption to legitimate network operations.
Data Source
AI summary
The network reachability module maps and dynamically tracks network reachability of network addresses and/or devices. The network reachability module can map and dynamically track network reachability of a response-orchestrator engine, via communicating and cooperating with the response-orchestrator engine. The network reachability module has a tracking module to 1) monitor network traffic and 2) keep a list of known devices and/or known subnets on the network, which is dynamically tracked and updated as previously unknown devices and subnets on the network are detected. A trigger module generates a spoofed transmission and/or response communication, supported by a network protocol used by the network. The spoofed transmission and/or response communication can be used to map network reachability of i) network devices, ii) network addresses, and iii) any combination of both, which either 1) can receive or 2) cannot receive protocol communications from a host for the network reachability module in the network.


