Reconnaissance Agent for Broadcast Domain Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current penetration testing systems face challenges in reliably identifying network nodes that share a common broadcast domain, which is crucial for assessing cyber-attacks and distributing data effectively, due to limitations in existing methods that often result in incorrect conclusions or inefficiencies.

Innovation Solution

A method and system that utilize reconnaissance agent software modules installed on network nodes to monitor and report data packets, allowing a penetration testing system to determine if nodes share a common broadcast domain by matching conditions such as packet types and timestamps, enabling accurate identification and potential attack methods.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If automated penetration testing systems are used to discover and report vulnerabilities, then productivity is improved, but measurement precision deteriorates due to inability to reliably identify broadcast domain members

Engineering Contradiction:
Improvepenetration testing efficiencyVSAvoidbroadcast domain identification accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent introduces a dedicated intermediary component called a 'reconnaissance agent' that is deployed on each network node to monitor and report broadcast domain membership. This agent acts as a mediator between the penetration testing system and the network nodes, collecting accurate broadcast domain information through packet analysis and relayed to the testing system for precise identification.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces manual network scanning methods with automated computer-based packet analysis. The reconnaissance agents automatically capture network packets, analyze their contents to determine broadcast domain membership, and transmit this information to the penetration testing system, eliminating the need for manual network exploration while improving both speed and accuracy.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If manual penetration testing by expert consultants is performed, then measurement precision is improved, but productivity deteriorates due to time-consuming nature and high costs

Engineering Contradiction:
Improvevulnerability detection accuracyVSAvoidtesting speed and cost-efficiency
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent implements self-service automation where reconnaissance agents are automatically deployed on network nodes to perform their own monitoring and reporting functions. The agents autonomously capture packets, analyze broadcast domain membership, and communicate with the penetration testing system without requiring continuous human intervention, enabling 24/7 operation and eliminating the need for expensive expert consultants for routine monitoring.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates virtual copies of network nodes through the reconnaissance agents that replicate the actual network infrastructure. These agent instances can be deployed, managed, and analyzed independently of the production network, allowing penetration testing to be performed on copies rather than directly on the live network, thereby improving safety and enabling parallel testing operations.

Inventive Principle:
Principle #26Copying

3Reliability

If comprehensive vulnerability testing is performed to ensure security, then reliability is improved, but loss of time increases due to lengthy testing processes

Engineering Contradiction:
Improvenetwork security assessment thoroughnessVSAvoiddiscovery period after new threats appear
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by continuously monitoring network traffic and maintaining an updated database of broadcast domain members through the reconnaissance agents. This ongoing collection of network topology information is done in advance of specific testing events, so when vulnerability assessment is needed, the data is already ready, eliminating time-consuming network discovery phases and enabling rapid security assessments.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements continuous monitoring where reconnaissance agents operate non-stop to track broadcast domain membership changes and network traffic patterns. This uninterrupted data collection ensures that the penetration testing system always has current information about the network topology, enabling immediate and continuous security assessment without the need for periodic re-scanning or re-discovery of network structures.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS10498803B1Identifying communicating network nodes in the same local network
Publication Date: 2019.12.03 XM CYBER LTD
  • US10498803B1 patent drawing
  • US10498803B1 patent drawing
  • US10498803B1 patent drawing

AI summary

Methods and systems for executing a penetration test of a networked system by a penetration testing system so as to determine a method by which an attacker could compromise the networked system, and/or for distributing common sets of data to nodes of a networked system. The methods and systems include identifying network nodes which have shared broadcast domains.