Reconnaissance and Assessment Tool for Network Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing vulnerability assessment and security tools are limited in identifying 'forgotten' components in computer networks, as they rely on user and administrator input and fail to detect unrecorded or unidentified network elements, leading to incomplete security assessments.

Innovation Solution

A reconnaissance and assessment (RA) tool that integrates network reconnaissance and security assessments, using base information to identify the attack surface by scanning internal and external sources, including third-party databases and search engines, to uncover unknown components and iteratively perform additional assessments based on new information found during security evaluations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If existing vulnerability assessment and security tools are used, then security assessment can be performed on identified components, but 'forgotten' components are never detected because users and administrators do not know about them

Engineering Contradiction:
Improvecompleteness of security assessmentVSAvoidunknown network components
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The system performs preliminary network reconnaissance before security assessment to identify all network components, including forgotten ones. The reconnaissance phase proactively scans network infrastructure, discovers hidden components, and builds a comprehensive inventory before the actual security assessment begins, ensuring no components are overlooked.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables itself to discover and identify network components without requiring manual input from users or administrators. Through automated reconnaissance techniques, the system independently maps the network topology, identifies services, and detects forgotten components, eliminating the dependency on human knowledge of the network infrastructure.

Inventive Principle:
Principle #25Self-service

2Productivity

If manual identification of network components is required, then security assessment can be targeted, but the process becomes time-consuming and incomplete due to forgotten components

Engineering Contradiction:
Improvespeed of security assessmentVSAvoidtime to identify all components
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system replaces manual identification processes with automated computer-based reconnaissance. Instead of requiring users to manually list network components, the system uses automated scanning, network mapping, and data collection techniques to rapidly identify all components, including forgotten ones, significantly reducing the time required for comprehensive security assessment.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If security assessment tools are limited to user-identified components, then tool simplicity is maintained, but detection coverage is reduced due to forgotten components

Engineering Contradiction:
Improvescope of network assessmentVSAvoidreconnaissance and assessment integration
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The system merges network reconnaissance functionality with security assessment tools into a unified platform. The reconnaissance module discovers all network components and the assessment module evaluates them for security vulnerabilities, combining what were previously separate functions into one integrated system that maintains simplicity while expanding scope to include forgotten components.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system creates a universal tool that performs multiple functions: network reconnaissance, component identification, security assessment, and vulnerability detection. This multi-functional approach allows a single tool to handle the entire security evaluation process, from discovering forgotten components to assessing their security posture, thereby expanding assessment scope without requiring multiple specialized tools.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS10447709B2Methods and systems for integrating reconnaissance with security assessments for computing networks
Publication Date: 2019.10.15 RAPID7 INC
  • US10447709B2 patent drawing
  • US10447709B2 patent drawing
  • US10447709B2 patent drawing

AI summary

A reconnaissance and assessment (RA) tool can receive base information about the network, such as basic network information and details about an entity and personnel associated with network. The RA tool can utilize the base information to perform reconnaissance procedures on the network to identify the attack surface of the network. The RA tool can perform reconnaissance on the network, itself, and on other external sources, such as third party databases, search engines, and partner networks. Once the attack surface is identified, the RA tool can automatically perform appropriate security assessments on the attack surface. Additionally, if additional information is determined about the network during the security assessments, the RA tool can perform additional reconnaissance and security assessments based on the additional information.