Relay Device Bypasses Firewall Latency for Vulnerability Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional network vulnerability assessments face challenges in transmitting data through firewalls, leading to network latency issues and difficulties in calibrating systems, which can result in compromised security and data breaches.

Innovation Solution

A method involving a relay device that accesses a network from behind a firewall, establishing a communication channel with a monitor system via a secondary network, allowing for network vulnerability assessments to be performed independently of the firewall, using encrypted connections and adjusting assessments based on network latency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If network vulnerability assessments are performed through a firewall, then security protection is maintained, but network latency increases and assessment accuracy deteriorates

Engineering Contradiction:
Improvesecurity protectionVSAvoidnetwork latency
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent introduces a relay device as an intermediary component positioned behind the firewall. This relay device establishes a communication channel between the monitor system (in front of the firewall) and the monitored devices (behind the firewall), allowing vulnerability assessments to bypass the firewall's latency-inducing inspection processes while maintaining security boundaries.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If network vulnerability assessments are performed through a firewall, then security boundaries are maintained, but measurement precision deteriorates due to firewall interference

Engineering Contradiction:
Improvesecurity boundary maintenanceVSAvoidvulnerability assessment accuracy
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The relay device serves as a mediator that enables direct communication between the monitor system and monitored devices without firewall interference. This intermediary approach preserves the firewall's security boundary function while eliminating its negative impact on assessment precision by routing assessment traffic through an authorized channel.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

Instead of having the monitor system communicate directly through the firewall (traditional approach), the patent inverts the approach by having a relay device behind the firewall establish outgoing communication channels to the monitor system. This reversal allows assessments to bypass firewall inspection while maintaining security boundaries.

Inventive Principle:
Principle #13The other way round (Inversion)

3Device complexity

If conventional vulnerability assessment methods are used, then system simplicity is maintained, but false negatives increase due to firewall latency

Engineering Contradiction:
Improvesystem simplicityVSAvoidfalse negative rate
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The relay device acts as an intermediary that resolves the conflict between system simplicity and assessment accuracy. By introducing this single intermediary component behind the firewall, the system gains the ability to perform accurate vulnerability assessments without the complexity of multiple systems or configurations, thereby reducing false negatives while maintaining operational simplicity.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS20210273971A1Network vulnerability assessment
Publication Date: 2021.09.02 SECURITYMETRICS INC
  • US20210273971A1 patent drawing
  • US20210273971A1 patent drawing
  • US20210273971A1 patent drawing

AI summary

A method to assess network vulnerabilities of devices may include accessing, by a relay device, a network that includes a firewall to separate the network from external networks such that the relay device is coupled to the network from behind the firewall attached to the network. The method may further include establishing a communication channel over a secondary network between the relay device and a monitor system. The method may further include detecting one or more devices behind the firewall attached to the network by the relay device. The method may also include after establishing the communication channel and detecting the one or more devices and while the relay device is coupled to the network from behind the firewall attached to the network, performing, by the monitor system, one or more network vulnerability assessments on the one or more devices via network communications that pass through the relay device.