Remote Network Security Scanner for Enterprise Audit

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current antivirus and patch management solutions are inefficient in monitoring and reporting the security readiness of multiple computing machines across a network, particularly in detecting up-to-date antivirus versions and Windows Server Update Services configurations, leading to increased vulnerability and productivity losses due to time-consuming manual processes.

Innovation Solution

The Network Security Scanner for Enterprise Protection (NSSEP) allows remote, unobtrusive scanning of computing machines across geographic locations without software installation, generating comprehensive reports on antivirus versions, quarantined files, and patch management status, enabling IT Management Groups to assess and upgrade security preparedness efficiently.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If built-in audit tools of antivirus solutions are used, then security monitoring is performed, but the tools are ineffective when administrator-privileged users stop services on their workstations, leading to incomplete security assessment

Engineering Contradiction:
Improvesecurity monitoring reliabilityVSAvoidservice accessibility
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent introduces a remote scanning mechanism that acts as an intermediary to access and audit security services on remote computers. Instead of relying on local audit tools that may be disabled by users, the system establishes remote connections to scan and assess antivirus and patch management status, bypassing local service restrictions and providing reliable security monitoring regardless of user actions.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If manual security auditing is performed by dedicated IT engineers, then comprehensive security assessment is achieved, but it requires significant time (almost a whole day) and reduces productivity

Engineering Contradiction:
Improvesecurity audit completenessVSAvoidIT engineer productivity
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent implements automated scanning and reporting functionality that performs security audits without requiring dedicated IT engineer intervention. The system automatically connects to remote computers, scans for security vulnerabilities, collects information about antivirus software and patch status, and generates comprehensive reports. This self-service capability eliminates the need for manual auditing while maintaining complete security assessment accuracy.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical manual process of security auditing with an automated electronic scanning system. Instead of IT engineers manually checking each computer's security status, the system uses automated remote scanning technology to collect and analyze security data across the network, dramatically reducing time requirements while maintaining or improving audit completeness.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Loss of information

If full security scanning is performed on all computing machines, then complete security information is obtained, but it takes significant time (more than twenty five minutes per segment) to complete

Engineering Contradiction:
Improvesecurity information completenessVSAvoidscanning time
Core Design Contradiction:
Loss of informationVSLoss of time

Solution Approach 1:

The patent divides the network into segments and processes them systematically. By organizing computers into manageable segments and scanning them in an structured manner, the system efficiently collects security information across the entire network while optimizing resource usage and reducing overall scanning time compared to attempting to scan all machines simultaneously or without organization.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS8850587B2Network security scanner for enterprise protection
Publication Date: 2014.09.30 WIPRO LTD
  • US8850587B2 patent drawing
  • US8850587B2 patent drawing
  • US8850587B2 patent drawing

AI summary

A method of monitoring levels of security conformity and preparedness of a plurality of network connected computing machines, obtains a report by remotely scanning the machines in segments. The machines might already be connected to commercial security software and a patch dispenser. The report includes definition dates and any files quarantined by the commercial security software, patch-management-software communication present and the patches received. The method uses the report and software (not installed on the scanned machines) to produce a Network Security Scanner for Enterprise Protection output to perform a security-preparedness audit of the scanned machines. The audit non-intrusively ascertains. If the scanned machines conform to user-defined fields and policies, and assists in selective security updating of the machines. The scanning, unrecognized by the scanned machines may be configured to suit their OS, and done periodically as desired. A computer readable medium executing the method is included.