Remote Registry Security Audits via Temporary Service Enablement

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems cannot effectively perform complete network audits due to the security risks associated with enabling remote access to device registries, which are often disabled to prevent malicious activity, thereby limiting the ability to obtain necessary information for vulnerability identification and remediation.

Innovation Solution

A system and method that utilize active and passive vulnerability scanners to temporarily enable remote registry access on devices with disabled services, allowing for the collection of registry information while minimizing exposure to malicious activity, and then disabling the service to prevent unauthorized access.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Difficulty of detecting and measuring

If remote registry service is enabled to allow vulnerability scanning, then network security audit capability is improved, but security risk increases due to potential malicious access

Engineering Contradiction:
Improvenetwork vulnerability detection capabilityVSAvoidsecurity risk from malicious activity
Core Design Contradiction:
Difficulty of detecting and measuringVSObject-affected harmful factors

Solution Approach 1:

The vulnerability scanner performs preliminary actions by enabling the remote registry service before conducting the security audit. This allows the scanner to access registry information needed for vulnerability detection, and then disables the service after the audit to prevent malicious activity, thus resolving the contradiction between detection capability and security risk

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables the remote registry service temporarily just long enough to complete the vulnerability scan, then immediately disables it. This rushing through approach allows the necessary security audit to be performed without leaving the service enabled, minimizing the window of exposure to malicious activity

Inventive Principle:
Principle #21Skipping (Rushing through)

2Object-affected harmful factors

If remote registry service is disabled to prevent malicious activity, then security risk is reduced, but network audit completeness deteriorates

Engineering Contradiction:
Improvesecurity risk from malicious activityVSAvoidregistry information availability
Core Design Contradiction:
Object-affected harmful factorsVSLoss of information

Solution Approach 1:

The system performs the necessary registry information collection as a preliminary action before disabling the remote registry service. This ensures that all required information for the security audit is obtained while the service is still accessible, preventing information loss while maintaining security

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The remote registry service is enabled continuously during the vulnerability scanning process to ensure uninterrupted information collection. The service is disabled only after the scanning action is complete, maintaining continuity of the useful audit action while ensuring security

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS8839442B2System and method for enabling remote registry service security audits
Publication Date: 2014.09.16 TENABLE INC
  • US8839442B2 patent drawing
  • US8839442B2 patent drawing
  • US8839442B2 patent drawing

AI summary

The system and method for enabling remote registry service security audits described herein may include scanning a network to construct a model or topology of the network. In particular, the model or topology of the network may include characteristics describing various devices in the network, which may be analyzed to determine whether a remote registry service has been enabled on the devices. For example, the security audits may include performing one or more credentialed policy scans to enable the remote registry service for certain devices that have disabled the remote registry service, auditing the devices in response to enabling the remote registry service, and then disabling the remote registry service on the devices. Thus, the system and method described herein may enable remotely scanning information contained in device registries during a security audit without exposing the device registries to malicious activity.