Reverse Scanning Agent for Network Vulnerability Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security technologies primarily focus on remote vulnerability scanning of servers, neglecting the security of the entire network environment, including clients, which can lead to undetected vulnerabilities being exploited by hackers.
Innovation Solution
A method and device involving a reverse scanning agent module that acquires and analyzes client messages to identify vulnerabilities, supplementing server security checks with client security analysis, and a vulnerability scanner that receives and processes these messages to update vulnerability rules and control the scanning process.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If vulnerability scanning is performed only on servers using prior art methods, then server security can be detected, but client security vulnerabilities remain undetected
Solution Approach 1:
The patent inverts the traditional scanning direction by placing scanning agents on servers to actively scan client devices instead of having external scanners scan servers. This reverse approach enables comprehensive detection of both server and client vulnerabilities, resolving the contradiction between maintaining server-focused detection reliability and expanding scanning coverage to include clients.
2Reliability
If remote vulnerability scanning is performed on servers only, then the scanning process is simple, but the entire network environment security cannot be verified
Solution Approach 1:
The patent segments the scanning system into distributed scanning agents deployed on individual servers and a centralized management server. Each agent independently scans client devices connected to its local network, while the management server coordinates and aggregates results. This segmentation enables comprehensive network security verification without requiring a monolithic complex scanning system.
Solution Approach 2:
The patent introduces scanning agents as intermediary components that bridge the gap between the centralized management server and client devices. These agents receive scanning tasks from the management server, execute local scans of connected clients, and report results back, thereby enabling comprehensive network security verification through a structured multi-layered architecture.
3Measurement precision
If traditional vulnerability scanners are used, then server vulnerabilities can be identified, but client message analysis for vulnerability detection is not performed
Solution Approach 1:
The patent adds a new dimension to vulnerability detection by analyzing client messages (HTTP requests, responses, and traffic patterns) in addition to traditional server scanning. The scanning agents capture and analyze messages between clients and servers, enabling detection of client-side vulnerabilities through message content analysis, thereby enhancing measurement precision for vulnerability identification.
Data Source
AI summary
The disclosed embodiment provides a method and device for vulnerability scanning, the method comprising: a reverse scanning agent module acquires a client message; the reverse scanning agent module transmits the client message to a vulnerability scanner, enabling the vulnerability scanner to identify a vulnerability of the client according to the client message; or the reverse scanning agent module identifies the vulnerability of the client according to the client message and transmits the vulnerability to the vulnerability scanner; the reverse scanning agent module receives a control instruction from the vulnerability scanner, changes operation manner and/or mode according to the control instruction, and updates a vulnerability rule. The reverse scanning agent module in the disclosure acquires and analyzes the client message to identify the vulnerability of the client, which supplements server security issue remote detection with client security issue analysis, thereby realizing security detection for the entire network.


