Rules-Based Engine for Network Scanning Disruption

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Network scanning, such as black box vulnerability scanning, can cause unstable behavior in network devices, leading to performance issues or shutdowns, and randomly selecting devices or scanning during off-peak times may not provide a comprehensive security assessment or be feasible due to constant network usage.

Innovation Solution

A rules-based engine identifies and scans network devices in accordance with a rule set, allowing for continuous scanning without waiting intervals, thereby minimizing disruptions and optimizing scanning efficiency by identifying initial and additional groups of devices to be scanned based on constraints like redundancy and network topology.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If network scanning is conducted to identify vulnerabilities, then security assessment capability is improved, but network device stability deteriorates

Engineering Contradiction:
Improvesecurity assessment capabilityVSAvoidnetwork device stability
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent segments the network device population into multiple groups based on service criticality and scanning impact. By dividing devices into different scan groups (e.g., critical services vs. non-critical services), the system can scan less critical devices more aggressively while protecting critical devices from scanning-induced instability, thus resolving the contradiction between comprehensive security assessment and device stability.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies different scanning strategies to different network devices based on their local characteristics. Critical devices receive lighter scanning or deferred scanning, while non-critical devices undergo more thorough scanning. This localized approach allows the system to maintain device stability for critical infrastructure while still achieving comprehensive security coverage.

Inventive Principle:
Principle #3Local quality

2Loss of time

If a subset of network devices is randomly selected for scanning, then scanning time is reduced, but measurement precision of security state deteriorates

Engineering Contradiction:
Improvescanning timeVSAvoidsecurity state accuracy
Core Design Contradiction:
Loss of timeVSMeasurement precision

Solution Approach 1:

The patent changes the selection parameters from random selection to rule-based selection criteria. Devices are selected for scanning based on multiple parameters including service criticality, historical vulnerability data, and current network conditions. This parameter-based selection reduces scanning time by prioritizing high-risk devices while maintaining measurement precision through intelligent targeting rather than random sampling.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system incorporates feedback mechanisms where scanning results and network conditions inform subsequent scanning decisions. Devices that show signs of vulnerability or are part of high-risk networks are prioritized for scanning, while devices with clean records may be deferred. This feedback-driven approach reduces overall scanning time while maintaining accurate security assessment by focusing resources on high-probability targets.

Inventive Principle:
Principle #23Feedback

3Reliability

If network scans are run during off-peak times, then network device stability is improved, but productivity of security assessment deteriorates

Engineering Contradiction:
Improvenetwork device stabilityVSAvoidsecurity assessment throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent implements dynamic scanning scheduling that adapts to real-time network conditions rather than using fixed off-peak time windows. The system continuously monitors network traffic patterns and device stability metrics, dynamically adjusting when to scan which devices. This allows scanning to occur during periods of lower actual load even if overall network usage is high, maintaining device stability while maximizing security assessment productivity throughout the day.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS11750635B2Minimizing production disruption through a scan rule engine
Publication Date: 2023.09.05 GOOGLE LLC
  • US11750635B2 patent drawing
  • US11750635B2 patent drawing
  • US11750635B2 patent drawing

AI summary

This technology is directed to a rules based engine for managing network-based scanning of devices on a network to minimize disruptions to the network. One or more processors may identify an initial group of network devices from a set of network devices, the initial group of network devices being identified in accordance with a rule set, and initiate a scan of the initial group of network devices. The one or more processors may determine, in accordance with the rule set, an additional group of network devices from the set of network devices to be scanned and initiate a scan of the additional group of network devices. The steps may be repeated until all network devices in the set of network devices are scanned in accordance with the rule set.