Scan Assistant Authentication for Network Asset Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network computing systems face challenges in authenticated asset assessment due to the need for administrative or root-level credentials, which complicate credential management and increase the risk of unauthorized access if credentials become compromised.

Innovation Solution

The implementation of a scan assistant within the network system that authenticates a scan engine without requiring third-party credentials, using a reversed two-way client certificate authentication method to simplify deployment and reduce the risk of credential compromise.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If administrative or root-level credentials are used for authenticated asset assessment, then authentication reliability is improved, but device complexity and ease of operation deteriorate due to complex credential management and deployment challenges

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidcredential management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a credential service as an intermediary component that manages authentication credentials centrally. Instead of embedding credentials directly in scan engines or requiring manual administrative credential management, the credential service acts as a mediator that provides credentials to authorized components through standardized interfaces. This resolves the contradiction by maintaining authentication reliability through centralized credential management while reducing device complexity by eliminating the need for each scan engine to independently manage sensitive credentials.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If administrative or root-level credentials are used for authenticated asset assessment, then authentication reliability is improved, but ease of operation worsens due to challenges in credential distribution and integration with third-party services

Engineering Contradiction:
Improveauthentication reliabilityVSAvoidcredential deployment ease
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent implements self-service mechanisms where the credential service automatically discovers, manages, and distributes credentials to scan engines and other components without requiring manual administrative intervention for each credential deployment. The system includes automated credential rotation, renewal, and revocation capabilities that operate autonomously. This resolves the contradiction by maintaining authentication reliability while dramatically improving ease of operation, as administrators no longer need to manually distribute and manage complex credentials across multiple systems.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If traditional authenticated scanning is implemented, then measurement precision of asset state is improved, but loss of time increases due to requirement for ad-hoc or scheduled assessments and remediation verification scans

Engineering Contradiction:
Improveasset state assessment precisionVSAvoidassessment time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent transforms the traditional periodic or ad-hoc assessment model into a continuous monitoring system. The scan assistant and credential service enable ongoing authenticated access to assets, allowing the system to continuously collect and update asset state information without requiring repeated full assessment cycles. This resolves the contradiction by maintaining measurement precision through continuous data collection while eliminating time loss associated with scheduling and executing periodic assessments and remediation verification scans.

Inventive Principle:
Principle #20Continuity of useful action

4Productivity

If continuous updates on asset risk are required, then productivity is improved, but device complexity increases due to need for continuous monitoring and assessment mechanisms

Engineering Contradiction:
Improverisk update frequencyVSAvoidcontinuous monitoring complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent creates multi-functional components that perform multiple roles. The credential service not only manages authentication credentials but also coordinates continuous monitoring activities, manages scan engine lifecycles, and handles remediation verification. The scan assistant similarly integrates multiple functions including event monitoring, scan coordination, and result aggregation. This resolves the contradiction by enabling continuous risk updates that improve productivity while avoiding the complexity increase that would result from adding separate dedicated components for each function.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12206800B1Event-driven assessment of network system assets
Publication Date: 2025.01.21 RAPID7 INC
  • US12206800B1 patent drawing
  • US12206800B1 patent drawing
  • US12206800B1 patent drawing

AI summary

A method for asset assessment is provided. The method includes receiving, by a scan engine, an event message from a scan assistant associated with an asset of a network system. The asset includes at least one computing resource. The event message includes an indication of one or more events associated with the asset. The method also includes responsive to receiving the event message, transmitting, by the scan engine, a request to the scan assistant for executing one or more scan operations on the asset and to determine a state of the asset based on at least one of an amount of available network resources or a schedule associated with the asset. The method further includes executing, by the scan engine, the one or more scan operations on the asset after transmitting the request.