Network Vulnerability Scanner Control Device for Automated Test Profiles

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network and vulnerability scanners require extensive manual parameter adjustments, high administrative effort, and lack flexibility in scheduling investigations, often leading to delayed error corrections and increased complexity in security testing.

Innovation Solution

A control device with a first interface for selecting a test profile and a second interface for transmitting parameter data to the scanner, enabling simplified operation by defining and determining a logic of test runs, authenticating users, and ensuring secure data transmission, allowing for modular connection to various scanners and automatic detection of scanner types and operating systems.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If manual parameter adjustment is required for network and vulnerability scanner operation, then the scanner can be customized for specific examination needs, but the administrative effort and complexity increase significantly

Engineering Contradiction:
Improvecustomization capabilityVSAvoidadministrative effort
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the complex parameter configuration into pre-defined test profiles that group related parameters together. Users select entire profiles rather than configuring individual parameters, reducing administrative effort while maintaining customization through profile selection and combination.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies preliminary action by pre-configuring test profiles with commonly used parameter sets before actual scanning operations. This allows users to start examinations with ready-made configurations, reducing the time and effort required for manual parameter adjustment while still allowing customization when needed.

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If extensive manual configuration is required before scanning, then comprehensive security examination can be achieved, but the examination process takes longer and delays error correction

Engineering Contradiction:
Improveexamination completenessVSAvoidexamination duration
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

Test profiles are prepared in advance with comprehensive parameter sets that ensure complete security examinations. This preliminary configuration eliminates the need for time-consuming manual setup during actual scanning operations, maintaining examination completeness while reducing overall examination duration.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables self-service by allowing users to automatically select and apply appropriate test profiles based on their examination needs without requiring deep technical knowledge or extensive manual configuration. This automation maintains comprehensive examination coverage while significantly reducing setup time.

Inventive Principle:
Principle #25Self-service

3Reliability

If security testing requires coordination between functional testing and security testing, then thorough security assessment can be performed, but the process becomes more complex and requires security professionals

Engineering Contradiction:
Improvesecurity assessment qualityVSAvoidoperational simplicity
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent merges functional testing and security testing into integrated test profiles that combine both types of examinations. This consolidation maintains thorough security assessment quality by including both functional and security checks, while simplifying operation by providing unified profiles that don't require separate coordination between different testing disciplines.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

Test profiles are designed with multi-functionality, serving both functional testing and security testing purposes simultaneously. This universality allows non-security professionals to perform comprehensive security assessments using the same interface and configuration mechanisms used for functional testing, eliminating the need for specialized security testing procedures.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Productivity

If parameters are transmitted in plain text, then the scanner can process them efficiently, but unauthorized reading and security breaches become possible

Engineering Contradiction:
Improvedata processing speedVSAvoidunauthorized access
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent uses cryptographic encoding to create secure copies of parameter data during transmission. The original data remains unchanged for processing efficiency, while encoded copies are transmitted securely. This approach maintains productivity by allowing efficient processing of original data while preventing unauthorized access through secure transmission of encoded representations.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

Cryptographic encoding acts as an intermediary between the parameter data and the transmission channel. The encoding layer protects the underlying data from unauthorized reading during transmission, while allowing the receiving system to efficiently process the data after proper decryption, thus balancing security requirements with processing efficiency.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2985715B1Control device and method for a network and vulnerability scanner
Publication Date: 2018.02.14 DEUTSCHE TELEKOM AG
  • EP2985715B1 patent drawingFigure 1
  • EP2985715B1 patent drawingFigure 2
  • EP2985715B1 patent drawingFigure 3

AI summary

The present invention relates to a control device (100) for a network and vulnerability scanner (110) for examining a computer system (200) for the presence of security vulnerabilities, comprising a first interface (101-1) for selecting a test profile comprising parameter data that defines an examination of the computer system (200); and a second interface (101-2) for transmitting the parameter data of the test profile to the network and vulnerability scanner.