Security Asset Manager for Vulnerability Scanning Coordination
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current vulnerability scanners, such as Nessus, are limited in their ability to assess security vulnerabilities beyond individual machines, failing to consider network configurations and often require manual intervention to manage and update, which can lead to incomplete security assessments in complex networks.
Innovation Solution
A Security Asset Manager (SAM) system that coordinates multiple vulnerability scanners to perform comprehensive scans across a network, assigns severity ratings based on network configurations, and automatically updates plugins to ensure accurate and efficient vulnerability detection and reporting.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If multiple vulnerability scanners are deployed to scan multiple networks, then the coverage and comprehensiveness of vulnerability assessment is improved, but the system complexity and coordination overhead increase
Solution Approach 1:
The patent combines multiple vulnerability scanners and network assessment tools into a single integrated Security Asset Manager platform. This consolidation allows the system to coordinate scans across multiple networks simultaneously while centralizing vulnerability data collection, analysis, and reporting functions, thereby improving assessment completeness without proportionally increasing system complexity
Solution Approach 2:
The Security Asset Manager is designed as a universal platform that can perform multiple functions including vulnerability scanning, network discovery, asset inventory, and compliance checking across diverse network environments. This multi-functionality allows a single system to replace multiple specialized tools, improving comprehensive coverage while reducing the overall complexity of managing separate scanning systems
2Ease of operation
If manual updates and management of vulnerability scanners are performed, then individual scanner control is maintained, but time consumption and operational effort increase
Solution Approach 1:
The Security Asset Manager implements automatic self-updating capabilities that allow the system to autonomously download, install, and configure vulnerability scanner plugins and database updates without requiring manual intervention. The system automatically manages its own maintenance tasks including signature updates, plugin installations, and configuration synchronizations across all deployed scanners, eliminating time-consuming manual update processes while maintaining centralized control
Solution Approach 2:
The system incorporates automated feedback mechanisms where the Security Asset Manager continuously monitors scanner performance, vulnerability database currency, and plugin versions across all scanned networks. Based on this feedback, the system automatically initiates update processes, coordinates plugin distributions, and synchronizes configurations across the scanning infrastructure, reducing manual operational effort while maintaining precise control
3Productivity
If severity ratings are assigned without considering network configuration, then vulnerability identification is simplified, but the accuracy and relevance of security risk assessment deteriorate
Solution Approach 1:
The Security Asset Manager performs preliminary network discovery and asset inventory assessments before conducting vulnerability scans. By pre-collecting information about network topology, device types, operating systems, and service configurations, the system prepares contextual data that enables accurate severity rating adjustments. This preliminary action allows the system to quickly correlate vulnerability findings with relevant network context during the scanning phase, maintaining high productivity while ensuring accurate risk assessment
Solution Approach 2:
The system applies local quality adjustments to severity ratings based on specific network configuration contexts. Rather than using uniform severity criteria across all scans, the Security Asset Manager tailors severity assessments to local network conditions such as device criticality, network segment security zones, exposed services, and compliance requirements. This contextualized approach maintains scanning efficiency while significantly improving the accuracy and relevance of security risk assessments
Data Source
AI summary
Implementations of the present disclosure involve a system and/or method of performing security asset management. The system and/or method may schedule vulnerability scanners to scan the various portions of one or more networks and obtain the results of the vulnerability scans. IP addresses may be assigned to each of vulnerability scanners to scan. The system obtains the results of the vulnerability scans and may adjust the results of the scans according to configuration of the one or more networks that an IP address is associated with. The system and/or method may also assign and reassign IP addresses amongst the scanners to optimize scanning speed.


