Security Scanning System for Customer Premises Equipment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for determining and addressing security vulnerabilities in application programs for customer premises equipment (CPE) are inadequate, as they do not provide comprehensive and integrated solutions for identifying and fixing vulnerabilities across various applications in a network environment.

Innovation Solution

A system and method that utilize multiple scanning programs, including network scanners and web-based scanners, to identify security vulnerabilities in control panel, Internet content, and component management system applications, correlating results to provide a consolidated report and risk assessment, with the ability to run these programs on servers within the network or at application provider locations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If individual security scanners are run against each application program separately, then each provider can test their own programs, but comprehensive and integrated security vulnerability detection across the network environment cannot be achieved

Engineering Contradiction:
Improvesecurity vulnerability detectionVSAvoidsecurity scanning system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple individual security scanners into a single integrated security scanning system that can simultaneously scan multiple application programs from different providers. The system merges the scanning capabilities of individual tools while adding coordination and correlation functions to provide comprehensive security assessment across the entire network environment, resolving the contradiction between individual testing and comprehensive detection.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The integrated security scanning system is designed to be universal by accepting application programs from multiple different providers and scanning them with a unified approach. The system can handle diverse application types (control panel, Internet content, component management) through a single multi-functional platform, eliminating the need for separate scanning systems for each provider while maintaining comprehensive coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If multiple scanning programs are run against various application programs to achieve comprehensive vulnerability identification, then security coverage is improved, but the complexity and resource requirements of the scanning system increase

Engineering Contradiction:
Improvesecurity vulnerability detectionVSAvoidscanning system structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the security scanning process into distinct functional modules, each responsible for scanning specific types of application programs (control panel, Internet content, component management). This segmentation allows the system to manage complexity by organizing multiple scanners into structured categories while maintaining comprehensive coverage through coordinated operation of all segments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a central coordinator or intermediary component that manages the operation of multiple scanning programs. This intermediary receives application programs, distributes them to appropriate scanners, collects results, and correlates findings into a unified security assessment. The intermediary simplifies the system architecture by providing a single point of control rather than requiring direct integration between all scanner components.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Adaptability or versatility

If security scanners are deployed at multiple locations (network servers and application provider locations), then scanning flexibility and coverage are improved, but system coordination and result correlation become more difficult

Engineering Contradiction:
Improvescanning location flexibilityVSAvoiddistributed system coordination
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent implements feedback mechanisms where scanning results from distributed locations are continuously collected and correlated with the central system. The system receives vulnerability data from scanners at network servers and application provider locations, processes this feedback information, and uses it to generate comprehensive security assessments. This feedback loop enables coordinated operation across distributed locations while maintaining unified control and result correlation.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS9197659B2Security scanning system and method
Publication Date: 2015.11.24 AT&T INTELLECTUAL PROPERTY I L P
  • US9197659B2 patent drawing
  • US9197659B2 patent drawing
  • US9197659B2 patent drawing

AI summary

The present disclosure provides a computer-readable medium, method and system for determining security vulnerabilities for a plurality of application programs used to provide television services to a customer device over a communications network. The method includes running a first scanning program against a first application program relating to a control panel for the customer device; running a second scanning program against a second application program that provides Internet content to the customer device; running a third scanning program against a third application program that relates to a component management system of customer premises equipment; and correlating security vulnerabilities identified utilizing the first, second, and third scanning programs.