Targeted IP Address Scanning for Rogue Certificate Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for verifying security certificates across large IP address spaces are time-consuming and inefficient, making it difficult to detect rogue security certificates and suspicious activity in a timely manner.

Innovation Solution

A targeted scanning method that identifies a priority queue of IP addresses based on network activity, allowing for focused verification of security certificates, thereby reducing the time needed to detect rogue certificates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a scan is performed across an entire address space to verify all security certificates, then comprehensive security verification is achieved, but the time required to detect rogue certificates increases significantly

Engineering Contradiction:
Improvecomprehensive security verificationVSAvoiddetection time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent divides the entire IP address space into multiple sub-ranges and processes them in parallel using multiple scanning threads. This segmentation allows the system to maintain comprehensive coverage while reducing the time required for each individual scan segment, thereby resolving the contradiction between thorough verification and detection speed.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by first identifying and prioritizing IP addresses based on network activity metrics before conducting full security certificate verification. This preliminary filtering reduces the scope of comprehensive scanning to only those addresses most likely to contain rogue certificates, maintaining reliability while significantly reducing detection time.

Inventive Principle:
Principle #10Preliminary action

2Productivity

If traffic limits are imposed to avoid impacting network operational performance, then network performance is maintained, but the time required to verify security certificates increases

Engineering Contradiction:
Improvenetwork operational performanceVSAvoidcertificate verification time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent implements dynamic scanning rate adjustment based on network conditions and priority levels. High-priority IP addresses receive increased scanning intensity and bandwidth allocation, while lower-priority addresses are scanned at reduced rates. This dynamic approach maintains network performance by adapting traffic limits in real-time while ensuring critical verification tasks are completed promptly.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system continuously monitors network performance metrics and adjusts scanning traffic limits based on feedback from the network environment. When network performance degrades, the system automatically reduces scanning intensity; when performance allows, it increases verification throughput. This feedback mechanism resolves the contradiction by making traffic limits responsive rather than static.

Inventive Principle:
Principle #23Feedback

3Loss of time

If a priority queue system is implemented to focus scans on active IP addresses, then detection speed is improved, but system complexity increases

Engineering Contradiction:
Improvedetection timeVSAvoidscanning system complexity
Core Design Contradiction:
Loss of timeVSDevice complexity

Solution Approach 1:

The system automatically performs priority classification and queue management based on network activity metrics without requiring manual intervention. The scanning mechanism self-adjusts by pulling high-priority targets from the priority queue and allocating scanning resources accordingly. This self-service approach reduces detection time while minimizing the operational complexity burden on users.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent changes the parameter of scanning priority from a static configuration to a dynamic value that changes based on network activity metrics. IP addresses are re-prioritized continuously based on observed network behavior, allowing the system to adapt to changing threats while maintaining a manageable level of complexity through automated parameter adjustment rather than complex manual configuration.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS10630674B2Systems and methods for performing targeted scanning of a target range of IP addresses to verify security certificates
Publication Date: 2020.04.21 CITRIX SYSTEMS INC
  • US10630674B2 patent drawing
  • US10630674B2 patent drawing
  • US10630674B2 patent drawing

AI summary

The present disclosure is directed towards systems and methods for scanning of a target range of IP addresses to verify security certificates associated with the target range of IP addresses. Network traffic may be monitored between a plurality of clients and a plurality of servers over an IP address space. Traffic monitors positioned intermediary to the plurality of client and the plurality of servers can identify a target range of IP addresses in the address space for targeted scanning. The target range of IP address may be grouped into a priority queue and a scan can be performed of the target range of IP addresses to verify a security certificate associated with each IP address in the target range of IP addresses. In some embodiments, a rogue security certificate is detected that is associated with at least one IP address in the target range of IP addresses.