Time-Tagged Penetration Testing Scenarios

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing penetration testing systems lack the ability to conduct time-specific tests, leading to inefficiencies and potentially misleading results due to their calendar-time-agnostic nature, which can result in vulnerabilities being overlooked or misinterpreted, especially in scenarios like watering hole attacks, Denial-Of-Service (DOS) attacks, and tests requiring specific timing.

Innovation Solution

The implementation of a user-selectable time-tagged scenario system that allows penetration testing campaigns to be scheduled and executed at specific times, ensuring that only scenarios matching the scheduled start time are displayed and selectable, thereby optimizing the testing process and ensuring accurate vulnerability assessment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If penetration testing is conducted without time-specific scheduling, then the testing can be performed at any time, but the accuracy of vulnerability detection deteriorates due to missing time-sensitive attack patterns

Engineering Contradiction:
Improvevulnerability detection accuracyVSAvoidtesting system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent applies preliminary action by pre-defining time-tagged scenarios that specify optimal testing times for different attack types. Before conducting penetration testing, the system prepares a library of scenarios with associated time tags (e.g., watering hole attacks scheduled during business hours, DOS attacks during low-traffic periods). This allows the testing system to automatically select and execute the appropriate scenario based on the current time, thereby improving vulnerability detection accuracy without requiring complex real-time decision-making logic during the actual testing process.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If penetration testing is conducted at inappropriate times, then the testing process is simpler to schedule, but the reliability of test results deteriorates due to false negatives and false positives

Engineering Contradiction:
Improvetest result reliabilityVSAvoidtesting scheduling time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements self-service by enabling the penetration testing system to automatically select appropriate test scenarios based on the current time and scheduled start time. The system retrieves time-tagged scenarios from storage, compares their time tags with the scheduled time, and autonomously selects the matching scenario without requiring manual intervention or complex scheduling algorithms. This self-service mechanism ensures reliable test results by guaranteeing that the correct time-specific scenario is executed, while minimizing the time loss associated with manual scenario selection and scheduling decisions.

Inventive Principle:
Principle #25Self-service

3Ease of operation

If all pre-defined scenarios are always displayed, then the user has maximum flexibility in selection, but the ease of operation deteriorates due to difficulty in identifying time-appropriate scenarios

Engineering Contradiction:
Improvescenario selection easeVSAvoidscenario selection flexibility
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by dynamically filtering and displaying only those pre-defined scenarios whose time tags match the current or scheduled start time. Instead of presenting all scenarios uniformly, the system adapts the displayed scenario set based on the temporal context. This local customization of the scenario list allows users to easily identify and select appropriate scenarios without being overwhelmed by irrelevant options, while still maintaining access to the full range of time-specific scenarios when needed. The filtering mechanism is applied locally to the scenario display rather than globally to the entire system.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS10581895B2Time-tagged pre-defined scenarios for penetration testing
Publication Date: 2020.03.03 XM CYBER LTD
  • US10581895B2 patent drawing
  • US10581895B2 patent drawing
  • US10581895B2 patent drawing

AI summary

Methods and systems for carrying out campaigns of penetration testing for discovering and reporting security vulnerabilities of a networked system. Penetration testing campaigns are carried out based on pre-defined penetration testing scenarios associated with respective time tags. A penetration testing scenario is selected by a user from a set of pre-defined test scenarios, the set containing only pre-defined test scenarios with time tags matching a scheduled starting time of a penetration testing campaign.