Unified Scan Engine for Security Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security scanning tools often require manual synthesis of results from multiple independent scanning utilities, leading to inefficiencies and difficulties in generating comprehensive security assessments due to redundant checks and inconsistent data.

Innovation Solution

An asset management system and unified scan engines that centralize control and processing of scans, utilizing a library of language interpreters to perform various scans and aggregate results, thereby streamlining security assessments and reducing human intervention.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If multiple independent scanning utilities are used to perform comprehensive security scans, then the coverage and thoroughness of security assessment is improved, but the complexity of synthesizing results and generating reports increases

Engineering Contradiction:
Improvesecurity assessment completenessVSAvoidresult synthesis complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple independent scanning utilities into a single unified scanning system that executes multiple scan types (vulnerability scans, port scans, traceroute, ping) through a centralized engine. The unified system consolidates result collection, synthesis, and report generation into one integrated platform, eliminating the need for manual synthesis of results from separate tools while maintaining comprehensive security assessment coverage.

Inventive Principle:
Principle #5Merging (Combining)

2Adaptability or versatility

If multiple independent scanning utilities are deployed to cover different security aspects, then the versatility of scanning capabilities is improved, but the consistency and coordination of scans deteriorates

Engineering Contradiction:
Improvescanning capability diversityVSAvoidscan result consistency
Core Design Contradiction:
Adaptability or versatilityVSStability of the object's composition

Solution Approach 1:

The unified scanning system implements a multi-functional scan engine capable of executing various scan types (vulnerability assessment, port scanning, network path analysis, host availability checks) through a single platform. The system maintains consistent configuration management and coordinated execution across all scan types, ensuring uniform result formats and synchronized timing while preserving the diversity of scanning capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If manual synthesis of scan results is performed by administrators, then the flexibility in analyzing results is improved, but the time and effort required for security reporting increases

Engineering Contradiction:
Improveresult analysis flexibilityVSAvoidreport generation time
Core Design Contradiction:
Ease of operationVSLoss of time

Solution Approach 1:

The unified scanning system performs preliminary automated synthesis and organization of scan results from multiple scan types before report generation. The system pre-processes and structures data from vulnerability scans, port scans, traceroute, and ping operations into standardized formats, preparing comprehensive security assessment data in advance. This preliminary automation reduces the time required for administrators to generate final reports while preserving their ability to analyze and interpret results flexibly.

Inventive Principle:
Principle #10Preliminary action

4Measurement precision

If multiple scanning tools are used to test network vulnerabilities, then the depth of security testing is improved, but the redundancy of checks and resource consumption increases

Engineering Contradiction:
Improvevulnerability detection accuracyVSAvoidcomputational resource consumption
Core Design Contradiction:
Measurement precisionVSLoss of energy

Solution Approach 1:

The unified scanning system implements dynamic scan orchestration that adapts the execution of multiple scan types based on real-time conditions and previously obtained results. The system dynamically determines which scans to execute next based on findings from previous scans, avoiding redundant checks. For example, if a host is determined to be inactive through ping, subsequent vulnerability scans for that host are dynamically skipped, reducing resource consumption while maintaining detection accuracy for active targets.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS9407653B2Unified scan management
Publication Date: 2016.08.02 MCAFEE LLC
  • US9407653B2 patent drawing
  • US9407653B2 patent drawing
  • US9407653B2 patent drawing

AI summary

A particular scan set to be performed on at least a portion of a computing environment is identified. A particular scan engine, in a plurality of scan engines, is identified that is adapted to perform at least one scan in the particular scan set, each scan engine in the plurality of scan engines adapted to perform one or more scans on one or more host devices in the computing environment. A request is sent to the particular scan engine to perform the at least one scan in the particular scan set and scan result data is received from the particular scan engine corresponding to the at least one scan in the particular scan set.