Vulnerability Detection Platform Using Attack Server Association
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing technologies face challenges in effectively identifying and mitigating compromised computing infrastructure, as legitimate operators often remain unaware of vulnerabilities and subsequent compromises.
Innovation Solution
A vulnerability detection platform that utilizes feeds to identify attack and potentially vulnerable servers, leveraging search infrastructure and NetFlow data to detect malicious activity and associate attack infrastructure with vulnerable targets.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional vulnerability scanning and monitoring methods are used, then some vulnerable systems can be detected, but the majority of compromised systems remain undetected because legitimate operators are unaware of the vulnerabilities
Solution Approach 1:
Instead of attempting to detect vulnerabilities from the perspective of system owners (who are unaware), the patent inverts the approach by monitoring from the attacker's perspective - tracking malicious infrastructure, command-and-control servers, and exploit traffic patterns. This allows detection of compromised systems through external behavioral indicators rather than relying on internal awareness.
Solution Approach 2:
The patent introduces intermediary indicators such as malicious IP addresses, domain names, hash values of malicious files, and network traffic patterns as mediators between the vulnerable system and the detection mechanism. These intermediaries provide observable evidence of compromise without requiring direct access to or awareness by the system operator.
2Reliability
If comprehensive monitoring of all computing infrastructure is implemented, then more compromised systems can be identified, but the complexity and cost of the detection system increases significantly
Solution Approach 1:
The patent applies local quality by focusing detection resources on specific high-value targets and indicators rather than attempting uniform monitoring of all infrastructure. It prioritizes monitoring of command-and-control servers, exploit kits, and known malicious infrastructure, allocating computational and analytical resources where they provide maximum protection value.
Solution Approach 2:
The detection system is segmented into multiple specialized components: threat intelligence gathering, indicator analysis, network traffic monitoring, vulnerability correlation, and response coordination. Each segment handles specific aspects of detection, reducing overall system complexity while maintaining comprehensive coverage through coordinated operation of discrete modules.
3Loss of time
If real-time detection and alerting systems are deployed, then compromised infrastructure can be identified quickly, but the time and resources required to process and analyze vast amounts of security data increase
Solution Approach 1:
The system performs preliminary actions by pre-collecting and indexing threat intelligence data, maintaining updated databases of known malicious infrastructure, and pre-establishing detection rules and correlations. This preparation work is done in advance so that when actual compromise indicators appear, they can be rapidly matched against pre-computed reference data, reducing real-time processing requirements.
Solution Approach 2:
The patent replaces manual mechanical analysis of security data with automated computational systems that use algorithms, machine learning models, and heuristic analysis to process large volumes of security data. This substitution of automated electronic processing for manual analysis dramatically increases processing speed and efficiency while maintaining detection accuracy.
Data Source
AI summary
Embodiments of a vulnerability detection platform and various examples of its uses are disclosed. A set of attack servers associated with malicious activity is received. A set of potentially vulnerable target servers is also received. A determination of an association between at least one attack server included in the set and one potentially vulnerable target server included in the set is made. An action is performed, at least in part, based on the determined association.


