IP Library Granted Patent US 7,673,043
Granted Patent B2
US 7,673,043 · App. 11/748,445 · Granted Mar 2, 2010

System and method for network vulnerability detection and reporting

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 7,673,043
App. No.
11/748,445
Granted
Mar 2, 2010
Kind
B2
Abstract

A system and method provide comprehensive and highly automated testing of vulnerabilities to intrusion on a target network, including identification of operating system, identification of target network topology and target computers, identification of open target ports, assessment of vulnerabilities on target ports, active assessment of vulnerabilities based on information acquired from target computers, quantitative assessment of target network security and vulnerability, and hierarchical graphical representation of the target network, target computers, and vulnerabilities in a test report. The system and method employ minimally obtrusive techniques to avoid interference with or damage to the target network during or after testing.

Claims (62)

1. A method of conducting an automated vulnerability assessment on a computer network, comprising:

sending a plurality of IP addresses to a network scanning process;

assigning a first group of IP addresses from the plurality of IP addresses to a first subscanning process and assigning a second group of IP addresses from the plurality of IP addresses to a second subscanning process, the first subscanning process scanning the computer network with a first selected sequence of IP addresses from the first group of IP addresses and receiving and storing a first set of responses from the computer network, the second subscanning process scanning the computer network with a second selected sequence of IP addresses from the second group of IP addresses and receiving and storing a second set of responses from the computer network, the first selected sequence of IP addresses and the second selected sequence of IP addresses being applied in parallel; and

providing the first set of responses and the second set of responses as data for performing a vulnerability assessment of the computer network;

wherein an IP address shuffler performs a deterministic shuffling process on a group of IP addresses.

2. The method as defined in claim 1 , wherein the deterministic shuffling process uses a prime number to determine an order of IP addresses in a shuffled IP address array.

3. The method as defined in claim 1 , wherein the network scanning process divides an initial range of IP addresses into a plurality of subranges of IP addresses.

4. The method as defined in claim 3 , wherein each of the subranges of IP addresses include contiguous IP addresses.

5. The method as defined in claim 1 , wherein each subscanning process reports subscanning results to the network scanning process.

6. A method of conducting an automated vulnerability assessment on a computer network, comprising:

sending a plurality of IP addresses to a network scanning process;

assigning a first group of IP addresses from the plurality of IP addresses to a first subscanning process and assigning a second group of IP addresses from the plurality of IP addresses to a second subscanning process, the first subscanning process scanning the computer network with a first selected sequence of IP addresses from the first group of IP addresses and receiving and storing a first set of responses from the computer network, the second subscanning process scanning the computer network with a second selected sequence of IP addresses from the second group of IP addresses and receiving and storing a second set of responses from the computer network, the first selected sequence of IP addresses and the second selected sequence of IP addresses being applied in parallel; and

providing the first set of responses and the second set of responses as data for performing a vulnerability assessment of the computer network;

the first group of IP addresses applied by the first subscanning process are distributed among at least a first batch of IP addresses and a second batch of IP addresses;

the first batch of IP addresses comprises a first non-ordered sequence of a first portion of the first group of IP addresses and the second batch of IP addresses comprises a second non-ordered sequence of a second portion of the first group of IP addresses;

the second group of IP addresses applied by the second subscanning process are distributed among at least a third batch of IP addresses and a fourth batch of IP addresses; and

the third batch of IP addresses comprises a third non-ordered sequence of a first portion of the second group of IP addresses and the fourth batch of IP addresses comprises a fourth non-ordered sequence of a second portion of the second group of IP addresses.

7. A method of conducting an automated vulnerability assessment on a computer network, comprising:

sending a plurality of IP addresses to a network scanning process;

assigning a first group of IP addresses from the plurality of IP addresses to a first subscanning process and assigning a second group of IP addresses from the plurality of IP addresses to a second subscanning process, the first subscanning process scanning the computer network with a first selected sequence of IP addresses from the first group of IP addresses and receiving and storing a first set of responses from the computer network, the second subscanning process scanning the computer network with a second selected sequence of IP addresses from the second group of IP addresses and receiving and storing a second set of responses from the computer network, the first selected sequence of IP addresses and the second selected sequence of IP addresses being applied in parallel; and

providing the first set of responses and the second set of responses as data for performing a vulnerability assessment of the computer network;

a first non-ordered sequence and a second non-ordered sequence are generated by applying a deterministic shuffling process to the first group of IP addresses; and

a third non-ordered sequence and a fourth non-ordered sequence are generated by applying a deterministic shuffling process to the second group of IP addresses.

8. A computer program product embodied on a tangible computer readable medium, comprising:

computer code for sending a plurality of IP addresses to a network scanning process;

computer code for assigning a first group of IP addresses from the plurality of IP addresses to a first subscanning process and assigning a second group of IP addresses from the plurality of IP addresses to a second subscanning process, the first subscanning process scanning the computer network with a first selected sequence of IP addresses from the first group of IP addresses and receiving and storing a first set of responses from the computer network, the second subscanning process scanning the computer network with a second selected sequence of IP addresses from the second group of IP addresses and receiving and storing a second set of responses from the computer network, the first selected sequence of IP addresses and the second selected sequence of IP addresses being applied in parallel; and

computer code for providing the first set of responses and the second set of responses as data for performing a vulnerability assessment of the computer network;

wherein the computer program product is operable such that:

the first group of IP addresses applied by the first subscanning process are distributed among at least a first batch of IP addresses and a second batch of IP addresses;

the first batch of IP addresses comprises a first non-ordered sequence of a first portion of the first group of IP addresses and the second batch of IP addresses comprises a second non-ordered sequence of a second portion of the first group of IP addresses;

the second group of IP addresses applied by the second subscanning process are distributed among at least a third batch of IP addresses and a fourth batch of IP addresses; and

the third batch of IP addresses comprises a third non-ordered sequence of a first portion of the second group of IP addresses and the fourth batch of IP addresses comprises a fourth non-ordered sequence of a second portion of the second group of IP addresses.

9. The computer program product as defined in claim 8 , wherein:

the first non-ordered sequence and the second non-ordered sequence are generated by applying a deterministic shuffling process to the first group of IP addresses; and

the third non-ordered sequence and the fourth non-ordered sequence are generated by applying a deterministic shuffling process to the second group of IP addresses.

10. The computer program product as defined in claim 8 , wherein an IP address shuffler performs a deterministic shuffling process on a group of IP addresses.

11. The computer program product as defined in claim 10 , wherein the deterministic shuffling process uses a prime number to determine an order of IP addresses in a shuffled IP address array.

12. The computer program product as defined in claim 8 , wherein the network scanning process divides an initial range of IP addresses into a plurality of subranges of IP addresses.

13. The computer program product as defined in claim 12 , wherein each of the subranges of IP addresses include contiguous IP addresses.

14. The computer program product as defined in claim 8 , wherein each subscanning process reports subscanning results to the network scanning process.

15. Apparatus, comprising:

means for sending a plurality of IP addresses to a network scanning process;

means for assigning a first group of IP addresses from the plurality of IP addresses to a first subscanning process and assigning a second group of IP addresses from the plurality of IP addresses to a second subscanning process, the first subscanning process scanning the computer network with a first selected sequence of IP addresses from the first group of IP addresses and receiving and storing a first set of responses from the computer network, the second subscanning process scanning the computer network with a second selected sequence of IP addresses from the second group of IP addresses and receiving and storing a second set of responses from the computer network, the first selected sequence of IP addresses and the second selected sequence of IP addresses being applied in parallel; and

means for providing the first set of responses and the second set of responses as data for performing a vulnerability assessment of the computer network;

wherein the apparatus is operable such that:

the first group of IP addresses applied by the first subscanning process are distributed among at least a first batch of IP addresses and a second batch of IP addresses;

the first batch of IP addresses comprises a first non-ordered sequence of a first portion of the first group of IP addresses and the second batch of IP addresses comprises a second non-ordered sequence of a second portion of the first group of IP addresses;

the second group of IP addresses applied by the second subscanning process are distributed among at least a third batch of IP addresses and a fourth batch of IP addresses; and

the third batch of IP addresses comprises a third non-ordered sequence of a first portion of the second group of IP addresses and the fourth batch of IP addresses comprises a fourth non-ordered sequence of a second portion of the second group of IP addresses.

16. Apparatus as defined in claim 15 , wherein:

the first non-ordered sequence and the second non-ordered sequence are generated by applying a deterministic shuffling process to the first group of IP addresses; and

the third non-ordered sequence and the fourth non-ordered sequence are generated by applying a deterministic shuffling process to the second group of IP addresses.

17. Apparatus as defined in claim 15 , wherein an IP address shuffler performs a deterministic shuffling process on a group of IP addresses.

18. Apparatus as defined in claim 17 , wherein the deterministic shuffling process uses a prime number to determine an order of IP addresses in a shuffled IP address array.

19. Apparatus as defined in claim 15 , wherein the network scanning process divides an initial range of IP addresses into a plurality of subranges of IP addresses.

20. Apparatus as defined in claim 19 , wherein each of the subranges of IP addresses include contiguous IP addresses.

21. A method, comprising:

assigning a first group including one or more IP addresses to a first subscanning process and assigning a second group including one or more IP addresses to a second subscanning process, the first subscanning process scanning the computer network with the one or more IP addresses of the first group and receiving and storing one or more responses from the computer network, the second subscanning process scanning the computer network with the one or more IP addresses of the second group and receiving and storing one or more responses from the computer network, the first subscanning process occurring in parallel with the second subscanning process; and

providing the responses as data for performing a vulnerability assessment of the computer network;

wherein an IP address shuffler performs a deterministic shuffling process on a group of IP addresses.

22. The method as defined in claim 21 , wherein the first group and the second group each includes a single IP address.

23. The method as defined in claim 21 , wherein the first group and the second group each includes a plurality of IP addresses.

Assignments (9)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →