IP Library Granted Patent US 8,490,196
Granted Patent B2
US 8,490,196 · App. 12/851,516 · Granted Jul 16, 2013

System and method for extending automated penetration testing to develop an intelligent and cost efficient security strategy

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,490,196
App. No.
12/851,516
Granted
Jul 16, 2013
Kind
B2
Abstract

A system and method for extending automated penetration testing of a target network is provided. The method comprises: computing a scenario, comprises the steps of: translating a workspace having at least one target computer in the target network, to a planning definition language, translating penetration modules available in a penetration testing framework to a planning definition language, and defining a goal in the target network and translating the goal into a planning definition language; building a knowledge database with information regarding the target network, properties of hosts in the network, parameters and running history of modules in the penetration testing framework; and running an attack plan solver module, comprising: running an attack planner using the scenario as input, to produce at least one attack plan that achieves the goal, and executing actions defined in the at least one attack plan against the target network from the penetration testing framework.

Claims (36)

1. A method for extending automated penetration testing of a target network comprising, the steps of:

a. computing a scenario, wherein the step of computing the scenario comprises the steps of

i. translating a workspace having at least one target computer in the target network, to a planning definition language;

ii. translating penetration modules available in a penetration testing framework to the planning definition language; and

iii. defining a goal in the target network and translating the goal into the planning definition language;

b. building a knowledge database with information regarding the target network, properties of hosts in the network, parameters and running history of modules in the penetration testing framework; and

c. running an attack plan solver module, wherein the attack plan solver module performs the steps of:

i. running an attack planner using the scenario as input, to produce at least one attack plan that achieves the goal; and

ii. executing actions defined in the at least one attack plan against the target network from the penetration testing framework.

2. The method of claim 1 wherein, prior to running the attack plan solver module, a pre-planner processor module is run using the scenario as input to produce a new scenario, wherein the pre-planner processor module parses the scenario to remove actions that cannot be executed against the hosts described in the scenario.

3. The method of claim 1 wherein, prior to running the attack plan solver module, a pre-planner processor module is run using the scenario as input to produce a new scenario, wherein the pre-planner processor module parses the scenario to combine into a single asset all those assets that can be targeted by the same actions and pose the same preconditions for these actions.

4. The method of claim 1 wherein, prior to running the attack plan solver module, a pre-planner processor module is run using the scenario as input to produce a new scenario, wherein the pre-planner processor module parses the scenario to combine into a single action all those actions that can be used to compromise a previously specified asset.

5. The method of claim 1 wherein the attack planner is selected from the group consisting of a proactive planner, a reactive planner, and a custom planner.

6. The method of claim 1 , where the attack planner solver module, after computing the attack plan, executes a post-planner processor module, wherein the post-planner processor module runs an iterative process comprising the steps of:

i. executing the first action in the plan;

ii. monitoring the result of the first action in the workspace to ascertain if the effect predicted by the attack plan was successful; and

iii. in case the action failed, modifying the scenario to produce a modified scenario, and calling the attack planner to re-calculate a modified plan with the modified scenario.

7. The method of claim 1 wherein an end user defines the goal to be achieved by the system.

8. The method of claim 1 , wherein the actions defined in the attack plans by the attack plan solver module are run in parallel when the preconditions for these actions are satisfied and as limited by the penetration testing framework.

9. The method of claim 1 , wherein the attack plan solver module updates the knowledge base after each action is executed.

10. The method of claim 1 , wherein the planning definition language is a planning domain definition language.

11. The method of claim 1 wherein the attack plan softer module comprises a pre-planner processor module that uses information available in the knowledge database and the scenario, which is in the planning definition language, to modify the scenario.

12. The method of claim 11 wherein the attack plan solver module further comprises a planner processor module and a post-planner processor module, the method further comprising:

sending the modified scenario from the pre-planner processor module to the planner processor module,

computing a single plan at the planner processor module, and

calling from the post-planner processor module a plan translator and executing each step of the single plan using the penetration testing framework.

13. The method of claim 11 wherein the attack plan solver module further comprises a planner processor module and a post-planner processor module, the method further comprising:

sending the modified scenario from the pre-planner processor module to the planner processor module;

computing different plans at the planner processor module; and

executing the different plans in parallel using the penetration testing framework until the goal is reached by one of the plans.

14. The method of claim 11 wherein the attack plan solver module further comprises a planner processor module and a post-planner processor module, the method further comprising:

sending the modified scenario from the pre-planner processor module to the planner processor module;

computing a first plan with the planner processor module;

forwarding the first plan to the post-planner processor module, which starts executing each step of the first plan by calling a plan translator to translate the first plan into commands of the penetration testing framework; and

monitoring with the planner processor module when new information is updated in the scenario.

15. The method of claim 1 wherein the computed scenario is in the planning definition language and wherein running the attack planner using the scenario as input comprises using the computed scenario in the planning definition language to produce at least one attack plan that achieves the goal.

Assignments (20)
SECURITY INTEREST Recorded Jan 6, 2026
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.
To: ACQUIOM AGENCY SERVICES LLC, AS COLLATERAL AGENT
Reel/Frame 074233/0632 →
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 51059/0861 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: FORTRA, LLC (FORMERLY KNOWN AS HELP/SYSTEMS, LLC)
Reel/Frame 073783/0406 →
EXTENDED FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: FORTRA, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0914 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 51059/0911 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERV ICES LLC
To: FORTRA, LLC (F/K/A HELP/SYSTEMS, LLC)
Reel/Frame 073662/0442 →
EXTENDED RCF FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: FORTRA, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 073663/0327 →
NEW MONEY FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 21, 2025
From: ALERT LOGIC, INC.; DIGITAL GUARDIAN LLC; ECRIME MANAGEMENT STRATEGIES, INC.; FORTRA, LLC; GLOBALSCAPE, INC.; TRIPWIRE, INC.; VERA SECURITY, INC.
To: ARES CAPITAL CORPORATION, AS COLLATERAL AGENT
Reel/Frame 073683/0534 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
RELEASE OF SECURITY INTEREST Recorded Feb 3, 2025
From: PNC BANK. NATIONAL ASSOCIATION
To: COURION CORPORATION; CORE SECURITY TECHNOLOGIES, INC.; CORE SDI, INC.; COURIONLIVE CORPORATION; COURION HOLDINGS, INC.; COURION INTERMEDIATE HOLDINGS, INC.
Reel/Frame 070086/0008 →
CHANGE OF NAME Recorded Dec 15, 2022
From: HELP/SYSTEMS, LLC
To: FORTRA, LLC
Reel/Frame 062136/0777 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 20, 2021
From: JEFFERIES FINANCE LLC, AS EXISTING AGENT
To: GOLUB CAPITAL MARKETS LLC, AS SUCCESSOR AGENT
Reel/Frame 056322/0628 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 19, 2019
From: HELP/SYSTEMS, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 051059/0911 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 19, 2019
From: HELP/SYSTEMS, LLC
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 051059/0861 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 24, 2019
From: CORE SECURITY TECHNOLOGIES, INC.
To: HELP/SYSTEMS, LLC
Reel/Frame 048981/0868 →
RELEASE OF SECURITY INTEREST Recorded Feb 8, 2019
From: PNC BANK, NATIONAL ASSOCIATION
To: COURION INTERMEDIATE HOLDINGS, INC.; CORE SECURITY SDI CORPORATION; CORE SECURITY TECHNOLOGIES, INC.; CORE SDI, INC.; CORE SECURITY LIVE CORPORATION; CORE SECURITY HOLDINGS, INC.; DAMABLLA, INC.
Reel/Frame 048281/0835 →
RELEASE OF SECURITY INTEREST Recorded Jan 4, 2018
From: SARATOGA INVESTMENT CORP. SBIC LP
To: COURION CORPORATION; CORE SDI, INC.; CORE SECURITY TECHNOLOGIES, INC.
Reel/Frame 044535/0830 →
PATENT SECURITY AGREEMENT Recorded Oct 10, 2016
From: COURION CORPORATION; CORE SECURITY TECHNOLOGIES, INC.; CORE SDI, INC.
To: SARATOGA INVESTMENT CORP. SBIC LP, AS ADMINISTRATIVE AGENT
Reel/Frame 040298/0816 →
SECURITY INTEREST Recorded Dec 29, 2015
From: COURION CORPORATION; CORE SECURITY TECHNOLOGIES, INC.; CORE SDI, INC.; COURIONLIVE CORPORATION; COURION HOLDINGS, INC.; COURION INTERMEDIATE HOLDINGS, INC.
To: PNC BANK, NATIONAL ASSOCIATION
Reel/Frame 037374/0301 →
RELEASE OF SECURITY INTEREST Recorded Dec 29, 2015
From: MULTIPLIER CAPITAL, L.P.
To: CORE SECURITY TECHNOLOGIES, INC.; CORE SDI, INC.
Reel/Frame 037372/0488 →
SECURITY AGREEMENT Recorded Aug 23, 2013
From: CORE SDI, INC.; CORE SECURITY TECHNOLOGIES, INC.
To: MULTIPLIER CAPITAL, LP
Reel/Frame 031077/0477 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 22, 2010
From: OBES, JORGE LUCANGELI; YAMADA, CARLOS EMILIO SARRAUTE; RICHARTE, GERARDO GABRIEL
To: CORE SECURITY TECHNOLOGIES
Reel/Frame 025179/0916 →