IP Library Granted Patent US 10,447,709
Granted Patent B2
US 10,447,709 · App. 12/980,524 · Granted Oct 15, 2019

Methods and systems for integrating reconnaissance with security assessments for computing networks

Inventors: Anastasios Giakouminakis (Allendale, NJ); Chad Loder (Los Angeles, CA); Richard Li (Somerville, MA)
Assignee: Rapid7, Inc.
H04L63/1416G06F21/577H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,447,709
App. No.
12/980,524
Granted
Oct 15, 2019
Kind
B2
Abstract

A reconnaissance and assessment (RA) tool can receive base information about the network, such as basic network information and details about an entity and personnel associated with network. The RA tool can utilize the base information to perform reconnaissance procedures on the network to identify the attack surface of the network. The RA tool can perform reconnaissance on the network, itself, and on other external sources, such as third party databases, search engines, and partner networks. Once the attack surface is identified, the RA tool can automatically perform appropriate security assessments on the attack surface. Additionally, if additional information is determined about the network during the security assessments, the RA tool can perform additional reconnaissance and security assessments based on the additional information.

Claims (29)

1. A computer-implemented method to assess security threats, comprising:

receiving base information for a network that comprises entity information and network information associated with the network;

performing a security reconnaissance process on the network by scanning the network to identify a computing entity that is part of the entity information, and based on the identity of the computing entity, searching the network and an external source in a partner network for a network component that is unrecorded or unidentified in the network information;

determining, based on the security reconnaissance process and the base information indicating that the network component is associated with the computing entity, an attack surface of the network that comprises one or more parts, using a security reconnaissance agent executing in the partner network of the external source;

identifying a part of the one or more parts of the attack surface based on the network information associated with the computing entity and the network component indicating that the part matches a first security threat assessment; and

performing the first security threat assessment by evaluating the part of the attack surface for one or more security vulnerabilities followed by a second security threat assessment on one or more other parts of the attack surface in the partner network of the external source that match the second security threat assessment based on the network information updated with the identity of the network component that was previously unrecorded or unidentified if at least one of the one or more security vulnerabilities are discovered during the first security threat assessment.

2. The computer-implemented method of claim 1 , wherein

the security reconnaissance agent scans the network using Border Gateway Protocol (BGP) maps analysis, traceroutes, web crawling, or wireless access point search, and

the security reconnaissance agent executes on one or more network taps or one or more phishing agents to determine the attack surface.

3. A non-transitory computer readable storage medium comprising program instructions executable to:

receive base information for a network that comprises entity information and network information associated with the network;

perform a security reconnaissance process on the network by scanning the network to identify a computing entity that is part of the entity information, and based on the identity of the computing entity, searching the network and an external source in a partner network for a network component that is unrecorded or unidentified in the network information;

determine, based on the security reconnaissance process and the base information indicating that the network component is associated with the computing entity, an attack surface of the network that comprises one or more parts, using a security reconnaissance agent executing in the partner network of the external source;

identify a part of the one or more parts of the attack surface based on the network information associated with the computing entity and the network component indicating that the part matches a first security threat assessment; and

perform the first security threat assessment by evaluating the part of the attack surface for one or more security vulnerabilities followed by a second security threat assessment on one or more other parts of the attack surface in the partner network of the external source that match the second security threat assessment based on the network information updated with the identity of the network component that was previously unrecorded or unidentified if at least one of the one or more security vulnerabilities are discovered during the first security threat assessment.

4. The non-transitory computer readable storage medium of claim 3 , wherein

the security reconnaissance agent scans the network using Border Gateway Protocol (BGP) maps analysis, traceroutes, web crawling, or wireless access point search, and

the security reconnaissance agent executes on one or more network taps or one or more phishing agents to determine the attack surface.

5. A system to assess security threats comprising:

one or more processors; and

a memory coupled to the one or more processors, wherein the memory stores program instructions executable by the one or more processors to:

receive base information for a network that comprises entity information and network information associated with the network;

perform a security reconnaissance process on the network by scanning the network to identify a computing entity that is part of the entity information, and based on the identity of the computing entity, searching the network and an external source in a partner network for a network component that is unrecorded or unidentified in the network information;

determine, based on the security reconnaissance process and the base information indicating that the network component is associated with the computing entity, an attack surface of the network that comprises one or more parts, using a security reconnaissance agent executing in the partner network of the external source;

identify a part of the one or more parts of the attack surface based on the network information associated with the computing entity and the network component indicating that the part matches a first security threat assessment; and

perform the first security threat assessment by evaluating the part of the attack surface for one or more security vulnerabilities followed by a second security threat assessment on one or more other parts of the attack surface in the partner network of the external source that match the second security threat assessment based on the network information updated with the identity of the network component that was previously unrecorded or unidentified if at least one of the one or more security vulnerabilities are discovered during the first security threat assessment.

6. The system of claim 4 , wherein

the security reconnaissance agent scans the network using Border Gateway Protocol (BGP) maps analysis, traceroutes, web crawling, or wireless access point search, and

the security reconnaissance agent executes on one or more network taps or one or more phishing agents to determine the attack surface.

Assignments (7)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
RELEASE OF SECURITY INTEREST Recorded Dec 27, 2024
From: KEYBANK NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
To: RAPID7 LLC
Reel/Frame 069686/0652 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 24, 2020
From: RAPID7 LLC
To: KEYBANK NATIONAL ASSOCIATION
Reel/Frame 052487/0013 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 25, 2019
From: LI, RICHARD; LODER, CHAD; GIAKOUMINAKIS, ANASTASIOS
To: RAPID7, INC.
Reel/Frame 048419/0897 →
FULL RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 8, 2015
From: SILICON VALLEY BANK
To: RAPID7 LLC
Reel/Frame 037233/0889 →
SECURITY AGREEMENT Recorded Dec 30, 2013
From: RAPID7 LLC
To: SILICON VALLEY BANK
Reel/Frame 031872/0199 →
SECURITY AGREEMENT Recorded Dec 27, 2013
From: RAPID7 LLC
To: SILICON VALLEY BANK
Reel/Frame 031870/0367 →
Cited By (1)
US 12,206,708