IP Library Granted Patent US 8,938,531
Granted Patent B1
US 8,938,531 · App. 13/026,668 · Granted Jan 20, 2015

Apparatus, system and method for multi-context event streaming network vulnerability scanner

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,938,531
App. No.
13/026,668
Granted
Jan 20, 2015
Kind
B1
Abstract

An apparatus, systems, and methods for multi-context event streaming network vulnerability scanners. A method is disclosed for scanning a network by executing a first test program, receiving data from one or more devices on a network in response to the data sent by the first test program, determining one or more context findings from the first test program, and reporting the one or more context findings from the first test program to the scanner engine while the first test program is executing.

Claims (74)

1. A method for scanning a network comprising:

providing a network scanner having computer memory and a network interface for sending and receiving data over a computer network;

receiving in the computer memory a scanner engine, where the scanner engine is configured to initiate a plurality of test programs;

executing the scanner engine in the network scanner;

receiving in the computer memory a first test program;

executing the first test program in response to a first command from the scanner engine, where the first test program sends one or more queries using the network interface to one or more devices on the network, where the one or more devices on the network do not contain code or debug operators provided by the network scanner;

receiving data using the network interface from the one or more devices on the network in response to the one or more queries sent by the first test program;

determining one or more context findings from the first test program based on the data received from the one or more devices on the network in response to the one or more queries sent by the first test program;

reporting the one or more context findings from the first test program to the scanner engine while the first test program is executing;

receiving in the computer memory a second test program; and

executing the second test program in response to a second command from the scanner engine, where the second command from the scanner engine is created in response to the one or more context findings from the first test program and where the execution of the second test program causes the network scanner to send one or more queries to the one or more devices on the network while the first test program is executing.

2. The method of claim 1 , further comprising:

receiving data using the network interface from the one or more devices on the network in response to the one or more queries sent by the second test program;

determining one or more context findings from the second test program based on the data received from the one or more devices on the network in response to the one or more queries sent by the second test program; and

reporting the one or more context findings from the second test program to the scanner engine while the second test program is executing.

3. The method of claim 2 , further comprising:

receiving in the computer memory a third test program; and

executing the third test program in response to a third command from the scanner engine, where the third command from the scanner engine is created in response to the one or more context findings from the first test program and the one or more context findings from the second test program, and where the execution of the third test program causes the network scanner to send one or more queries to one or more devices on the network.

4. The method of claim 1 , further comprising:

modifying the one or more queries sent by the second test program in response to the one or more context findings from the first test program.

5. The method of claim 1 , further comprising:

initiating a network scan on the network scanner from a network security operations center, where the network scan includes executing at least the first test program.

6. The method of claim 5 , further comprising:

sending one or more of the context findings determined from a test program to the network security operations center; and

storing the one or more context findings in a database accessible by the network security operations center.

7. The method of claim 6 , further comprising:

sending a scanner release from the network security operations center to the network scanner via the interne, where the scanner release includes at least the first test program.

8. The method of claim 7 , where the scanner release is tailored for the network on which the first test program is executed in response to information known about the network.

9. The method of claim 1 , where the first test program has ordering instructions that specify the order in which the first test program attempts to determine context findings.

10. The method of claim 9 , further comprising:

receiving in the first test program from the scanner engine optional ordering instructions that alter the order in which the first test program attempts to determine context findings.

11. A tangible non-transitory computer-readable medium comprising computer-readable code that, when executed by a computer, causes the computer to perform operations comprising:

providing a network scanner having computer memory and a network interface for sending and receiving data over a computer network;

receiving in the computer memory a scanner engine, where the scanner engine is configured to initiate a plurality of test programs;

executing the scanner engine in the network scanner;

receiving in the computer memory a first test program;

executing the first test program in response to a first command from the scanner engine, where the first test program sends one or more queries using the network interface to one or more devices on the network, where the one or more devices on the network do not contain code or debug operators provided by the network scanner;

receiving data using the network interface from the one or more devices on the network in response to the one or more queries sent by the first test program;

determining one or more context findings from the first test program based on the data received from the one or more devices on the network in response to the one or more queries sent by the first test program;

reporting the one or more context findings from the first test program to the scanner engine while the first test program is executing;

receiving in the computer memory a second test program; and

executing the second test program in response to a second command from the scanner engine, where the second command from the scanner engine is created in response to the one or more context findings from the first test program and where the execution of the second test program causes the network scanner to send one or more queries to the one or more devices on the network while the first test program is executing.

12. The tangible non-transitory computer-readable medium of claim 11 , further comprising computer-readable code that, when executed by a computer, causes the computer to perform operations comprising:

receiving data using the network interface from the one or more devices on the network in response to the one or more queries sent by the second test program;

determining one or more context findings from the second test program based on the data received from the one or more devices on the network in response to the one or more queries sent by the second test program; and

reporting the one or more context findings from the second test program to the scanner engine while the second test program is executing.

13. The tangible non-transitory computer-readable medium of claim 12 , further comprising computer-readable code that, when executed by a computer, causes the computer to perform operations comprising:

receiving in the computer memory a third test program; and

executing the third test program in response to a third command from the scanner engine, where the third command from the scanner engine is created in response to the one or more context findings from the first test program and the one or more context findings from the second test program, and where the execution of the third test program causes the network scanner to send one or more queries to the one or more devices on the network.

14. The tangible non-transitory computer-readable medium of claim 11 , further comprising computer-readable code that, when executed by a computer, causes the computer to perform operations comprising:

modifying the one or more queries sent by the second test program in response to the one or more context findings from the first test program.

15. The tangible non-transitory computer-readable medium of claim 11 , further comprising computer-readable code that, when executed by a computer, causes the computer to perform operations comprising:

initiating a network scan on the network scanner from a network security operations center, where the network scan includes executing at least the first test program.

16. The tangible non-transitory computer-readable medium of claim 15 , further comprising computer-readable code that, when executed by a computer, causes the computer to perform operations comprising:

sending one or more of the context findings determined from a test program to the network security operations center; and

storing the one or more context findings in a database accessible by the network security operations center.

17. The tangible non-transitory computer-readable medium of claim 16 , further comprising computer-readable code that, when executed by a computer, causes the computer to perform operations comprising:

sending a scanner release from the network security operations center to the network scanner via the interne, where the scanner release includes at least the first test program.

18. The tangible non-transitory computer-readable medium of claim 17 , where the scanner release is tailored for the network on which the first test program is executed in response to information known about the network.

19. The tangible non-transitory computer-readable medium of claim 11 , where the first test program has ordering instructions that specify the order in which the first test program attempts to determine context findings.

20. The tangible non-transitory computer-readable medium of claim 19 , further comprising computer-readable code that, when executed by a computer, causes the computer to perform operations comprising:

receiving in the first test program from the scanner engine optional ordering instructions that alter the order in which the first test program attempts to determine context findings.

21. A method of making a tangible computer-readable medium, the method comprising:

recording the computer readable medium with computer readable code that, when executed by a computer, causes the computer to perform operations comprising:

providing a network scanner having computer memory and a network interface for sending and receiving data over a computer network;

receiving in the computer memory a scanner engine, where the scanner engine is configured to initiate a plurality of test programs;

executing the scanner engine in the network scanner;

receiving in the computer memory a first test program;

executing the first test program in response to a first command from the scanner engine, where the first test program sends one or more queries using the network interface to one or more devices on the network, where the one or more devices on the network do not contain code or debug operators provided by the network scanner;

receiving data using the network interface from the one or more devices on the network in response to the one or more queries sent by the first test program;

determining one or more context findings from the first test program based on the data received from the one or more devices on the network in response to the one or more queries sent by the first test program;

reporting the one or more context findings from the first test program to the scanner engine while the first test program is executing;

receiving in the computer memory a second test program; and

executing the second test program in response to a second command from the scanner engine, where the second command from the scanner engine is created in response to the one or more context findings from the first test program and where the execution of the second test program causes the network scanner to send one or more queries to the one or more devices on the network while the first test program is executing.

Assignments (7)
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 56229/0029 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: DIGITAL DEFENSE, INC.
Reel/Frame 073781/0173 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 56229/0076 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERVICES LLC
To: DIGITAL DEFENSE, INC.
Reel/Frame 073658/0891 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 20, 2021
From: JEFFERIES FINANCE LLC, AS EXISTING AGENT
To: GOLUB CAPITAL MARKETS LLC, AS SUCCESSOR AGENT
Reel/Frame 056322/0628 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 13, 2021
From: DIGITAL DEFENSE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 056229/0076 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 13, 2021
From: DIGITAL DEFENSE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 056229/0029 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 26, 2011
From: COTTON, MIKE; MACKAY, GORDON; SHILLING, BRANDON
To: DIGITAL DEFENSE INCORPORATED
Reel/Frame 026180/0337 →