IP Library Granted Patent US 10,437,620
Granted Patent B2
US 10,437,620 · App. 13/218,606 · Granted Oct 8, 2019

Pinned vulnerability scanner for scanning virtual machines on a single machine

Inventors: Richard D. Li (Somerville, MA); Jeffrey L. Berger (Belmont, MA); Anastasios Giakouminakis (Allendale, NJ)
Assignee: RAPID7, INC.
G06F9/45558G06F2009/45587H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,437,620
App. No.
13/218,606
Granted
Oct 8, 2019
Kind
B2
Abstract

Embodiments described herein relate to systems and methods for identifying virtual machines in a network. The systems and methods comprise a virtual asset tool that can interface with a virtualization manager to receive metadata identifying virtual machines hosted by a plurality of physical machines. The virtual asset tool can subscribe to updates associated with the virtual machines, such as changes to the virtual machines, or additions or deletions of virtual machines. In response to receiving an update, the virtual asset tool can modify an asset record associated with the virtual machines and any corresponding descriptions. In embodiments, the virtual asset tool can schedule vulnerability scans for any or all of the virtual machines.

Claims (74)

1. A computer-implemented method of discovering virtual assets and physical devices that host the virtual assets, comprising:

communicating, by a processor, with a virtualization manager to identify a plurality of virtual machines hosted by a plurality of physical machines executing on a network;

receiving, from the virtualization manager, metadata associated with the plurality of virtual machines;

receiving an update to the metadata associated with the plurality of virtual machines, wherein

the update to the metadata corresponds to changes to the plurality of virtual machines, and

the changes to the plurality of virtual machines comprise an addition of one or more new virtual machines to the plurality of virtual machines;

pinning a vulnerability scanner for scanning at least one virtual machine to a single physical machine hosting the at least one virtual machine, wherein

the pinning the vulnerability scanner causes the vulnerability scanner to be confined to the single physical machine and

scan only one or more virtual machines hosted by the single physical machine, and

avoid having to create and send data packets via the network to the at least one virtual machine that is to be scanned;

determining a process for scanning for vulnerabilities in the plurality of virtual machines based on the update to the metadata; and

scanning, utilizing the process and the vulnerability scanner, the at least one virtual machine for vulnerabilities.

2. The computer-implemented method of claim 1 , further comprising: subscribing with the virtualization manager to receive the updates to the metadata.

3. The computer-implemented method of claim 1 , further comprising: polling the virtualization manager for the updates to the metadata.

4. The computer-implemented method of claim 1 , further comprising: storing the metadata about the virtual machines in an asset record.

5. The computer-implemented method of claim 1 , wherein

the metadata associated with the plurality of virtual machines comprises at least one of an identification of a hypervisor associated with the plurality of virtual machines, a unique identifier of each of the plurality of virtual machines, and an identification of the single physical machine hosting each of the plurality of virtual machines.

6. The computer-implemented method of claim 1 , wherein

the virtualization manager is one of a software application or an application programming interface (API).

7. The computer-implemented method of claim 1 , further comprising: creating a subgroup of the virtual machines based on a common property in the metadata.

8. The computer-implemented method of claim 1 , further comprising: performing an action to reflect the update to the metadata.

9. The computer-implemented method of claim 1 , wherein

the process comprises scanning the plurality of virtual machines based on the plurality of physical machines hosting each of the plurality of virtual machines.

10. A system for discovering virtual assets and physical devices that host the virtual assets, comprising:

a processor; and

a computer readable storage medium coupled to the processor and comprising instructions for configuring the processor to:

communicate, by a processor, with a virtualization manager to identify a plurality of virtual machines hosted by a plurality of physical machines executing on a network;

receive, from the virtualization manager, metadata associated with the plurality of virtual machines;

receive an update to the metadata associated with the plurality of virtual machines, wherein

the update to the metadata corresponds to changes to the plurality of virtual machines, and

the changes to the plurality of virtual machines comprise an addition of one or more new virtual machines to the plurality of virtual machines;

pin a vulnerability scanner for scanning at least one virtual machine to a single physical machine hosting the at least one virtual machine, wherein

the pinning the vulnerability scanner causes the vulnerability scanner to be confined to the single physical machine and

scan only one or more virtual machines hosted by the single physical machine, and

avoid having to create and send data packets via the network to the at least one virtual machine that is to be scanned;

determine a process for scanning for vulnerabilities in the plurality of virtual machines based on the update to the metadata; and

scan, utilizing the process and the vulnerability scanner, the at least one virtual machine for vulnerabilities.

11. The system of clam 10 , wherein

the processor further performs: subscribing with the virtualization manager to receive the updates to the metadata.

12. The system of clam 10 , wherein

the processor further performs: polling the virtualization manager for the updates to the metadata.

13. The system of claim 10 , wherein

the processor further performs: storing the metadata about the virtual machines in an asset record.

14. The system of claim 10 , wherein

the metadata associated with the plurality of virtual machines comprises at least one of an identification of a hypervisor associated with the plurality of virtual machines, a unique identifier of each of the plurality of virtual machines, and an identification of the plurality of physical machines hosting each of the plurality of virtual machines.

15. The system of claim 10 , wherein

the virtualization manager is one of a software application or an application programming interface (API).

16. The system of claim 10 , wherein

the processor further performs: creating a subgroup of the virtual machines based on a common property in the metadata.

17. The system of claim 10 , wherein

the process comprises scanning the plurality of virtual machines based on the plurality of physical machines hosting each of the plurality of virtual machines.

18. A system for discovering assets for vulnerability scanning, comprising:

a processor; and

a non-transitory computer readable storage medium coupled to the processor and comprising instructions for causing the processor:

communicate with a virtualization manager to identify a group of virtual machines hosted by a plurality of physical machines executing on a network;

receive, from the virtualization manager, metadata about the virtual machines;

receive an update to the metadata about the virtual machines, wherein

the update to the metadata corresponds to changes to the virtual machines, and

the changes to the virtual machines comprise at least one of changes in the virtual machines and an addition of new virtual machines to the group of virtual machines;

pin a vulnerability scanner for scanning at least one virtual machine to a single physical machine hosting the at least one virtual machine, wherein

pinning the vulnerability scanner causes the vulnerability scanner to be confined to the single physical machine and scan only one or more virtual machines hosted by the single physical machine, and

avoid having to create and send data packets via the network to the at least one virtual machine that is to be scanned;

determine a process for scanning for vulnerabilities in the virtual machines based on the update to the metadata; and

scan, utilizing the process and the vulnerability scanner, the at least one of the virtual machines for vulnerabilities.

19. The system of claim 18 , wherein the processor further performs:

subscribing to the updates provided by the virtualization manager.

20. The system of claim 18 , wherein

the metadata associated with the plurality of virtual machines comprises at least one of an identification of a hypervisor associated with the plurality of virtual machines, a unique identifier of each of the plurality of virtual machines, and an identification of the plurality of physical machines hosting each of the plurality of virtual machines.

21. The system of claim 18 , wherein

the virtualization manager is one of a software application or an application programming interface (API).

22. The system of claim 18 , wherein

the processor further performs: creating a subgroup of the virtual machines based on a common property in the identifications.

23. The system of claim 18 , wherein

the process comprises scanning the plurality of virtual machines based on the plurality of physical machines hosting each of the plurality of virtual machines.

Assignments (7)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
RELEASE OF SECURITY INTEREST Recorded Dec 27, 2024
From: KEYBANK NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
To: RAPID7 LLC
Reel/Frame 069686/0652 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 24, 2020
From: RAPID7 LLC
To: KEYBANK NATIONAL ASSOCIATION
Reel/Frame 052487/0013 →
FULL RELEASE OF SECURITY INTEREST IN PATENTS Recorded Dec 8, 2015
From: SILICON VALLEY BANK
To: RAPID7 LLC
Reel/Frame 037233/0889 →
SECURITY AGREEMENT Recorded Dec 30, 2013
From: RAPID7 LLC
To: SILICON VALLEY BANK
Reel/Frame 031872/0199 →
SECURITY AGREEMENT Recorded Dec 27, 2013
From: RAPID7 LLC
To: SILICON VALLEY BANK
Reel/Frame 031870/0367 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 26, 2011
From: LI, RICHARD D; BERGER, JEFFREY L; GIAKOUMINAKIS, ANASTASIOS
To: RAPID7, LLC
Reel/Frame 026813/0468 →
Continuity (1)
Related Publication 20130055246A1 · Feb 28, 2013
Cited By (1)
US 12,481,566