IP Library Granted Patent US 8,595,822
Granted Patent B2
US 8,595,822 · App. 13/340,457 · Granted Nov 26, 2013

System and method for cloud based scanning for computer vulnerabilities in a network environment

View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 8,595,822
App. No.
13/340,457
Granted
Nov 26, 2013
Kind
B2
Abstract

A method in one embodiment includes establishing a first secure tunnel between a scanner and a configuration manager, and a second secure tunnel between the scanner and a scan controller, where the scanner is located in a public network and the configuration manager and the scan controller are located in a private network, communicating scanner configuration information between the scanner and the configuration manager over the first secure tunnel, and communicating scan information between the scanner and the scan controller over the second secure tunnel. The secure tunnels may be established from within the private network, by forwarding a first origination port and a second origination port to a first destination port and a second destination port, respectively. The first and second origination ports may be located in the public network, and the first and second destination ports may be located in the private network.

Claims (51)

1. A method comprising:

establishing a first secure tunnel between a configuration manager and a scanner, and a second secure tunnel between a scan controller and the scanner, wherein the scanner is located in a public network and the configuration manager and the scan controller are located in a private network;

communicating scanner configuration information between the scanner and the configuration manager over the first secure tunnel; and

communicating scan information between the scanner and the scan controller over the second secure tunnel.

2. The method of claim 1 , wherein each secure tunnel is a reverse Secure Shell (SSH) tunnel.

3. The method of claim 1 , wherein establishing the first secure tunnel and the second secure tunnel comprises:

identifying a first origination port, a second origination port, a first destination port, and a second destination port, wherein the first origination port and second origination port are coupled to the scanner, the first destination port is coupled to the configuration manager, and second destination port is coupled to the scan controller; and

forwarding, from within the private network, the first origination port to the first destination port to create the first secure tunnel, and the second origination port to the second destination port to create the second secure tunnel.

4. The method of claim 3 , wherein the scanner comprises a first port coupled to the first origination port and a second port coupled to the second origination port.

5. The method of claim 4 , further comprising:

configuring the scanner to communicate scan information through the second port.

6. The method of claim 1 , wherein the scanner comprises:

a scan engine configured to scan one or more assets in the private network based on scan information provided by the scan controller; and

a configuration agent configured to facilitate configuring the scan engine based on scanner configuration information provided by the configuration manager.

7. The method of claim 6 , wherein the scanner further comprises:

an SSH server.

8. The method of claim 1 , wherein the scan controller and the configuration manager communicate with one or more scanners located in the private network.

9. The method of claim 1 , wherein the first and second secure tunnels are the same tunnel.

10. The method of claim 1 , wherein the first secure tunnel is distinct from the second secure tunnel.

11. An apparatus comprising:

a scan engine;

a configuration agent;

a first port;

a second port;

a memory element configured to store data; and

a processor operable to execute instructions associated with the data, wherein the apparatus is configured for:

establishing a first secure tunnel between a configuration manager and the configuration agent, and a second secure tunnel between a scan controller and the scan engine, wherein the apparatus is located in a public network and the configuration manager and the scan controller are located in a private network;

communicating scanner configuration information between the configuration agent and the configuration manager over the first secure tunnel; and

communicating scan information between the scan engine and the scan controller over the second secure tunnel.

12. The apparatus of claim 11 , wherein each secure tunnel is a reverse Secure Shell (SSH) tunnel.

13. The apparatus of claim 11 , wherein the scan engine is configured to scan one or more assets in the private network based on scan information provided by the scan controller, and the configuration agent is configured to facilitate configuring the scan engine based on scanner configuration information provided by the configuration manager.

14. The apparatus of claim 11 , wherein establishing the first secure tunnel and the second secure tunnel comprises:

identifying a first origination port, a second origination port, a first destination port, and a second destination port, wherein the first origination port and second origination port are coupled to the apparatus, the first destination port is coupled to the configuration manager, and second destination port is coupled to the scan controller; and

forwarding, from within the private network, the first origination port to the first destination port to create the first secure tunnel, and the second origination port to the second destination port to create the second secure tunnel.

15. The apparatus of claim 14 , wherein the first port is coupled to the first origination port and the second port is coupled to the second origination port.

16. The apparatus of claim 15 , further configured for:

communicating scan information through the second port.

17. Logic encoded in non-transitory media that includes code for execution and when executed by a processor is operable to perform operations comprising:

establishing a first secure tunnel between a configuration manager and a scanner, and a second secure tunnel between a scan controller and the scanner, wherein the scanner is located in a public network and the configuration manager and the scan controller are located in a private network;

communicating scanner configuration information between the scanner and the configuration manager over the first secure tunnel; and

communicating scan information between the scanner and the scan controller over the second secure tunnel.

18. The logic of claim 17 , wherein each secure tunnel is a reverse Secure Shell (SSH) tunnel.

19. The logic of claim 17 , wherein the scanner comprises:

a scan engine configured to scan one or more assets in the private network based on scan information provided by the scan controller; and

a configuration agent configured to facilitate configuring the scan engine based on scanner configuration information provided by the configuration manager.

20. The logic of claim 17 , wherein establishing the first secure tunnel and the second secure tunnel comprises:

identifying a first origination port, a second origination port, a first destination port, and a second destination port, wherein the first origination port and second origination port are coupled to the scanner, the first destination port is coupled to the configuration manager, and second destination port is coupled to the scan controller; and

forwarding, from within the private network, the first origination port to the first destination port to create the first secure tunnel, and the second origination port to the second destination port to create the second secure tunnel.

21. The logic of claim 20 , wherein the scanner comprises a first port coupled to the first origination port and a second port coupled to the second origination port.

22. The logic of claim 21 , the operations further comprising:

configuring the scanner to communicate scan information through the second port.

Assignments (10)
CORRECTIVE ASSIGNMENT TO CORRECT THE THE PATENT TITLES AND REMOVE DUPLICATES IN THE SCHEDULE PREVIOUSLY RECORDED AT REEL: 059354 FRAME: 0335. ASSIGNOR(S) HEREBY CONFIRMS THE ASSIGNMENT. Recorded Jun 23, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT
Reel/Frame 060792/0307 →
SECURITY INTEREST Recorded Mar 3, 2022
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A., AS ADMINISTRATIVE AGENT AND COLLATERAL AGENT
Reel/Frame 059354/0335 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045056/0676 Recorded Mar 2, 2022
From: MORGAN STANLEY SENIOR FUNDING, INC., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 059354/0213 →
RELEASE OF INTELLECTUAL PROPERTY COLLATERAL - REEL/FRAME 045055/0786 Recorded Oct 26, 2020
From: JPMORGAN CHASE BANK, N.A., AS COLLATERAL AGENT
To: MCAFEE, LLC
Reel/Frame 054238/0001 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045056 FRAME 0676. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 054206/0593 →
CORRECTIVE ASSIGNMENT TO CORRECT THE REMOVE PATENT 6336186 PREVIOUSLY RECORDED ON REEL 045055 FRAME 786. ASSIGNOR(S) HEREBY CONFIRMS THE SECURITY INTEREST. Recorded Oct 22, 2020
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 055854/0047 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: MORGAN STANLEY SENIOR FUNDING, INC.
Reel/Frame 045056/0676 →
SECURITY INTEREST Recorded Jan 12, 2018
From: MCAFEE, LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 045055/0786 →
CHANGE OF NAME AND ENTITY CONVERSION Recorded Aug 24, 2017
From: MCAFEE, INC.
To: MCAFEE, LLC
Reel/Frame 043665/0918 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 29, 2011
From: SCHRECKER, SVEN; ROBISON, BRIAN
To: MCAFEE, INC.
Reel/Frame 027460/0620 →