IP Library Granted Patent US 10,425,430
Granted Patent B2
US 10,425,430 · App. 15/136,620 · Granted Sep 24, 2019

Hierarchical scanning of internet connected assets

Inventors: Connor Leete Gilbert (San Francisco, CA); Michael Haggblade (San Bruno, CA)
Assignee: Expanse, Inc.
H04L63/1416H04L63/0236H04L63/0245H04L63/0428H04L63/1433H04L63/20H04L63/205H04L69/169
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,425,430
App. No.
15/136,620
Granted
Sep 24, 2019
Kind
B2
Abstract

A system for hierarchical scanning includes an interface and a processor. The interface is to receive an indication to scan using a payload; provide the payload to a set of addresses on a set of ports; and receive a set of responses. Each response is associated with an address and a port. The processor is to: for each response of the set of responses: determine whether a follow-up probe exists associated with the response; and in the event the follow-up probe exists associated with the response: execute the follow-up probe on the address and the port associated with the response; and store the set of data received in response to the follow-up probe in a database.

Claims (44)

1. A system for hierarchical scanning to identify security vulnerabilities, comprising:

an interface configured to scan a set of addresses on a set of ports using a payload, and receive a set of responses, wherein each response is associated with an address and a port; and

a processor configured to:

determine that a follow-up probe exists associated with a first response of the set of responses, wherein the first response indicates a universal plug and play (UPnP) configuration file; and

execute the follow-up probe on the address and the port associated with the first response, wherein the follow-up probe includes programmed steps:

retrieve the UPnP configuration file, the UPnP configuration file indicating presence of hardware, presence of software, or a combination thereof;

request additional information on the hardware, the software, or a combination thereof;

store a set of data received in response to the follow-up probe in a database; and

determine an appropriate action to restore security based on the set of data.

2. The system of claim 1 , wherein the interface is further to receive an indication of a set of addresses to scan.

3. The system of claim 2 , wherein the set of addresses comprises all addresses of a network.

4. The system of claim 1 , wherein the interface is further to receive an indication of a set of ports to scan.

5. The system of claim 4 , wherein the set of ports to scan comprises all ports.

6. The system of claim 1 , wherein the addresses comprise IPv4 addresses.

7. The system of claim 1 , wherein the addresses comprise IPv6 addresses.

8. The system of claim 1 , wherein the payload comprises a SYN packet.

9. The system of claim 1 , wherein the payload is provided using a TCP protocol.

10. The system of claim 1 , wherein the payload is provided using a UDP protocol.

11. The system of claim 1 , wherein the follow-up probe comprises a follow-up collecting probe for collecting UPNP information, NetBIOS information, or DNS information.

12. The system of claim 1 , wherein the follow-up probe comprises a follow-up unencrypted probe for establishing an unencrypted connection.

13. The system of claim 12 , wherein the unencrypted connection comprises an HTTP connection, a FTP connection, a Modbus connection, a SMTP connection, or a Telnet connection.

14. The system of claim 1 , wherein the follow-up probe comprises a follow-up encrypted probe for establishing the encrypted connection.

15. The system of claim 14 , wherein the encrypted connection comprises an HTTPS connection, a FTPS connection, a SFTP connection, a SSH connection, or a SMTPS connection.

16. The system of claim 14 , wherein establishing the encrypted connection comprises receiving a certificate.

17. The system of claim 1 , wherein the follow-up probe comprises a follow-up ipv4 probe for determining IPv4 addresses to scan.

18. The system of claim 1 , wherein the database is used to determine one or more network devices with a known vulnerability.

19. A method for hierarchical scanning to identify security vulnerabilities, comprising:

scanning a set of addresses on a set of ports using a payload;

receiving a set of responses, wherein each response is associated with an address and a port;

determining, using a processor, that a follow-up probe is associated with a first response, wherein the first response indicates a universal plug and play (UPnP) configuration file;

executing the follow-up probe on the address and the port associated with the first response, wherein the follow-up probe includes programmed steps:

retrieving the UPnP configuration file, the UPnP configuration file indicating presence of hardware, presence of software, or a combination thereof;

requesting additional information on the hardware, the software, or a combination thereof;

storing a set of data received in response to the follow-up probe in a database; and

determining an appropriate action to restore security based on the set of data.

20. A computer program product for hierarchical scanning to identify security vulnerabilities, the computer program product being embodied in a non-transitory computer readable storage medium and comprising computer instructions for:

scanning a set of addresses on a set of ports using a payload;

receiving a set of responses, wherein each response is associated with an address and a port;

determining, using a processor, that a follow-up probe is associated with a first response, wherein the first response indicates a universal plug and play (UPnP) configuration file; and

executing the follow-up probe on the address and the port associated with the first response, wherein the follow-up probe includes programmed steps:

retrieving the UPnP configuration file, the UPnP configuration file indicating presence of hardware, presence of software, or a combination thereof;

requesting additional information on the hardware, the software, or a combination thereof;

storing a set of data received in response to the follow-up probe in a database; and

determining an appropriate action to restore security based on the set of data.

Assignments (4)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 28, 2021
From: EXPANSE, LLC
To: PALO ALTO NETWORKS, INC.
Reel/Frame 056379/0222 →
CHANGE OF NAME Recorded May 24, 2021
From: EXPANSE, INC.
To: EXPANSE, LLC.
Reel/Frame 056355/0769 →
CHANGE OF NAME Recorded May 29, 2019
From: QADIUM, INC.
To: EXPANSE, INC.
Reel/Frame 049314/0179 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 16, 2016
From: GILBERT, CONNOR LEETE; HAGGBLADE, MICHAEL
To: QADIUM, INC.
Reel/Frame 039454/0580 →
Continuity (1)
Related Publication 20170310699A1 · Oct 26, 2017