IP Library Granted Patent US 11,102,222
Granted Patent B1
US 11,102,222 · App. 16/443,194 · Granted Aug 24, 2021

Multi-stage network scanning

Inventors: Roy Hodgman (Cambridge, MA); Jonathan Hart (Kernville, CA)
Assignee: Rapid7, Inc.
H04L63/1416H04L63/1425H04L69/16H04W8/005H04L67/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,102,222
App. No.
16/443,194
Granted
Aug 24, 2021
Kind
B1
Abstract

Methods and systems for scanning a network. The disclosed methods may involve receiving a list of a plurality of target devices and scanning a first device to determine if a particular port and protocol combination appears to be open on the first device. Upon determining that a particular port and protocol combination appears to be open on the first device, the method involves interrogating the first device before or during scanning of a second device to gather data regarding a service running on the first device.

Claims (26)

1. A method for scanning a network, the method comprising:

receiving a list of a plurality of target devices, wherein the list includes at least a first device and a second device;

scanning the first device to determine if a particular port and protocol combination appears to be open on the first device;

storing target devices with the open port and protocol combinations in the queueing service; and

upon determining that the particular port and protocol combination appears to be open on the first device, interrogating the first device before or during scanning of the second device to gather data regarding a service running on the first device;

wherein the interrogated device is an HTTP server, and the method further comprises organizing data from the interrogation into objects representing HTTP responses.

2. The method of claim 1 wherein the interrogation comprises connecting to the first device using transmission control protocol (TCP) or user datagram protocol (UDP).

3. The method of claim 1 further comprising receiving metadata specifying port and protocol combinations for scanning.

4. The method of claim 1 wherein the list of the plurality of target devices includes devices that specifically have not opted out from being scanned.

5. The method of claim 1 further comprising processing an opt-out request from a target.

6. The method of claim 1 wherein the list of the plurality of target devices includes at least one of an IP address and a host name for each of the plurality of target devices.

7. The method of claim 1 wherein interrogating the first device comprises interrogating the first device from a plurality of interrogation locations.

8. The method of claim 1 wherein scanning the first device involves scanning the first device from a plurality of locations.

9. A system for scanning a network, the system comprising:

an interface for at least receiving a list of a plurality of target devices, wherein the list includes at least a first device and a second device;

a scanning module configured to scan the first device to determine if a particular port and protocol combination appears to be open on the first device;

a queueing service to store target devices with the open port and protocol combinations; and

a first collection device configured to, upon the scanning module determining that the particular port and protocol combination appears to be open on the first device, interrogate the first device before or during scanning of the second device to gather data regarding a service running on the first device;

wherein the interrogated device is an HTTP server, and the system further includes a processing module configured to organize data from the interrogation into objects representing HTTP responses.

10. The system of claim 9 wherein the interrogation involves connecting to the first device using transmission control protocol (TCP) or user datagram protocol (UDP).

11. The system of claim 9 wherein the scanning module is further configured to receive metadata specifying port and protocol combinations for scanning.

12. The system of claim 9 wherein the list of the plurality of target devices includes devices that specifically have not opted out from being scanned.

13. The system of claim 9 wherein the interface is further configured to process an opt-out request from a target.

14. The system of claim 9 wherein the list of the plurality of target devices includes at least one of an IP address and a host name for each of the plurality of target devices.

15. The system of claim 9 further comprising a second collection device configured to interrogate the first device from a different location than the first collection device to observe trends from differing collection points.

16. The system of claim 9 wherein the first device is scanned from a plurality of locations.

Assignments (5)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
RELEASE OF SECURITY INTEREST Recorded Dec 27, 2024
From: KEYBANK NATIONAL ASSOCIATION, AS ADMINISTRATIVE AGENT
To: RAPID7, INC.
Reel/Frame 069785/0328 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 14, 2020
From: HART, JEFFRY
To: RAPID7, INC.
Reel/Frame 053764/0446 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Apr 24, 2020
From: RAPID7, INC.
To: KEYBANK NATIONAL ASSOCIATION
Reel/Frame 052489/0939 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 12, 2019
From: HODGMAN, ROY
To: RAPID7, INC.
Reel/Frame 051260/0432 →