IP Library › Granted Patent US 12,153,667
Granted Patent B2
US 12,153,667 · App. 17/127,686 · Granted Nov 26, 2024

Security automation using robotic process automation

Inventor: Alexandru Razvan Caciulescu (Bucharest, RO)
Assignee: UiPath, Inc.
G06F21/552
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,153,667
App. No.
17/127,686
Granted
Nov 26, 2024
Kind
B2
Abstract

Security automation, such as penetration testing or security hardening, is performed using robotic process automation (RPA) by directly connecting one or more robots into an operating system of a platform. The one or more robots execute a workflow to simulate the penetration testing of the operating system to identify malicious activity or vulnerable configurations within the operating system. The one or more robots also generate a report for the user identifying the malicious activity, misconfigurations or vulnerabilities within the environment.

Claims (102)

1. A computer-implemented method for performing penetration testing using robotic process automation (RPA), the method comprising:

directly connecting one or more robots into an operating system of a platform;

determining, by the one or more robots, a type of the operating system based on a port number of the operating system, binary of the operating system, or both;

loading, by the one or more robots, a workflow associated with the operating system based on the type of the operating system;

executing, by the one or more robots, the workflow to simulate the penetration testing of the operating system to identify malicious activity or vulnerable configurations within the operating system; and

generating, by the one or more robots, a report for the user identifying the malicious activity or the vulnerable configurations within the operating system; and

executing a workflow to perform corrective measures based on the generated report.

2. The computer-implemented method of claim 1 , wherein the directly connecting of the one or more robots comprising:

utilizing the one or more robots configured to perform a RPA process, and

reassigning the one or more robots to perform the penetration testing.

3. The computer-implemented method of claim 1 , wherein the directly connecting of the one or more robots comprising:

deploying the one or more robots unassigned to one another RPA process, and

assigning the one or more robots to perform the penetration testing.

4. The computer-implemented method of claim 1 , wherein the executing of the penetration testing comprising:

accessing the workflow specific for the operating system; and

executing the workflow to cause the one or more robots to simulate the penetration testing.

5. The computer-implemented method of claim 1 , wherein the executing of the penetration testing comprising:

recording, by the one or more robots, actions performed by a penetration tester during a penetration test; and

using, by the one or more robots, the recorded actions to create the workflow to simulate the penetration test.

6. The computer-implemented method of claim 1 , wherein the executing of the penetration testing comprising:

scanning, by the one or more robots, ports and services open or available within the OS, and identifying the ports and services with vulnerabilities and weak credential logins.

7. The computer-implemented method of claim 1 , wherein the executing of the penetration testing comprising:

attempting to access, by the one or more robots, one or more user accounts to identify one or more compromised user accounts, wherein

the attempting to access of the one or more user accounts comprises using default login credentials for each the one or more user accounts, and

identifying the one or more comprised user accounts that are granted access during the penetration testing.

8. The computer-implemented method of claim 1 , further comprising:

upon directly connecting with the operating system, determining, by the one or more robots, type of the operating system; and

loading, by the one or more robots, the workflow associated with the type of operating system in order to execute the simulation of the penetration testing.

9. The computer-implemented method of claim 1 , further comprising:

modifying, by a system admin robot, one or more steps in a workflow to create a new workflow for simulating the penetration testing, or

combining, by the system admin robot, two or more workflows to create a new workflow for simulating the penetration testing.

10. The computer-implemented method of claim 1 , further comprising:

receiving, by the system admin robot, the report identifying the malicious activity, misconfigurations or vulnerabilities within the operating system.

11. An apparatus configured to perform penetration testing using robotic processor automation (RPA), the apparatus comprising:

memory comprising a set of instructions; and

at least one processor, wherein

the set of instructions are configured to cause the at least one processor to execute:

directly connecting one or more robots into an operating system of a platform;

determining, by the one or more robots, a type of the operating system based on a port number of the operating system, binary of the operating system, or both;

loading, by the one or more robots, a workflow associated with the operating system based on the type of the operating system;

executing, by the one or more robots, the workflow to simulate the penetration testing of the operating system to identify malicious activity, misconfigurations or vulnerabilities within the operating system;

generating, by the one or more robots, a report for the user identifying the malicious activity, misconfigurations or vulnerabilities within the operating system; and

executing a workflow to perform corrective measures based on the generated report.

12. The apparatus of claim 11 , wherein the set of instructions are further configured to cause the at least one processor to execute:

utilizing the one or more robots configured to perform a RPA process, and

reassigning the one or more robots to perform the penetration testing.

13. The apparatus of claim 11 , wherein the set of instructions are further configured to cause the at least one processor to execute:

deploying the one or more robots unassigned to one another RPA process, and

assigning the one or more robots to perform the penetration testing.

14. The apparatus of claim 11 , wherein the set of instructions are further configured to cause the at least one processor to execute:

accessing the workflow specific for the operating system; and

executing the workflow to cause the one or more robots to simulate the penetration testing.

15. The apparatus of claim 11 , wherein the set of instructions are further configured to cause the at least one processor to execute:

recording, by the one or more robots, actions performed by a penetration tester during a penetration test; and

using, by the one or more robots, the recorded actions to create the workflow to simulate the penetration test.

16. The apparatus of claim 11 , wherein the set of instructions are further configured to cause the at least one processor to execute:

scanning, by the one or more robots, ports and services open or available within the OS, and identifying the ports and services with vulnerabilities and weak credential logins.

17. The apparatus of claim 11 , wherein the set of instructions are further configured to cause the at least one processor to execute:

attempting to access, by the one or more robots, one or more user accounts to identify one or more compromised user accounts, wherein

the attempting to access of the one or more user accounts comprises using default login credentials for each the one or more user accounts, and

identifying the one or more comprised user accounts that are granted access during the penetration testing.

18. The apparatus of claim 11 , the set of instructions are further configured to cause the at least one processor to execute:

upon directly connecting with the operating system, determining, by the one or more robots, type of the operating system; and

loading, by the one or more robots, the workflow associated with the type of operating system in order to execute the simulation of the penetration testing.

19. The apparatus of claim 11 , the set of instructions are further configured to cause the at least one processor to execute:

modifying, by a system admin robot, one or more steps in a workflow to create a new workflow for simulating the penetration testing, or

combining, by the system admin robot, two or more workflows to create a new workflow for simulating the penetration testing.

20. The apparatus of claim 11 , the set of instructions are further configured to cause the at least one processor to execute:

receiving, by the system admin robot, the report identifying the malicious activity, misconfigurations or vulnerabilities within the operating system.

21. A computer program embodied on a non-transitory computer-readable medium, the computer program is configured to cause at least one processor to execute:

directly connecting one or more robots into an operating system of a platform;

determining, by the one or more robots, a type of the operating system based on a port number of the operating system, binary of the operating system, or both;

loading, by the one or more robots, a workflow associated with the operating system based on the type of the operating system;

executing, by the one or more robots, the workflow to simulate the penetration testing of the operating system to identify malicious activity, misconfigurations or vulnerabilities within the operating system;

generating, by the one or more robots, a report for the user identifying the malicious activity, misconfigurations or vulnerabilities within the operating system; and

executing a workflow to perform corrective measures based on the generated report.

22. The computer program of claim 21 , wherein the computer program is further configured to cause at least one processor to execute:

utilizing the one or more robots configured to perform a RPA process, and

reassigning the one or more robots to perform the penetration testing.

23. The computer program of claim 21 , wherein the computer program is further configured to cause at least one processor to execute:

deploying the one or more robots unassigned to one another RPA process, and

assigning the one or more robots to perform the penetration testing.

24. The computer program of claim 21 , wherein the computer program is further configured to cause at least one processor to execute:

accessing the workflow specific for the operating system; and

executing the workflow to cause the one or more robots to simulate the penetration testing.

25. The computer program of claim 21 , wherein the computer program is further configured to cause at least one processor to execute:

recording, by the one or more robots, actions performed by a penetration tester during a penetration test; and

using, by the one or more robots, the recorded actions to create the workflow to simulate the penetration test.

26. The computer program of claim 21 , wherein the computer program is further configured to cause at least one processor to execute:

scanning, by the one or more robots, ports and services open or available within the OS, and identifying the ports and services with vulnerabilities and weak credential logins.

27. The computer program of claim 21 , wherein the computer program is further configured to cause at least one processor to execute:

attempting to access, by the one or more robots, one or more user accounts to identify one or more compromised user accounts, wherein

the attempting to access of the one or more user accounts comprises using default login credentials for each the one or more user accounts, and

identifying the one or more comprised user accounts that are granted access during the penetration testing.

28. The computer program of claim 21 , wherein the computer program is further configured to cause at least one processor to execute:

upon directly connecting with the operating system, determining, by the one or more robots, type of the operating system; and

loading, by the one or more robots, the workflow associated with the type of operating system in order to execute the simulation of the penetration testing.

29. The computer program of claim 21 , wherein the computer program is further configured to cause at least one processor to execute:

modifying, by a system admin robot, one or more steps in a workflow to create a new workflow for simulating the penetration testing, or

combining, by the system admin robot, two or more workflows to create a new workflow for simulating the penetration testing.

30. The computer program of claim 21 , wherein the computer program is further configured to cause at least one processor to execute:

receiving, by the system admin robot, the report identifying the malicious activity, misconfigurations or vulnerabilities within the operating system.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 18, 2020
From: CACIULESCU, ALEXANDRU RAZVAN
To: UIPATH, INC.
Reel/Frame 054699/0361 →
Continuity (1)
Related Publication 20220198002A1 · Jun 23, 2022