IP Library Granted Patent US 11,709,945
Granted Patent B2
US 11,709,945 · App. 17/503,853 · Granted Jul 25, 2023

System and method for identifying network security threats and assessing network security

Inventors: Marcus J. Carey (Austin, TX); Tolulope Oyeniyi (Austin, TX)
Assignee: RELIAQUEST HOLDINGS, LLC
G06F21/577G06F21/50G06F21/53G06F21/55G06F21/562H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,709,945
App. No.
17/503,853
Granted
Jul 25, 2023
Kind
B2
Abstract

A system and method of security assessment of a network is described. The system may include one or more security assessment computers controlled by a security assessor, and connected to a network, and first executable program code for acting as an agent on a first end device on the network. The first executable program code is configured to be executed by a browser application of the first end device, and is configured to collect software information, hardware information, and/or vulnerability information of the first end device and transmit the same to a first security assessment computer of the one or more security assessment computers. The information may be transmitted as part of a domain name server (DNS) request. The DNS request may include information identifying the first end device to thus allow modification of the first end device in response to analysis of the collected information.

Claims (37)

1. A security assessment system for a computer network, comprising:

one or more security assessment computers controlled by a security assessor, and connected to a network; and

first executable program code for acting as an agent on a first end device on the network, the first executable program code configured to be executed by a browser application of the first end device,

wherein the first executable program code is configured to obtain information about the first end device; and

wherein the first executable program code is configured to be automatically deleted from the first end device in response to one or more of: passage of an expiration date, the browser application exiting a webpage, a browser window associated with the browser application being closed, and the browser application being closed.

2. The security assessment system according to claim 1 , wherein the first executable program code is configured to receive instructions from the security assessor for performing a simulation session.

3. The security assessment system according to claim 2 , wherein the instructions for performing the simulation session include one or more of an indication of operations to perform, an indication of target destinations, an indication of information to be to be retrieved, an indication of information to be distributed, and an indication of timing for the simulation session.

4. The security assessment system according to claim 1 , wherein the information about the first end device includes one or more of information about software installed on the first end device, information about hardware of the first end device, and information about detected vulnerabilities of the first end device.

5. The security assessment system according to claim 1 , wherein the first executable program code is further configured to transmit identifying information about the first end device.

6. The security assessment system according to claim 1 , further comprising:

second executable program code for acting as an agent on the first end device, the second executable program code configured to be executed by the browser application of the first end device;

wherein the second executable program code is selected based on a vulnerability detected in connection with execution of the first executable program code.

7. The security assessment system according to claim 6 , wherein the second executable program code is configured to simulate a network attack on the first end device.

8. A computer program product residing on a non-transitory computer readable medium having a plurality of instructions stored thereon, which, when executed by a processor, cause the processor to perform operations comprising:

receiving, by a first end device on a network, first executable program code for acting as an agent on the first end device, the first executable program code configured to be executed by a browser application of the first end device,

wherein the first executable program code is configured to obtain information about the first end device; and

wherein the first executable program code is configured to be automatically deleted from the first end device in response to one or more of: passage of an expiration date, the browser application exiting a webpage, a browser window associated with the browser application being closed, and the browser application being closed.

9. The computer program product according to claim 8 , wherein the first executable program code is configured to receive instructions from a security assessor for performing a simulation session.

10. The computer program product according to claim 9 , wherein the instructions for performing the simulation session include one or more of an indication of operations to perform, an indication of target destinations, an indication of information to be to be retrieved, an indication of information to be distributed, and an indication of timing for the simulation session.

11. The computer program product according to claim 8 , wherein the information about the first end device includes one or more of information about software installed on the first end device, information about hardware of the first end device, and information about detected vulnerabilities of the first end device.

12. The computer program product according to claim 9 , wherein the first executable program code is further configured to transmit identifying information about the first end device.

13. The computer program product according to claim 8 , further comprising:

receiving second executable program code for acting as an agent on the first end device, the second executable program code configured to be executed by the browser application of the first end device;

wherein the second executable program code is selected based on a vulnerability detected in connection with execution of the first executable program code.

14. The computer program product according to claim 13 , wherein the second executable program code is configured to simulate a network attack on the first end device.

15. A computer-implemented method comprising:

receiving, by a first end device on a network, first executable program code for acting as an agent on the first end device, the first executable program code configured to be executed by a browser application of the first end device,

wherein the first executable program code is configured to obtain information about the first end device; and

wherein the first executable program code is configured to be automatically deleted from the first end device in response to one or more of: passage of an expiration date, the browser application exiting a webpage, a browser window associated with the browser application being closed, and the browser application being closed.

16. The computer-implemented method according to claim 15 , wherein the first executable program code is configured to receive instructions from a security assessor for performing a simulation session.

17. The computer-implemented method according to claim 16 , wherein the instructions for performing the simulation session include one or more of an indication of operations to perform, an indication of target destinations, an indication of information to be to be retrieved, an indication of information to be distributed, and an indication of timing for the simulation session.

18. The computer-implemented method according to claim 13 , wherein the information about the first end device includes one or more of information about software installed on the first end device, information about hardware of the first end device, and information about detected vulnerabilities of the first end device.

19. The computer-implemented method according to claim 15 , wherein the first executable program code is further configured to transmit identifying information about the first end device.

20. The computer-implemented method according to claim 15 , further comprising:

receiving second executable program code for acting as an agent on the first end device, the second executable program code configured to be executed by the browser application of the first end device;

wherein the second executable program code is selected based on a vulnerability detected in connection with execution of the first executable program code; and

wherein the second executable program code is configured to simulate a network attack on the first end device.

Assignments (2)
SECURITY INTEREST Recorded Apr 30, 2024
From: RELIAQUEST HOLDINGS, LLC
To: GOLUB CAPITAL LLC, AS COLLATERAL AGENT
Reel/Frame 067274/0381 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 18, 2021
From: VTHREAT, INC.
To: RELIAQUEST HOLDINGS, LLC
Reel/Frame 057821/0861 →
Continuity (4)
Continuation 16550723 · Aug 26, 2019
Continuation 15653293 · Jul 18, 2017
Provisional Application 62363537 · Jul 18, 2016
Related Publication 20220035930A1 · Feb 3, 2022
Cited By (1)
US 12,363,003