IP Library Granted Patent US 12,323,466
Granted Patent B1
US 12,323,466 · App. 17/808,079 · Granted Jun 3, 2025

Policy exceptions for assessment of network system assets

Inventors: Paul Miseiko (Mississauga, CA); Leonardo Varela (Austin, TX)
Assignee: Rapid7, Inc.
H04L63/20H04L63/166G06F21/568G06F21/577H04L63/1408H04L63/1416H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,323,466
App. No.
17/808,079
Granted
Jun 3, 2025
Kind
B1
Abstract

A method for authenticated asset assessment is provided. The method involves executing a scan assistant on an asset to allow a remote scan engine to execute one or more scan operations on the asset for determining a state of the asset. The scan assistant may verify the identity of the scan engine by checking that a certificate received from the scan engine is signed with a private key associated with the scan engine. In some embodiments, the authentication may be performed as part of a TLS handshake process that establishes a TLS connection between the scan engine and the scan assistant. Once the scan engine is authenticated, the scan engine may communicate with the scan assistant according to a communication protocol to collect data about the asset. Advantageously, the disclosed technique reduces security risks associated with authenticated scans and improves the performance of authenticated scans.

Claims (46)

1. A method comprising:

performing, by an asset comprising at least one computing resource in a network:

deploying a scan assistant on the asset, wherein the scan assistant is associated with a scan engine outside the network configured to perform scans of the asset to collect information about the asset, and the asset is subject to one or more policy benchmarks of the network that prevents scans of the asset from outside the network;

executing the scan assistant on the asset to perform a scan of the asset, including:

authenticating the scan engine based on a scan engine certificate obtained from the scan engine;

after authenticating the scan engine, establishing a connection with the scan engine;

receiving a request to perform a scan of the asset from the scan engine over the connections wherein the scan includes one or more scan operations that uses an administrative credential of the asset; and

executing the scan on the asset, wherein the execution bypasses the one or more policy benchmarks so that the one or more scan operations are performed to bypass requiring a remote authentication of the administrative credential and to bypass the need for applying a policy exception to the one or more policy benchmarks.

2. The method of claim 1 , further comprising the scan assistant performing a two-way certificate authentication with the scan engine prior to establishing the connection.

3. The method of claim 1 , wherein the connection is established by the scan assistant sending a request for connection to the scan engine.

4. The method of claim 1 , wherein the scan engine is implemented in a platform-as-a-service provider network accessible to the network via Internet.

5. The method of claim 1 , wherein:

the connection is a transport layer security (TLS) connection; and

the one or more scan operations are received according to a communication protocol implemented by the scan assistant and the scan engine; and

the method further comprises the scan assistant sending scan results of the scan back to the scan engine over the connection and according to the communication protocol.

6. The method of claim 1 , wherein the one or more policy benchmarks prohibits remote access to one or more services running the asset.

7. The method of claim 1 , wherein the one or more policy benchmarks are implemented by a gateway of the network and the execution of the scan assistant includes instructing the gateway to bypass the one or more security benchmarks for a duration of the one or more scan operations.

8. The method of claim 1 , wherein the one or more policy benchmarks restricts permissions of remote connections to the asset, and the restriction prevents the one or more scan operations from executing.

9. The method of claim 1 , wherein the one or more scan operations comprise at least one of a command or a script executable on the asset.

10. A system comprising:

one or more computing devices that implement an asset in a network, configured to:

deploy a scan assistant on the asset, wherein the scan assistant is associated with a scan engine outside the network configured to perform scans of the asset to collect information about the asset, and the asset is subject to one or more policy benchmarks of the network that prevents scans of the asset from outside the network;

execute the scan assistant on the asset to perform a scan of the asset, including to:

authenticate the scan engine based on a scan engine certificate obtained from the scan engine;

after the scan engine is authenticated, establish a connection with the scan engine;

receive a request to perform a scan of the asset from the scan engine over the connections wherein the scan includes one or more scan operations that uses an administrative credential of the asset; and

execute the scan on the asset, wherein the execution bypasses the one or more policy benchmarks so that the one or more scan operations are performed to bypass requiring a remote authentication of the administrative credential and to bypass the need for applying a policy exception to the one or more policy benchmarks.

11. The system of claim 10 , wherein the scan assistant is configured to perform a two-way certificate authentication with the scan engine prior to establishing the connection.

12. The system of claim 10 , wherein the scan assistant is configured to send a request for connection to the scan engine to establish the connection.

13. The system of claim 10 , wherein the scan engine is implemented in a platform-as-a-service provider network accessible to the network via Internet.

14. The system of claim 10 , wherein:

the connection is a transport layer security (TLS) connection; and

the one or more scan operations are received according to a communication protocol implemented by the scan assistant and the scan engine; and

the scan assistant is configured to send scan results of the scan back to the scan engine over the connection and according to the communication protocol.

15. The system of claim 10 , wherein the one or more policy benchmarks prohibits remote access to one or more services running the asset.

16. The system of claim 10 , wherein the one or more policy benchmarks are implemented by a gateway of the network and the execution of the scan assistant includes to instruct the gateway to bypass the one or more security benchmarks for a duration of the one or more scan operations.

17. The system of claim 10 , wherein the one or more policy benchmarks restricts permissions of remote connections to the asset, and the restriction prevents the one or more scan operations from executing.

18. One or more non-transitory computer readable media storing program instructions that when executed on one or more processors implement an asset in a network and cause the asset to:

deploy a scan assistant on the asset, wherein the scan assistant is associated with a scan engine outside the network configured to perform scans of the asset to collect information about the asset, and the asset is subject to one or more policy benchmarks of the network that prevents scans of the asset from outside the network;

execute the scan assistant on the asset to perform a scan of the asset, including to:

authenticate the scan engine based on a scan engine certificate obtained from the scan engine;

after the scan engine is authenticated, establish a connection with the scan engine;

receive a request to perform a scan of the asset from the scan engine over the connection, wherein the scan includes one or more scan operations that uses an administrative credential of the asset; and

execute the scan on the asset, wherein the execution bypasses the one or more policy benchmarks so that the one or more scan operations are performed to bypass requiring a remote authentication of the administrative credential and to bypass the need for applying a policy exception to the one or more policy benchmarks.

19. The one or more non-transitory computer readable media of claim 18 , wherein the program instructions when executed on one or more processors causes the scan assistant to perform a two-way certificate authentication with the scan engine prior to establishing the connection.

20. The one or more non-transitory computer readable media of claim 18 , wherein the program instructions when executed on one or more processors causes the scan assistant to send scan results of the scan back to the scan engine over the connection.

Assignments (2)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 22, 2022
From: MISEIKO, PAUL; VARELA, LEONARDO
To: RAPID7, INC.
Reel/Frame 060276/0136 →
References Cited (11)
US 7609650B2 · Roskowski et al. · 2009 [cited by applicant]
US 7926113B1 · Gula · 2011 [cited by examiner]
US 8955038B2 · Nicodemus et al. · 2015 [cited by applicant]
US 9503472B2 · Laidlaw et al. · 2016 [cited by applicant]
US 9634951B1 · Hunt et al. · 2017 [cited by applicant]
US 9954883B2 · Ahuja · 2018 [cited by examiner]
US 11216553B1 · Cancilla · 2022 [cited by examiner]
US 20140013436A1 · Deraison · 2014 [cited by examiner]
US 20160044057A1 · Chenette et al. · 2016 [cited by applicant]
“How to Create an OS-Based Policy Scanning Workflow in Insight VM”—Landon Dalke, Rapid 7, Dec. 4, 2020 https://www.rapid7.com/blog/post/2020/12/04/how-to-create-an-os-based-policy-scanning-workflow-in-insightvm/ (Year: … [cited by examiner]
“Bypass Vulnerability Management Scan Traffic in Deep Security”—Deep Security Help Center, Trend Micro, Aug. 25, 2020 https://help.deepsecurity.trendmicro.com/10_1/aws/vulnerability-traffic-bypass.html (Year: 2020). [cited by examiner]
Cited By (4)
US 12,495,032 US 12,562,966 US 12,563,029 US 12,719,850