IP Library Granted Patent US 12,238,133
Granted Patent B1
US 12,238,133 · App. 17/845,418 · Granted Feb 25, 2025

Predictive scan engine autoscaling

Inventors: Luke Matear (Belfast, GB); Stephen Hegarty (Belfast, GB)
Assignee: Rapid7, Inc.
H04L63/1433H04L63/107H04L63/1416
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,238,133
App. No.
17/845,418
Granted
Feb 25, 2025
Kind
B1
Abstract

Various embodiments include systems and methods to implement predictive scan autoscaling by a security platform to predict scanning loads associated with computing resources. Predictive scan autoscaling may improve the security posture of computing resources by improving the speed by which a security platform may scan for threats of a cyberattack. The security platform may predict scanning loads based on data indicative of previous scanning loads over one or more periods of time. The security platform may combine predicted scanning loads with requests for scans received from various client networks.

Claims (60)

1. A method comprising:

determining, based on a prediction model associated with a computing resource, a prediction of a request load of a security service, wherein the prediction is used to determine a first number of compute instances usable to perform the security service associated with the computing resource;

deploying, based on the first number of compute instances and prior to receiving a request to initiate the security service, a second number of compute instances, wherein the second number of compute instances is within a threshold number to the first number of compute instances;

receiving the request to perform the security service; and

initiating, in response to receiving the request to perform the security service, execution of the security service on the second number of compute instances;

receiving, prior to the determining the first number of compute instances, snapshot data; and

training, based on the snapshot data, the prediction model.

2. The method of claim 1 , further comprising:

determining, based on the request to perform the security service, a third number of compute instances;

deploying, in response to the receiving the request to perform the security service, the third number of compute instances; and

initiating, in response to the receiving the request to perform the security service, the security service on the third number of compute instances.

3. The method of claim 1 , further comprising:

determining a particular geographic region associated with the computing instance, wherein the particular geographic region is among a plurality of geographic regions; and

determining, based on the particular geographic region, a regional model;

wherein the prediction model comprises the regional model.

4. The method of claim 1 , further comprising:

receiving, after the initiating the execution of the security service, additional snapshot data; and training, based on the additional snapshot data, an updated prediction model;

wherein the prediction model comprises the updated prediction model.

5. The method of claim 1 , wherein the security service is a scan for cyberattacks on the computing resource.

6. The method of claim 5 , wherein a given compute instance among the compute instances comprises a scan engine configured to perform the scan for cyberattacks, and wherein the scan engine is deployed within a cloud computing environment.

7. The method of claim 1 , wherein the threshold number is based on a first amount of computing resources associated with the first number of compute instances being substantially similar to a second amount of computing resources associated with the second number of compute instances.

8. A system comprising:

a memory storing executable instructions; and

one or more processors that execute the executable instructions to:

determine, based on a prediction model associated with a computing resource, a prediction of a request load of a security service, wherein the prediction is used to determine a first number of compute instances usable to perform the security service associated with the computing resource;

deploy, based on the first number of compute instances and prior to receiving a request to initiate the security service, a second number of compute instances, wherein the second number of compute instances is within a threshold number to the first number of compute instances;

receive the request to perform the security service; and

initiate, in response to receiving the request to perform the security service, execution of the security service on the second number of compute instances;

receive, prior to the determining the first number of compute instances, snapshot data; and

train, based on the snapshot data, the prediction model.

9. The system of claim 8 , wherein the one or more processors further execute the executable instructions to:

determine, based on the request to perform the security service, a third number of compute instances;

deploy, in response to the receiving the request to perform the security service, the third number of compute instances; and

initiate, in response to the receiving the request to perform the security service, the security service on the third number of compute instances.

10. The system of claim 8 , wherein the one or more processors further execute the executable instructions to:

determine a particular geographic region associated with the computing instance, wherein the particular geographic region is among a plurality of geographic regions; and

determine, based on the particular geographic region, a regional model;

wherein the prediction model comprises the regional model.

11. The system of claim 8 , wherein the one or more processors further execute the executable instructions to:

receive, after the initiating the execution of the security service, additional snapshot data; and

train, based on the additional snapshot data, an updated prediction model;

wherein the prediction model comprises the updated prediction model.

12. The system of claim 8 , wherein the security service is a scan for cyberattacks on the computing resource.

13. The system of claim 8 , wherein a given compute instance among the compute instances comprises a scan engine configured to perform the scan for cyberattacks, and wherein the scan engine is deployed within a cloud computing environment.

14. The system of claim 8 , wherein the threshold number is based on a first amount of computing resources associated with the first number of compute instances being substantially similar to a second amount of computing resources associated with the second number of compute instances.

15. One or more non-transitory computer-accessible storage media storing executable instructions that, when executed by one or more processors, cause a computer system to:

determine, based on a prediction model associated with a computing resource, a prediction of a request load of a security service, wherein the prediction is used to determine a first number of compute instances usable to perform the security service associated with the computing resource;

deploy, based on the first number of compute instances and prior to receiving a request to initiate the security service, a second number of compute instances, wherein the second number of compute instances is within a threshold number to the first number of compute instances;

receive the request to perform the security service; and

initiate, in response to receiving the request to perform the security service, execution of the security service on the second number of compute instances;

receive, prior to the determining the first number of compute instances, snapshot data; and

train, based on the snapshot data, the prediction model.

16. The non-transitory computer-accessible storage media of claim 15 , wherein the one or more processors further execute the executable instructions to:

determine, based on the request to perform the security service, a third number of compute instances;

deploy, in response to the receiving the request to perform the security service, the third number of compute instances; and

initiate, in response to the receiving the request to perform the security service, the security service on the third number of compute instances.

17. The non-transitory computer-accessible storage media of claim 15 , wherein the one or more processors further execute the executable instructions to:

determine a particular geographic region associated with the computing instance, wherein the particular geographic region is among a plurality of geographic regions; and

determine, based on the particular geographic region, a regional model;

wherein the prediction model comprises the regional model.

Assignments (2)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 23, 2022
From: MATEAR, LUKE; HEGARTY, STEPHEN
To: RAPID7, INC.
Reel/Frame 060293/0410 →
References Cited (10)
US 8127358B1 · Lee · 2012 [cited by applicant]
US 8578499B1 · Zhu et al. · 2013 [cited by applicant]
US 10032032B2 · Suarez et al. · 2018 [cited by applicant]
US 20120216190A1 · Sivak · 2012 [cited by applicant]
US 20170180346A1 · Suarez et al. · 2017 [cited by applicant]
US 20190258807A1 · DiMaggio · 2019 [cited by examiner]
US 20200057857A1 · Roytman · 2020 [cited by examiner]
US 20220215100A1 · Waplington · 2022 [cited by examiner]
US 20230004858A1 · Santhanagopal · 2023 [cited by examiner]
US 20230141928A1 · Sterba · 2023 [cited by examiner]