IP Library Granted Patent US 12,095,802
Granted Patent B1
US 12,095,802 · App. 17/845,432 · Granted Sep 17, 2024

Scan engine autoscaling using cluster-based prediction models

Inventors: Luke Matear (Belfast, GB); Stephen Hegarty (Belfast, GB)
Assignee: Rapid7, Inc.
H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,095,802
App. No.
17/845,432
Granted
Sep 17, 2024
Kind
B1
Abstract

Various embodiments include systems and methods to implement predictive scan autoscaling using cluster-based prediction models by a security platform to predict scanning loads associated with computing resources. Predictive scan autoscaling using cluster-based prediction models may improve the security posture of computing resources by improving the speed by which a security platform may scan for threats of a cyberattack. The security platform may predict scanning loads based on data indicative of previous scanning loads over one or more periods of time for clusters of similar client networks, where similarity may be based on a comparison of deployment assets. The security platform may combine predicted scanning loads with requests for scans received from various client networks.

Claims (68)

1. A method comprising:

determining, based on a particular client network, a cluster of client networks, wherein the cluster of client networks is based on one or more similarities among client network asset deployments;

determining, based on the cluster of client networks, a prediction model that indicates a security service load based on a particular time;

determining, based on the prediction model, a first number of compute instances, where the first number of compute instances are usable to perform the security service;

deploying, prior to receiving a request to perform the security service, the first number of compute instances; and

initiating, in response to receiving the request to perform the security service, execution of the security service on the first number of compute instances.

2. The method of claim 1 , further comprising:

determining, based on the request to perform the security service, a second number of compute instances;

scaling up, based on the first number of compute instances being less than the second number of compute instances, from the first number of compute instances to the second number of compute instances; and

initiating the security service on the second number of compute instances.

3. The method of claim 1 , further comprising:

determining, based on the request to perform the security service, a second number of compute instances; and

scaling down, based on the first number of compute instances being greater than the second number of compute instances, from the first number of compute instances to the second number of compute instances.

4. The method of claim 1 , wherein determining the prediction model further comprises:

determining a particular geographic region associated with the computing instance, wherein the particular geographic region is among a plurality of geographic regions; and

determining, based on the particular geographic region and on the cluster of client networks, the prediction model.

5. The method of claim 1 , further comprising:

receiving, prior to the determining the first number of compute instances, snapshot data associated with the cluster of client networks; and

determining, based on the snapshot data, the prediction model.

6. The method of claim 5 , further comprising:

receiving, after the initiating the execution of the security service, additional snapshot data; and

determining, based on the additional snapshot data, an updated prediction model;

wherein the prediction model comprises the updated prediction model.

7. The method of claim 1 , wherein the security service is a scan for cyberattacks on the computing resource.

8. The method of claim 1 , wherein a given compute instance among the first number of compute instances comprises a scan engine configured to perform the scan for cyberattacks, and wherein the scan engine is deployed within a cloud computing environment.

9. A system comprising:

a memory storing executable instructions; and

one or more processors that execute the executable instructions to:

determine, based on a particular client network, a cluster of client networks, wherein the cluster of client networks is based on one or more similarities among client network asset deployments;

determine, based on the cluster of client networks, a prediction model that indicates a security service load based on a particular time;

determine, based on the prediction model, a first number of compute instances, where the first number of compute instances are usable to perform the security service;

deploy, prior to receiving a request to perform the security service, the first number of compute instances; and

initiate, in response to receiving the request to perform the security service, execution of the security service on the first number of compute instances.

10. The system of claim 9 , wherein the one or more processors further execute the executable instructions to:

determine, based on the request to perform the security service, a second number of compute instances;

scale up, based on the first number of compute instances being less than the second number of compute instances, from the first number of compute instances to the second number of compute instances; and

initiate the security service on the second number of compute instances.

11. The system of claim 9 , wherein the one or more processors further execute the executable instructions to:

determine, based on the request to perform the security service, a second number of compute instances; and

scale down, based on the first number of compute instances being greater than the second number of compute instances, from the first number of compute instances to the second number of compute instances.

12. The system of claim 9 , wherein the one or more processors further execute the executable instructions to:

determine a particular geographic region associated with the computing instance, wherein the particular geographic region is among a plurality of geographic regions; and

determine, based on the particular geographic region and on the cluster of client networks, the prediction model.

13. The system of claim 9 , wherein the one or more processors further execute the executable instructions to:

receive, prior to the determining the first number of compute instances, snapshot data associated with the cluster of client networks; and

determine, based on the snapshot data, the prediction model.

14. The system of claim 13 , wherein the one or more processors further execute the executable instructions to:

receive, after the initiating the execution of the security service, additional snapshot data; and

determine, based on the additional snapshot data, an updated prediction model;

wherein the prediction model comprises the updated prediction model.

15. The system of claim 9 , wherein the security service is a scan for cyberattacks on the computing resource.

16. The system of claim 9 , wherein a given compute instance among the first number of compute instances comprises a scan engine configured to perform the scan for cyberattacks, and wherein the scan engine is deployed within a cloud computing environment.

17. One or more non-transitory computer-accessible storage media storing executable instructions that, when executed by one or more processors, cause a computer system to:

determine, based on a particular client network, a cluster of client networks, wherein the cluster of client networks is based on one or more similarities among client network asset deployments;

determine, based on the cluster of client networks, a prediction model that indicates a security service load based on a particular time;

determine, based on the prediction model, a first number of compute instances, where the first number of compute instances are usable to perform the security service;

deploy, prior to receiving a request to perform the security service, the first number of compute instances; and

initiate, in response to receiving the request to perform the security service, execution of the security service on the first number of compute instances.

18. The non-transitory computer-accessible storage media of claim 17 , wherein the one or more processors further execute the executable instructions to:

determine, based on the request to perform the security service, a second number of compute instances;

scale up, based on the first number of compute instances being less than the second number of compute instances, from the first number of compute instances to the second number of compute instances; and

initiate the security service on the second number of compute instances.

19. The non-transitory computer-accessible storage media of claim 17 , wherein the one or more processors further execute the executable instructions to:

determine, based on the request to perform the security service, a second number of compute instances; and

scale down, based on the first number of compute instances being greater than the second number of compute instances, from the first number of compute instances to the second number of compute instances.

20. The non-transitory computer-accessible storage media of claim 17 , wherein the one or more processors further execute the executable instructions to:

determine a particular geographic region associated with the computing instance, wherein the particular geographic region is among a plurality of geographic regions; and

determine, based on the particular geographic region and on the cluster of client networks, the prediction model.

Assignments (2)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 23, 2022
From: MATEAR, LUKE; HEGARTY, STEPHEN
To: RAPID7, INC.
Reel/Frame 060293/0410 →
Cited By (1)
US 12,284,218