IP Library Granted Patent US 11,989,309
Granted Patent B2
US 11,989,309 · App. 17/994,458 · Granted May 21, 2024

Software type and version identification for security operations

Inventor: Sheung Hei Joseph Yeung (Toronto, CA)
Assignee: Rapid7, Inc.
G06F21/577G06F8/71G06F9/44505G06F21/51G06F21/552G06F21/554G06F21/566
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,989,309
App. No.
17/994,458
Granted
May 21, 2024
Kind
B2
Abstract

Disclosed herein are methods, systems, and processes to perform passive and realtime software identification and data collection for vulnerability management. Vulnerability management based on agent-collected event data involves monitoring a process start event associated with an application executing on a computing device that is part of a network, identifying a binary location of the process start event, and based on the binary location, identifying a software type of the application and a version of the software type. Vulnerability management based on event data in logs involves monitoring the process start event for configuration or file changes, generating fingerprint rules by mapping the configuration or files changes and the process start event associated with a software installation or an upgrade of the software, and processing log data to fingerprint the software type and the version of the software type. Agent-collected event data and event data in logs can be amalgamated to perform software and version identification for vulnerability management.

Claims (25)

1. A computer-implemented method, comprising:

monitoring a process start event associated with an application for a configuration change or a file change;

generating a fingerprint rule by mapping the configuration change or the file change with a software installation or a software upgrade;

processing log data with the fingerprint rule to fingerprint a software type and a version of the software type;

identifying a vulnerability associated with the software type and the version of the software type;

identifying a binary location of the process start event;

determining the software type and the version of the software type based on the binary location of the process start event;

accessing a record of previously processed binaries;

determining if a binary in the binary location is part of the record; and

inhibiting processing of the binary in the binary location if the binary in the binary location is part of the record.

2. The computer-implemented method of claim 1 , further comprising:

quarantining the application.

3. The computer-implemented method of claim 1 , further comprising:

identifying the software type and the version of the software type based on a frequency of the process start event.

4. A system comprising:

one or more processors; and

a memory coupled to the one or more processors, wherein the memory stores program instructions executable by the one or more processors to:

identify a binary location of a process start event associated with an application;

determine that a binary in the binary location is not part of a record of previously processed binaries;

determine a software type and a version of a software type based on the binary location and a frequency of the process start event;

monitor the process start event for a configuration change or a file change;

generate a fingerprint rule by mapping the configuration change or the file change with a software installation or a software upgrade;

process log data with the fingerprint rule to fingerprint the software type and the version of the software type;

identify a vulnerability associated with the software type and the version of the software type; and

quarantine the application or one of more files associated with the application.

Assignments (2)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 30, 2022
From: YEUNG, SHEUNG HEI JOSEPH
To: RAPID7, INC.
Reel/Frame 062029/0463 →
Continuity (2)
Continuation 16861339 · Apr 29, 2020
Related Publication 20230096024A1 · Mar 30, 2023