IP Library › Granted Patent US 12,580,942
Granted Patent B2
US 12,580,942 · App. 18/328,013 · Granted Mar 17, 2026

System and method for network penetration testing

Inventor: Christopher Laurence Mrozinski (Annapolis Junction, MD)
Assignee: BOOZ ALLEN HAMILTON, INC.
H04L63/1433H04L63/1408
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,580,942
App. No.
18/328,013
Filed
Jun 2, 2023
Granted
Mar 17, 2026
Kind
B2
Examiner
SU, SARAH
Art Unit
2431
USPC
726/25
Abstract

Embodiments relate to methods and systems for executing methods for penetration testing a network. The method involves receiving a first configuration file including network configuration information pertaining to defining a network, and defining log gathering procedures based on the network configuration information. The method involves locating a second configuration file including security module information pertaining to a security module, and defining a test case based on the security module information, the test case including a test data package. The method involves parsing data from the first and second configuration files to generate a data object. The method involves activating the security module to produce a vulnerability output. The method involves executing within the security module the test data package and the test case to identify a penetration vulnerability associated with the vulnerability output of the network. The method involves outputting the penetration vulnerability of the network.

Claims (64)

1 . A system for network penetration testing, the system comprising:

a processor;

computer memory having instructions stored thereon that when executed will cause the processor to:

receive a first configuration file including network configuration information pertaining to defining a network, and define log gathering procedures based on the network configuration information;

locate a second configuration file including security module information pertaining to a security module, and define a test case based on the security module information, the test case including a test data package;

parse data from the first configuration file and the second configuration file to generate a data object;

associate the security module with the parsed data;

activate the security module to evaluate a security of the network, and produce a vulnerability output;

execute within the security module, based on the data object, the test data package and the test case to identify a penetration vulnerability associated with the vulnerability output of the network; and

output, via a user interface, the penetration vulnerability of the network.

2 . The system of claim 1 , wherein:

the processor includes an authenticator module configured to receive the first configuration file, locate the second configuration file, and parse data from the first configuration file and the second configuration file.

3 . The system of claim 2 , wherein:

the instructions will cause the processor to transmit the data object created by the authenticator module to a database.

4 . The system of claim 3 , comprising:

the database.

5 . The system of claim 1 , wherein:

the processor includes a server module configured to monitor traffic on the network.

6 . The system of claim 1 , wherein:

the processor includes a test runner module configured to execute the test data package and test case.

7 . The system of claim 6 , wherein:

the test runner module is configured to create and execute a communication protocol to establish and maintain a communication with the security module.

8 . The system of claim 1 , wherein:

the processor includes a server module configured to monitor traffic on the network; and

the processor includes a test runner module configured to:

execute the test data package and test case; and

monitor an operational state of the server module.

9 . The system of claim 1 , wherein:

the instructions will cause the processor to configure the output as any one or combination of a hard copy report, a display of a graphical user interface, a signal, or an audio or visual alarm.

10 . The system of claim 9 , wherein:

the processor includes a report generator module configured to generate the output.

11 . The system of claim 1 , wherein:

the instructions will cause the processor to activate more than one security module.

12 . The system of claim 11 , wherein:

the instructions will cause the processor to activate more than one security module in serial manner, a parallel manner, or in any combination thereof.

13 . The system of claim 1 , wherein:

the network is a 5G network.

14 . A method for penetration testing a network, the method comprising:

using a configuration file to treat a security module as an operating module that is external to a system executing the method by defining a data object from the configuration file that associates the security module with parsed data of the configuration file;

activating the security module;

executing, based on the data object, a test data package and a test case to identify a penetration vulnerability of the network.

15 . The method of claim 14 , wherein:

the configuration file includes a first configuration file and a second configuration file.

16 . The method of claim 15 , wherein:

the first configuration file includes information pertaining to defining the network; and

the second configuration file includes information pertaining to the security module.

17 . The method of claim 14 , comprising:

parsing data from the configuration file to generate the data object.

18 . The method of claim 17 , comprising:

revising a command line of the configuration file when the security module is an operating module that has not been activated by the system to facilitate activation of the security module.

19 . The method of claim 14 , wherein:

the network is a 5G network.

20 . A method for penetration testing a network, the method comprising:

receiving a first configuration file including network configuration information pertaining to defining a network, and defining log gathering procedures based on the network configuration information;

locating a second configuration file including security module information pertaining to a security module, and defining a test case based on the security module information, the test case including a test data package;

parsing data from the first configuration file and the second configuration file to generate a data object;

associating the security module with the parsed data;

activating the security module to evaluate a security of the network, and produce a vulnerability output;

executing within the security module, based on the data object, the test data package and the test case to identify a penetration vulnerability associated with the vulnerability output of the network; and

outputting, via a user interface, the penetration vulnerability of the network.

21 . The method of claim 20 , wherein:

identifying the penetration vulnerability of the network involves correlating penetration vulnerability to a network function inside a core network of the network.

22 . The method of claim 20 , wherein:

the network is a 5G network.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 2, 2023
From: MROZINSKI, CHRISTOPHER LAURENCE
To: BOOZ ALLEN HAMILTON INC.
Reel/Frame 063838/0141 →
Continuity (2)
Provisional Application 63357052 · Jun 30, 2022
Related Publication 20240007494A1 · Jan 4, 2024
References Cited (33)
US 8356353B2 · Futoransky et al. · 2013 [cited by applicant]
US 10454966B2 · Gorodissky · 2019 [cited by examiner]
US 10880326B1 · Gofman · 2020 [cited by examiner]
US 11582256B2 · Moskovich · 2023 [cited by examiner]
US 20040260818A1 · Valois · 2004 [cited by examiner]
US 20150237063A1 · Cotton · 2015 [cited by examiner]
US 20180013657A1 · Cantwell · 2018 [cited by examiner]
US 20190182286A1 · Zini · 2019 [cited by examiner]
US 20190245883A1 · Gorodissky · 2019 [cited by examiner]
US 20200265144A1 · Gwilliams · 2020 [cited by applicant]
US 20210144548A1 · Ben Henda · 2021 [cited by examiner]
US 20220377095A1 · Lee · 2022 [cited by examiner]
US 20230229787A1 · Mahdavipour · 2023 [cited by examiner]
CN 102468985B · 2016 [cited by applicant]
CN 110162977A · 2019 [cited by applicant]
CN 110730193A · 2020 [cited by examiner]
CN 112511512A · 2021 [cited by examiner]
CN 112637873A · 2021 [cited by applicant]
CN 113454621A · 2021 [cited by examiner]
CN 114462048A · 2022 [cited by applicant]
CN 114465743A · 2022 [cited by examiner]
CN 116566674A · 2023 [cited by examiner]
CN 117118820A · 2023 [cited by examiner]
CN 117155597A · 2023 [cited by examiner]
CN 117498924A · 2024 [cited by examiner]
CN 117834633A · 2024 [cited by examiner]
CN 118075024A · 2024 [cited by examiner]
WO WO0208853A2 · 2002 [cited by examiner]
WO WO2015139724A1 · 2015 [cited by examiner]
WO WO2022049895A1 · 2022 [cited by examiner]
WO WO2023235408A1 · 2023 [cited by examiner]
International Search Report and Written Opinion of the International Searching Authority (Forms PCT/ISA/220, PCT/ISA/210, and PCT/SA/237) issued on Sep. 11, 2023, by the U.S. Patent & Trademark Office in corresponding I… [cited by applicant]
The extended European Search Report issued on Nov. 3, 2025, by the European Patent Office in corresponding European Application No. 23832113.7. (9 pages). [cited by applicant]