IP Library Granted Patent US 12,634,319
Granted Patent B2
US 12,634,319 · App. 18/883,288 · Granted May 19, 2026

Using cached network data on a device to discover unscannable devices

Inventors: Emmett Kelly (Belfast, GB); Ross Kirk (Belfast, GB)
Assignee: Rapid7, Inc.
H04L63/1425G06F9/547H04L63/02H04W64/00
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,634,319
App. No.
18/883,288
Granted
May 19, 2026
Kind
B2
Abstract

A software agent executing on a computing device receives a request from a client to provide data associated with neighboring devices to the computing device. The client includes a scan engine to perform a network scan of a network that includes the computing device. The software agent accesses device data in a cache of an operating system command, determines, based on the device data, an identifier associated with each device that is neighboring the computing device, converts the device data into a standardized format to create neighboring device data, and sends the neighboring device data to the client.

Claims (48)

1 . A method comprising:

executing a software agent on a computing device in a network, the execution comprising:

receiving a request from a scan engine to provide data associated with the computing device;

accessing an Address Resolution Protocol (ARP) cache or a Neighbor Discovery Protocol (NDP) cache maintained on the computing device to obtain a list of neighboring devices of the computing device in the network, wherein the scan engine is not able to directly scan a neighboring device in the list; and

sending, by the software agent, device data about the neighboring device to the scan engine.

2 . The method of claim 1 , further comprising the software agent:

converting the device data into a standardized format that is a same format for a plurality of different operating systems.

3 . The method of claim 1 , wherein

the device data includes an internet protocol (IP) address and a media access control (MAC) address of the neighboring device.

4 . The method of claim 1 , wherein

the computing device implements an application programming interface (API) endpoint for a remote procedure call (RPC) from the scan engine, and the request is received at the API endpoint.

5 . The method of claim 1 , wherein

the neighboring device implements a firewall that is configured to (a) not respond to network scans from the scan engine or (b) prevent the network scans from reaching one or more other computing devices in the network.

6 . The method of claim 1 , wherein

the computing device is a virtual machine.

7 . The method of claim 1 , wherein

the network is a wide area network (WAN).

8 . The method of claim 1 , wherein

the software agent is configured to collect fingerprints of software on the computing device according to instructions from the scan engine.

9 . The method of claim 1 , wherein

the software agent is configured to receive an operating system script from the scan engine and execute the script on the computing device.

10 . The method of claim 1 , wherein

the software agent is executed in one process on the computing device, and

the software agent is configured to invoke another process on the computing device to collect the device data.

11 . A system comprising:

a computer device configured to execute a software agent, the software agent executable to:

receive a request from a scan engine to provide data associated with the computing device;

access an Address Resolution Protocol (ARP) cache or a Neighbor Discovery Protocol (NDP) cache maintained on the computing device to obtain a list of neighboring devices of the computing device in the network, wherein the scan engine is not able to directly scan a neighboring device in the list; and

send, by the software agent, device data about the neighboring device to the scan engine.

12 . The system of claim 11 , wherein the software agent is executable to:

convert the device data into a standardized format that is a same format for a plurality of different operating systems.

13 . The system of claim 11 , wherein

the device data includes an internet protocol (IP) address and a media access control (MAC) address of the neighboring device.

14 . The system of claim 11 , wherein

the computing device implements an application programming interface (API) endpoint for a remote procedure call (RPC) from the scan engine, and

the request is received at the API endpoint.

15 . The system of claim 11 , wherein

the neighboring device implements a firewall that is configured to (a) not respond to network scans from the scan engine or (b) prevent the network scans from reaching one or more other computing devices in the network.

16 . The system of claim 11 , wherein

the computing device is a virtual machine.

17 . The system of claim 11 , wherein

the network is a wide area network (WAN).

18 . The system of claim 11 , wherein

the software agent is executable to receive a software patch from the scan engine.

19 . The system of claim 11 , wherein

the software agent is executable to receive an operating system script from the scan engine and execute the script on the computing device.

20 . The system of claim 11 , wherein

the software agent is executed in one process on the computing device, and the software agent is executable to invoke another process on the computing device to collect the device data.

Assignments (2)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 17, 2024
From: KELLY, EMMETT; KIRK, ROSS
To: RAPID7, INC.
Reel/Frame 068612/0334 →
Continuity (2)
Continuation 17682262 · Feb 28, 2022
Related Publication 20250007939A1 · Jan 2, 2025
References Cited (13)
US 6647412B1 · Strandberg · 2003 [cited by examiner]
US 11032124B1 · Haddow et al. · 2021 [cited by applicant]
US 11089490B1 · Ta et al. · 2021 [cited by applicant]
US 11533335B2 · Hale · 2022 [cited by examiner]
US 20060271934A1 · Ezaki · 2006 [cited by applicant]
US 20080304427A1 · Biswas · 2008 [cited by examiner]
US 20090325569A1 · Chou · 2009 [cited by applicant]
US 20110009135A1 · Roskowski et al. · 2011 [cited by applicant]
US 20130148573A1 · Boland · 2013 [cited by examiner]
US 20170187574A1 · Subramanian et al. · 2017 [cited by applicant]
US 20190261191A1 · Nakano et al. · 2019 [cited by applicant]
US 20230032366A1 · Lee et al. · 2023 [cited by applicant]
Tundis, Andrea, Wojciech Mazurczyk, and Max Mühlhäuser. “A review of network vulnerabilities scanning tools: Types, capabilities and functioning.” Proceedings of the 13th international conference on availability, reliab… [cited by examiner]