IP Library Granted Patent US 12,695,782
Granted Patent B2
US 12,695,782 · App. 18/973,140 · Granted Jul 28, 2026

Updating remote scan engines with custom vulnerability checks

Inventor: Jack Steers (Belfast, GB)
Assignee: Rapid7, Inc.
H04L63/1433H04L63/205
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,695,782
App. No.
18/973,140
Filed
Dec 9, 2024
Granted
Jul 28, 2026
Kind
B2
Art Unit
2439
USPC
726/25
Abstract

Various embodiments include systems and methods of implementing vulnerability check synchronization. Vulnerability check synchronization may occur between computing resources at multiple different locations including a first location and a second location. Custom vulnerability check information associated with a particular security vulnerability may be received via a security console user interface that is located at the first location. A selection may be received, via the security console user interface, of a particular distributed engine to be utilized to perform a scan of one or more assets based at least in part on the custom vulnerability check information. Responsive to a determination to initiate the scan of the one or more assets, transfer of the custom vulnerability check information to the particular distributed engine via one or more networks may be automatically initiated.

Claims (74)

1 . A system, comprising:

one or more computer devices that implement a security console, configured to:

receive, via a user interface of the security console, user input specifying a custom vulnerability check to be performed on assets located at a location remote from the security console;

store the custom vulnerability check as a plurality of extensible markup language (XML) files in a local file system of the security console, including:

(a) a vulnerability descriptor file that describes a type of vulnerability to be checked,

(b) a vulnerability check file that specifies instructions for a scan engine to check for the type of vulnerability, and

(c) a vulnerability solution file that specifies one or more remediation actions for the type of vulnerability;

receive, via the user interface, user input to initiate one or more scans of one or more of the assets, wherein the user input includes selection of one or more remote scan engines at the location to perform the one or more scans;

in response to a determination that a first remote scan engine is enabled for custom vulnerability checks:

transfer the XML files to the first remote scan engine;

cause the first remote scan engine to load the XML files; and

cause the first remote scan engine to perform a scan of a first asset with the custom vulnerability check; and

in response to a determination that a second remote scan engine is disabled for custom vulnerability checks:

refrain from transferring the XML files to the second remote scan engine; and

cause the second remote scan engine to perform a scan of a second asset without the custom vulnerability check.

2 . The system of claim 1 , wherein the vulnerability descriptor file includes information about the type of vulnerability, including two or more of:

a title or name of the vulnerability,

a description of the vulnerability, and

a severity of the vulnerability.

3 . The system of claim 2 , wherein the vulnerability descriptor file includes:

a Common Vulnerabilities and Exposure (CVE) identifier of the vulnerability, and

a Common Vulnerability Scoring System (CVSS) score of the vulnerability.

4 . The system of claim 1 , wherein the vulnerability check file specifies multiple tests to be performed during scans to check for the vulnerability.

5 . The system of claim 4 , wherein the vulnerability check file specifies:

a type of network service or network protocol to be tested,

a port number to be tested,

a scan request to use for a test, and

a scan response expression to match a response obtained for the test.

6 . The system of claim 4 , wherein the vulnerability check file specifies a particular test to check an operating system or one or more files of a particular asset for a software vulnerability.

7 . The system of claim 1 , wherein the vulnerability solution file includes a plurality of remediation actions that are common to different types of vulnerabilities.

8 . The system of claim 7 , wherein the security console is configured to:

display, via the user interface, one or more of the remediation steps in response to a determination that the type of vulnerability is detected on a particular asset.

9 . The system of claim 1 , wherein the security console is configured to:

send scan instructions to the one or more remote scan engine over Internet; and

receive scan results from the one or more remote scan engine over Internet.

10 . The system of claim 9 , wherein the security console is configured to:

display the scan results via the user interface.

11 . A method comprising:

executing a security console implemented by one or more computer devices, the execution comprising:

receiving, via a user interface of the security console, user input specifying a custom vulnerability check to be performed on assets located at a location remote from the security console;

storing the custom vulnerability check as a plurality of extensible markup language (XML) files in a local file system of the security console, including:

(a) a vulnerability descriptor file that describes a type of vulnerability to be checked,

(b) a vulnerability check file that specifies instructions for a scan engine to check for the type of vulnerability, and

(c) a vulnerability solution file that specifies one or more remediation actions for the type of vulnerability;

receiving, via the user interface, user input to initiate one or more scans of one or more of the assets, wherein the user input includes selection of one or more remote scan engines at the location to perform the one or more scans;

in response to a determination that a first remote scan engine is enabled for custom vulnerability checks:

transferring the XML files to the first remote scan engine;

causing the first remote scan engine to load the XML files; and

causing the first remote scan engine to perform a scan of a first asset with the custom vulnerability check; and

in response to a determination that a second remote scan engine is disabled for custom vulnerability checks:

refraining from transferring the XML files to the second remote scan engine; and

causing the second remote scan engine to perform a scan of a second asset without the custom vulnerability check.

12 . The method of claim 11 , wherein the vulnerability descriptor file includes information about the type of vulnerability, including two or more of:

a title or name of the vulnerability,

a description of the vulnerability, and

a severity of the vulnerability.

13 . The method of claim 12 , wherein the vulnerability descriptor file includes:

a Common Vulnerabilities and Exposure (CVE) identifier of the vulnerability, and

a Common Vulnerability Scoring System (CVSS) score of the vulnerability.

14 . The method of claim 11 , wherein the vulnerability check file specifies multiple tests to be performed during scans to check for the vulnerability.

15 . The method of claim 14 , wherein the vulnerability check file specifies:

a type of network service or network protocol to be tested,

a port number to be tested,

a scan request to use for a test, and

a scan response expression to match a response obtained for the test.

16 . The method of claim 14 , wherein the vulnerability check file specifies a particular test to check an operating system or one or more files of a particular asset for a software vulnerability.

17 . The method of claim 11 , wherein the vulnerability solution file includes a plurality of remediation actions that are common to different types of vulnerabilities.

18 . The method of claim 17 , further comprising the security console:

displaying, via the user interface, one or more of the remediation steps in response to a determination that the type of vulnerability is detected on a particular asset.

19 . The method of claim 11 , further comprising the security console:

sending scan instructions to the one or more remote scan engine over Internet; and

receiving scan results from the one or more remote scan engine over Internet.

20 . The method of claim 19 , further comprising the security console:

displaying the scan results via the user interface.

Assignments (2)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 9, 2024
From: STEERS, JACK
To: RAPID7, INC.
Reel/Frame 069522/0059 →
Continuity (2)
Continuation 17467484 · Sep 7, 2021
Related Publication 20250106241A1 · Mar 27, 2025
References Cited (51)
US 6799197B1 · Shetty · 2004 [cited by examiner]
US 6944775B2 · Barton · 2005 [cited by examiner]
US 6947986B1 · Huang · 2005 [cited by examiner]
US 7849507B1 · Bloch · 2010 [cited by examiner]
US 8201257B1 · Andres · 2012 [cited by examiner]
US 8302196B2 · Soderberg · 2012 [cited by examiner]
US 8789190B2 · Russell · 2014 [cited by examiner]
US 9117069B2 · Oliphant · 2015 [cited by examiner]
US 9251351B2 · Hugard, IV · 2016 [cited by examiner]
US 10284589B2 · Hamdi · 2019 [cited by examiner]
US 11310262B1 · Oliphant · 2022 [cited by examiner]
US 11853430B2 · Bhalla · 2023 [cited by examiner]
US 20030074581A1 · Hursey · 2003 [cited by examiner]
US 20030188194A1 · Currie · 2003 [cited by examiner]
US 20040049736A1 · Al-Azzawe · 2004 [cited by examiner]
US 20070028110A1 · Brennan · 2007 [cited by examiner]
US 20070220602A1 · Ricks · 2007 [cited by examiner]
US 20070266421A1 · Vaidya · 2007 [cited by examiner]
US 20080183603A1 · Kothari · 2008 [cited by examiner]
US 20080196104A1 · Tuvell · 2008 [cited by examiner]
US 20110231936A1 · Williams · 2011 [cited by examiner]
US 20120216190A1 · Sivak · 2012 [cited by examiner]
US 20130074188A1 · Giakouminakis · 2013 [cited by examiner]
US 20130167238A1 · Russell · 2013 [cited by examiner]
US 20130174246A1 · Schrecker · 2013 [cited by examiner]
US 20130247207A1 · Hugard, IV · 2013 [cited by examiner]
US 20130276053A1 · Hugard, IV · 2013 [cited by examiner]
US 20150099562A1 · Xiong · 2015 [cited by examiner]
US 20150106939A1 · Lietz · 2015 [cited by examiner]
US 20160164883A1 · Li · 2016 [cited by examiner]
US 20170286689A1 · Kelley · 2017 [cited by examiner]
US 20180124092A1 · Pope · 2018 [cited by examiner]
US 20180307840A1 · David · 2018 [cited by examiner]
US 20180332069A1 · Moore · 2018 [cited by examiner]
US 20190052994A1 · Dar · 2019 [cited by examiner]
US 20200042718A1 · Barouni Ebrahimi · 2020 [cited by examiner]
US 20200082094A1 · Mcallister · 2020 [cited by examiner]
US 20200302058A1 · Kenyon · 2020 [cited by examiner]
US 20210099478A1 · Seetharamaiah · 2021 [cited by examiner]
US 20210173935A1 · Ramasamy · 2021 [cited by examiner]
US 20210226979A1 · Wang · 2021 [cited by examiner]
US 20210326451A1 · Nuñez Di Croce · 2021 [cited by examiner]
US 20210400074A1 · Smith · 2021 [cited by examiner]
US 20220269790A1 · Rajana · 2022 [cited by examiner]
US 20220294817A1 · Parekh · 2022 [cited by examiner]
US 20240146763A1 · Curran · 2024 [cited by examiner]
US 20250335598A1 · Charles · 2025 [cited by examiner]
B. Wang, L. Liu, F. Li, J. Zhang, T. Chen and Z. Zou, “Research on Web Application Security Vulnerability Scanning Technology,” 2019 IEEE 4th Advanced Information Technology, Electronic and Automation Control Conference… [cited by examiner]
Kals, Stefan, et al. “Secubat: a web vulnerability scanner.” Proceedings of the 15th international conference on World Wide Web. 2006, pp. 247-256. (Year: 2006). [cited by examiner]
X. Tian and D. Tang, “A Distributed Vulnerability Scanning on Machine Learning,” 2019 6th International Conference on Information Science and Control Engineering (ICISCE), Shanghai, China, 2019, pp. 32-35. (Year: 2019). [cited by examiner]
Shivani, T. J., Hegde Ramakrishna, and Nagraj Nagashree. “Vulnerability management using machine learning techniques.” 2021 IEEE International Conference on Mobile Networks and Wireless Communications (ICMNWC). IEEE, 20… [cited by examiner]