IP Library › Granted Patent US 10,452,851
Granted Patent B2
US 10,452,851 · App. 15/015,511 · Granted Oct 22, 2019

Automated security assessment of business-critical systems and applications

Inventor: Mariano Nuñez Di Croce (Ciudad de Buenos Aires, AR)
Assignee: ONAPSIS S.R.L.
G06F21/577G06F16/951H04L63/1433G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,452,851
App. No.
15/015,511
Granted
Oct 22, 2019
Kind
B2
Abstract

Systems and methods which provide a new application security assessment framework that allows auditing and testing systems to automatically perform security and compliance audits, detect technical security vulnerabilities, and illustrate the associated security risks affecting business-critical applications.

Claims (34)

1. A system for automatically assessing the security of a computer running one or more software applications in a network in communication with a first server configured to execute a user interface and a core engine to receive a requested assessment of the computer, comprising:

a second server in communication via the network with the first server comprising a processor and memory configured to store non-transitory instructions, which when executed by the processor is configured to perform the steps of:

executing a scan engine comprising;

a system identifier subcomponent for determining resources of the computer;

a fingerprint database storing a set of probes and a corresponding expected response for each probe;

a plurality of testing and probing modules for automatically testing the resources of the computer and for determining a vulnerability of said resources of the computer; and

an intelligent dispatch subcomponent for launching at least one of said plurality of testing and probing modules based on a configuration of said module;

receiving instructions from the core engine regarding an activity to perform in the computer;

receiving from the core engine a port identifier specifying a port of the computer;

creating an application connector for a known service on the specified port;

using the application connector, probing the specified port with a probe from the fingerprint database to determine that the known service is open;

launching, by the intelligent dispatch subcomponent, a module of the plurality of testing and probing modules on the second server targeting the known service via the specified port of the computer;

receiving a result from the launched module indicating a vulnerability of the computer; and

sending the result to the core engine for presenting the result with the user interface.

2. The system of claim 1 , wherein the first server is a local server on the network and the second server comprises a cloud based server.

3. The system of claim 1 , wherein the first server is a cloud based server and the second server comprises a local server on the network.

4. The system of claim 1 , wherein the software application comprises one or more of a group consisting of Customer Relationship Management (CRM), Supplier Relationship Management (SRM), Supply Chain Management (SCM), Product Life-cycle Management (PLM), Human Capital Management (HCM), Integration Platforms, Business Warehouse (BW), Business Intelligence (BI), and enterprise resource planning (ERP).

5. The system of claim 1 , wherein the software application comprises one or more of a group consisting of SAP software, Oracle software, Microsoft software, Siebel software, JD Edwards software, and PeopleSoft software.

6. A system for automatically assessing the security of a computer running one or more software applications in a network in communication with a first server configured to execute a user interface and a core engine to receive a requested assessment of the computer, comprising:

a second server comprising a processor and memory configured to store non-transitory instructions, which when executed by the processor is configured to perform the steps of:

executing a scan engine comprising;

a system identifier subcomponent for determining resources of the computer;

a fingerprint database storing a set of probes and a corresponding expected response for each probe;

a plurality of testing and probing modules for automatically testing resources of the computer and for determining a vulnerability of said resources; and

an intelligent dispatch subcomponent for launching at least one of said testing and probing modules based on a configuration of said module;

receiving instructions from the core engine regarding an activity to perform in the computer;

creating an application connector for a known service on a specified port of the computer;

using the application connector, probing the specified port with a probe from the fingerprint database to determine that the known service is open;

launching, by the intelligent dispatch subcomponent, a module on the second server targeting the computer;

receiving a result from the launched module indicating a vulnerability of the computer; and

sending the result to the core engine for presenting the result with the user interface,

wherein the first server and the second server are partitioned on the same server.

7. The system of claim 6 , wherein the software application comprises one or more of a group consisting of Customer Relationship Management (CRM), Supplier Relationship Management (SRM), Supply Chain Management (SCM), Product Life-cycle Management (PLM), Human Capital Management (HCM), Integration Platforms, Business Warehouse (BW), Business Intelligence (BI), and enterprise resource planning (ERP).

8. The system of claim 6 , wherein the software application comprises one or more of a group consisting of SAP software, Oracle software, Microsoft software, Siebel software, JD Edwards software, and PeopleSoft software.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 3, 2017
From: NUÑEZ DI CROCE, MARIANO
To: ONAPSIS S.R.L.
Reel/Frame 042221/0417 →
Continuity (4)
Division 14631147 · Feb 25, 2015
Division 13807122
Provisional Application 61360610 · Jul 1, 2010
Related Publication 20160154962A1 · Jun 2, 2016