IP Library Granted Patent US 12,401,676
Granted Patent B2
US 12,401,676 · App. 18/468,584 · Granted Aug 26, 2025

Systems and methods for performing an external vulnerability scan using external internet protocol addresses

Inventor: Cameron Byrne (Seattle, WA)
Assignee: T-Mobile USA, Inc.
H04L63/1433H04L63/1425H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,401,676
App. No.
18/468,584
Granted
Aug 26, 2025
Kind
B2
Abstract

System and methods for external vulnerability scanning a network are described. When a user equipment is attached to a network, the network provides information about the user equipment to a lookup table. In some examples, the lookup table is maintained by a network, such as mobile network, that facilitates packet-based communications between the user equipment to devices on the Internet. A scanner that performs the external vulnerability scan is provided information stored in the lookup table. The scanner returns the results of the scan to the mobile network.

Claims (33)

1. A method, comprising:

receiving, at a first network, an Internet protocol (IP) address of a user equipment attached to a second network;

updating a lookup table, wherein the lookup table comprises the IP address of the user equipment, a geographic region of the user equipment, a geographic region of the second network, and a date/time when the user equipment was assigned the IP address;

prompting a scanner to perform a scanning operation on the second network using the IP address of the user equipment;

providing the scanner with the IP address of the user equipment from the lookup table; and

receiving results of the scanning operation.

2. The method of claim 1 , wherein the IP address of the user equipment is provided by a router servicing the second network.

3. The method of claim 2 , wherein the router servicing the second network performs a neighbor discovery protocol to provide the IP address of the user equipment.

4. The method of claim 1 , wherein prompting the scanner to perform the scanning operation on the second network using the IP address of the user equipment is done in response to the first network receiving an update to the lookup table from the second network indicating that the user equipment has been attached to the second network.

5. The method of claim 1 , wherein prompting the scanner to perform the scanning operation on the second network using the IP address of the user equipment is done in response to a period of time elapsing between a prior scanning operation and the scanning operation.

6. The method of claim 1 , wherein the IP address is associated with an address space for IPV6 communication protocols.

7. The method of claim 1 , further comprising providing the results of the scanning operation to the second network.

8. The method of claim 1 , wherein the scanning operation comprises scanning the IP address to probe for vulnerabilities to determine a possible exploit.

9. The method of claim 1 , wherein the lookup table further comprises a media access control (MAC) address of the user equipment.

10. A non-transitory computer-readable media storing computer-executable instructions that, when executed by one or more processors, cause the one or more processors to perform operations comprising:

receiving, at a first network, an Internet protocol (IP) address of a user equipment attached to a second network;

updating a lookup table, wherein the lookup table comprises the IP address of the user equipment, a geographic region of the user equipment, a geographic region of the second network, and a date/time when the user equipment was assigned the IP address;

prompting a scanner to perform a scanning operation on the second network using the IP address of the user equipment;

providing the scanner with the IP address of the user equipment from the lookup table; and

receiving results of the scanning operation.

11. The non-transitory computer-readable media of claim 10 , wherein the IP address of the user equipment is provided by a router servicing the second network.

12. The non-transitory computer-readable media of claim 11 , wherein the router servicing the second network performs a neighbor discovery protocol to provide the IP address of the user equipment.

13. The non-transitory computer-readable media of claim 10 , wherein prompting the scanner to perform the scanning operation on the second network using the IP address of the user equipment is done in response to the first network receiving an update to the lookup table from the second network indicating that the user equipment has been attached to the second network.

14. The non-transitory computer-readable media of claim 10 , wherein prompting the scanner to perform the scanning operation on the second network using the IP address of the user equipment is done in response to a period of time elapsing between a prior scanning operation and the scanning operation.

15. The non-transitory computer-readable media of claim 10 , wherein the IP address is associated with an address space for IPv6 communication protocols.

16. The non-transitory computer-readable media of claim 10 , further comprising providing the results of the scanning operation to the second network.

17. The non-transitory computer-readable media of claim 10 , wherein the scanning operation comprises scanning the IP address to probe for vulnerabilities to determine a possible exploit.

18. The non-transitory computer-readable media of claim 10 , wherein the lookup table further comprises a media access control (MAC) address of the user equipment.

19. A mobile telecommunications network, comprising:

a lookup table configured to receive information about one or more user equipment attached to an enterprise network, the information comprising an external Internet protocol (IP) address for each of the one or more user equipment provided by the enterprise network when the one or more user equipment is attached to the enterprise network, wherein the lookup table further comprises a geographic region of the one or more user equipment, a geographic region of the enterprise network, and a date/time when the one or more user equipment was assigned the IP address;

a scanner configured to perform an external vulnerability scan of at least one of the one or more user equipment attached to the enterprise network, wherein the external vulnerability scan comprises scanning the at least one of the one or more user equipment using the IP address to determine possible exploits; and

a security monitor configured to receive results of the external vulnerability scan and to provide the results to the enterprise network.

20. The mobile telecommunications network of claim 19 , wherein the lookup table further comprises a media access control (MAC) address of the one or more user equipment.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Sep 15, 2023
From: BYRNE, CAMERON
To: T-MOBILE USA, INC.
Reel/Frame 064927/0383 →
Continuity (1)
Related Publication 20250097250A1 · Mar 20, 2025
References Cited (9)
US 6768743B1 · Borella · 2004 [cited by examiner]
US 9160809B2 · Carney · 2015 [cited by examiner]
US 20070097976A1 · Wood · 2007 [cited by examiner]
US 20100046530A1 · Hautakorpi · 2010 [cited by examiner]
US 20100322237A1 · Raja · 2010 [cited by examiner]
US 20150188949A1 · Mahaffey · 2015 [cited by examiner]
US 20170006113A1 · Singhal · 2017 [cited by examiner]
US 20190036911A1 · Bell · 2019 [cited by examiner]
Ahmed et al. (IPv6 Neighbor Discovery Protocol Specifications, Threats and Countermeasures: A Survey, IEEE 2017, pp. 18187-18210) (Year: 2017). [cited by examiner]