IP Library Granted Patent US 12,437,080
Granted Patent B2
US 12,437,080 · App. 18/306,947 · Granted Oct 7, 2025

Automated packetless network reachability analysis

Inventors: Catherine Dodge (Seattle, WA); Nikhil Reddy Cheruku (Falls Church, VA); John Byron Cook (Brooklyn, NY); Temesghen Kahsai Azene (Union City, CA); William Jo Kocik (Charles Town, WV); Sean Mclaughlin (Seattle, WA); Mark Edward Stalzer (Arlington, VA); Blake Whaley (Fairfax, VA); Yiwen Wu (Fairfax, VA)
Assignee: Amazon Technologies, Inc.
G06F21/577H04L41/0866H04L43/06H04L63/0272H04L63/1433H04L63/1441
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,437,080
App. No.
18/306,947
Filed
Apr 25, 2023
Granted
Oct 7, 2025
Kind
B2
Examiner
LE, CHAU D
Art Unit
2408
USPC
726/25
Abstract

Methods, systems, and computer-readable media for automated packetless network reachability analysis are disclosed. An analysis is performed of network configuration data for a network comprising a host computer. Based at least in part on the analysis, one or more ports at the host computer that are reachable from another computer are determined. Based at least in part on the analysis, one or more routes to the one or more ports are determined. A report is generated that is descriptive of the one or more ports and the one or more routes.

Claims (30)

1. A system, comprising:

one or more computing devices configured to implement an infrastructure provider network, configured to:

create a virtual network for a client, wherein the virtual network includes virtual machines hosted on physical hosts of the infrastructure provider network;

install agents on the physical hosts, wherein the agents are configured to collect data about individual ones of the virtual machines;

determine, based at least in part on the collected data and on network configuration data for the virtual network, an open port on one of the virtual machines and whether the open port is reachable from outside a trusted location, wherein said determine is performed without sending packets to the open port from outside the trusted location; and

generate a report that identifies the virtual machine, a port number of the open port, and whether the open port is reachable from outside the trusted location.

2. The system as recited in claim 1 , wherein the infrastructure provider network is a multi-tenant provider network that hosts a plurality of private networks for a plurality of clients.

3. The system as recited in claim 1 , wherein the determination of the open port is performed by a network security evaluator that executes in the infrastructure provider network, wherein the network security evaluator is configured to control the agents.

4. The system as recited in claim 3 , wherein the network security evaluator is configured to determine a reachability of the open port from Internet and indicate the reachability in the report.

5. The system as recited in claim 3 , wherein the network security evaluator is configured to determine a process listening on the open port based at least in part on the collected data.

6. The system as recited in claim 3 , wherein the network security evaluator is configured to determine a network protocol associated with the open port and indicate the network protocol on the report.

7. The system as recited in claim 3 , wherein the network security evaluator is configured to determine that the port number is atypical for a network protocol associated with the open port.

8. The system as recited in claim 3 , wherein the network security evaluator is configured to monitor for connections to the open port and determine whether the connection represents a security threat.

9. The system as recited in claim 3 , wherein the network security evaluator is configured to determine open ports in the virtual network without sending packets to individual ones of the virtual machines from outside the trusted location.

10. The system as recited in claim 3 , wherein the network security evaluator is configured to determine one or more corrective actions regarding the open port and recommend the one or more corrective actions in the report.

11. The system as recited in claim 10 , wherein the one or more corrective actions includes stopping an application associated with the open port, changing an access control list (ACL) associated with the virtual network, or changing a security group associated with the virtual network.

12. The system as recited in claim 3 , wherein the network security evaluator is configured to display the report via a graphical user interface (GUI).

13. The system as recited in claim 12 , wherein the network security evaluator is configured to service user queries regarding network configuration of the virtual network via the GUI.

14. A method, comprising:

performing, by one or more computing devices of an infrastructure provider network:

creating a virtual network for a client, wherein the virtual network includes virtual machines hosted on physical hosts of the infrastructure provider network;

installing agents on the physical hosts, wherein the agents are configured to collect data about individual ones of the virtual machines;

determining, based at least in part on the collected data and on network configuration data for the virtual network, an open port on one of the virtual machines and whether the open port is reachable from outside a trusted location, wherein said determining is performed without sending packets to the open port from outside the trusted location; and

generating a report that identifies the virtual machine, a port number of the open port, and whether the open port is reachable from outside the trusted location.

15. The method as recited in claim 14 , wherein the determination of the open port is performed by a network security evaluator that executes in the infrastructure provider network, wherein the network security evaluator is configured to receive the data collected by the agents.

16. The method as recited in claim 15 , further comprising the network security evaluator determining a reachability of the open port from Internet and indicating the reachability in the report.

17. The method as recited in claim 15 , further comprising the network security evaluator determining a severity level of a security threat associated with the open port and indicating the severity level in the report.

18. The method as recited in claim 15 , further comprising the network security evaluator determining that the port number is atypical for a network protocol associated with the open port.

19. The method as recited in claim 15 , further comprising the network security evaluator repeatedly determining open ports in the virtual network according to a schedule.

20. The method as recited in claim 15 , further comprising the network security evaluator determining one or more corrective actions regarding the open port and recommending the one or more corrective actions in the report.

Continuity (3)
Continuation 17459908 · Aug 27, 2021
Continuation 16020865 · Jun 27, 2018
Related Publication 20230262087A1 · Aug 17, 2023
References Cited (76)
US 5892903A · Klaus · 1999 [cited by examiner]
US 7003562B2 · Mayer · 2006 [cited by applicant]
US 7685281B1 · Saraiya · 2010 [cited by applicant]
US 8250654B1 · Kennedy et al. · 2012 [cited by applicant]
US 8566269B2 · Jajodia et al. · 2013 [cited by applicant]
US 8949387B2 · Dickens et al. · 2015 [cited by applicant]
US 9276951B2 · Choi et al. · 2016 [cited by applicant]
US 9912549B2 · Rieke · 2018 [cited by examiner]
US 9923787B2 · Ngoo et al. · 2018 [cited by applicant]
US 10389608B2 · Searle · 2019 [cited by examiner]
US 10469324B2 · Cook et al. · 2019 [cited by applicant]
US 11095523B2 · Cook et al. · 2021 [cited by applicant]
US 11108805B2 · Dodge et al. · 2021 [cited by applicant]
US 11671442B2 · Dodge et al. · 2023 [cited by applicant]
US 20020091942A1 · Cooper et al. · 2002 [cited by applicant]
US 20060174337A1 · Bernoth · 2006 [cited by examiner]
US 20070136788A1 · Monahan et al. · 2007 [cited by applicant]
US 20080059416A1 · Forbes · 2008 [cited by applicant]
US 20080066160A1 · Becker et al. · 2008 [cited by applicant]
US 20080155537A1 · Dinda · 2008 [cited by applicant]
US 20110213870A1 · Cai et al. · 2011 [cited by applicant]
US 20110219434A1 · Betz et al. · 2011 [cited by applicant]
US 20120079464A1 · De Smet · 2012 [cited by applicant]
US 20120084862A1 · Freeman et al. · 2012 [cited by applicant]
US 20120124198A1 · Tomita · 2012 [cited by examiner]
US 20130047230A1 · Krishnan et al. · 2013 [cited by applicant]
US 20130111033A1 · Mao · 2013 [cited by applicant]
US 20130227697A1 · Zandani · 2013 [cited by applicant]
US 20140189125A1 · Amies et al. · 2014 [cited by applicant]
US 20140236579A1 · Kurz · 2014 [cited by applicant]
US 20140341218A1 · Bays et al. · 2014 [cited by applicant]
US 20150006458A1 · Zadka · 2015 [cited by applicant]
US 20150281269A1 · Ali-Ahmad et al. · 2015 [cited by applicant]
US 20150295761A1 · Wang et al. · 2015 [cited by applicant]
US 20160112269A1 · Singh et al. · 2016 [cited by applicant]
US 20170093640A1 · Subramanian · 2017 [cited by examiner]
US 20170293501A1 · Barapatre · 2017 [cited by applicant]
US 20180145879A1 · Cook · 2018 [cited by examiner]
US 20180357119A1 · Yagi · 2018 [cited by applicant]
US 20190334949A1 · Guri · 2019 [cited by examiner]
US 20200007569A1 · Dodge et al. · 2020 [cited by applicant]
US 20200067962A1 · Tan · 2020 [cited by applicant]
US 20200314145A1 · Bolignano et al. · 2020 [cited by applicant]
US 20210377126A1 · Cook et al. · 2021 [cited by applicant]
CN 101067823A · 2007 [cited by applicant]
CN 101699801 · 2010 [cited by applicant]
CN 102334111A · 2012 [cited by applicant]
CN 102413012A · 2012 [cited by applicant]
CN 103650430 · 2014 [cited by applicant]
CN 104363159 · 2015 [cited by applicant]
CN 106063223A · 2016 [cited by applicant]
CN 106603507A · 2017 [cited by applicant]
CN 108011893A · 2018 [cited by applicant]
CN 108200106A · 2018 [cited by applicant]
GB 2424539 · 2006 [cited by applicant]
JP 2015204614 · 2015 [cited by applicant]
WO 2005101789 · 2005 [cited by applicant]
WO 2010114715A1 · 2010 [cited by applicant]
WO 2015127894A1 · 2015 [cited by applicant]
WO 2017094845 · 2017 [cited by applicant]
Marcelo Santos, et al., “An Adaptive Random Heuristic in Virtual Networks: Dependability Analysis”, 2015 Latin American Network Operations and Management Symposium (LANOMS), Oct. 3, 2015, IEEE. [cited by applicant]
Su Xijuan, et al., “A Virtual Resource Description and Discovery Model Based on Hybrid Granularity”, Telecommunications Science, Feb. 20, 2013, pp. 43-50, 29(2). [cited by applicant]
Office Action mailed Nov. 24, 2023 in Chinese Patent Application No. 201980043063.6, Amazon Technologies, Inc., pp. 1-25 (including translation). [cited by applicant]
Office Action mailed Nov. 27, 2023 in European patent application No. 19740452.8, Amazon Technologies, Inc., 1 pp. 1-5. [cited by applicant]
Kals, Stefan, et al. “Secubat: a web vulnerability scanner.” Proceedings of the 15th international conference on World Wide Web. ACM, 2006, pp. 1-10. [cited by applicant]
Burns, James, et al. “Automatic management of network security policy.” DARPA Information Survivability Conference & Exposition II, 2001. DISCEX'01. Proceedings. vol. 2. IEEE, 2001, pp. 1-15. [cited by applicant]
Wang, Anduo, et al. “Declarative network verification.” International Symposium on Practical Aspects of Declarative Languages. Springer Berlin Heidelberg, 2009, pp. 1-15. [cited by applicant]
“Security Monkey Quick Start Guide”, Retrieved from URL: http://securitymonkey.readthedocs.io/en/latest/quickstart.html, pp. 1-27. [cited by applicant]
International Search Report and Written Opinion, Dated Mar. 1, 2018, Amazon Technologies, Inc., pp. 1-13. [cited by applicant]
Tyler Wall, “Common Basic Port Scanning Techniques,” Jul. 5, 2016, pp. 1-4. [cited by applicant]
U.S. Appl. No. 16/672,120, filed Nov. 1, 2019, John Cook, et al. [cited by applicant]
“Security Monkey Quick Start Guide”, Retrieved from URL: http://securitymonkey.readthedocs.io/en/latest/quickstart.html, Retrieved from the internet on Feb. 24, 2017, pp. 1-27. [cited by applicant]
International Search Report and Written Opinion from PCT/US2019/039250, dated Sep. 12, 2019, (Amazon Technologies, Inc.), pp. 1-13. [cited by applicant]
Kreutz et al., “Software-Defined Networking: A Comprehensive Survey”, IEEE, Retrieved From https://arxiv.org/pdf/1406.0440.pdf, Published May 31, 2014, (Year: 2014). pp. 1-61. [cited by applicant]
Backes J. et al. (2019) Reachability Analysis for AWS-Based Networks. In: Dillig I., Tasiran S. (eds) Computer Aided Verification. GAV 2019. Lecture Notes in Computer Science, vol. 11562. Springer, Cham. https://doi.org… [cited by applicant]
Office Action mailed Feb. 22, 2022 in Japanese Patent Application No. 2020-570434, Amazon Technologies, Inc, pp. 1-7 (including translation). [cited by applicant]
Cited By (2)
US 12,688,277 US 12,739,106