IP Library › Granted Patent US 12,614,138
Granted Patent B1
US 12,614,138 · App. 17/360,316 · Granted Apr 28, 2026

Organization vendor-based risk assessment using internet telemetry

Inventors: Wah-Kwan Lin (Melrose, MA); Harley Ray Rogers (Somerville, MA)
Assignee: Rapid7, Inc.
G06Q10/0635H04L63/1425H04L63/1433H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,614,138
App. No.
17/360,316
Granted
Apr 28, 2026
Kind
B1
Abstract

Various embodiments include systems and methods of assessing vendor risk. One or more sets of IP address(es) associated with one or more vendors is identified. Risk data related to the set(s) of IP address(es) is obtained using internet telemetry data. Based at least in part on the risk data, security risk level(s) are determined for the vendor(s). Some embodiments include systems and methods of implementing a vendor-based risk posture assessment of an organization. The vendor-based risk posture assessment may be based at least in part on one or more security risk levels determined for the vendor(s) of the organization.

Claims (84)

1 . A system, comprising:

one or more hardware processors with associated memory that implement a vendor-based risk posture assessment system of an organization, wherein the one or more hardware processors are configured to:

repeatedly determine security risk levels for a plurality of vendors of the organization over a plurality of time intervals, wherein the vendors have privileged access to one or more computer systems of the organization, wherein the determination of a respective security risk level of a respective vendor includes to:

identify a respective set of one or more internet protocol (IP) addresses of the respective vendor;

perform one or more network scans of the one or more IP addresses to collect internet telemetry data for the one or more IP addresses;

generate risk data related to the one or more IP addresses, wherein the risk data includes the internet telemetry data collected for the one or more IP addresses and indications of whether a set of security exposures are evidenced by the internet telemetry data, including:

(a) an expired domain name service (DNS) certificate associated with the one or more IP addresses,

(b) an exposed instance of an unencrypted service,

(c) an exposed network time protocol (NTP) and border gateway protocol (BGP), and

(d) an operating system or application that is no longer supported or patched by a provider; and

determine, based at least in part on the risk data, the respective security risk level of the respective vendor;

determine that a security risk level of a particular vendor has changed from a previous time interval, and in response:

identify, based on the change and the risk data, one or more security lapses of the particular vendor and one or more security improvement areas to address the one or more security lapses; and

generate a first alert via a graphical user interface indicating the one or more security lapses and the one or more security improvement areas; and

assess, based at least in part on the security risk levels for the plurality of vendors,

a risk posture of the organization, and in response:

determine, based on the risk posture of the organization, a secondary security exposure of the one or more computer systems of the organization through association with the particular vendor;

generate a second alert indicating the secondary security exposure of the organization via the graphical user interface; and

automatically perform one or more remedial actions to mitigate the secondary security exposure, wherein the one or more remedial actions includes terminating or altering a privileged access of the particular vendor to the one or more computer systems.

2 . The system of claim 1 , wherein to assess the risk posture, the one or more hardware processors are configured to apply a centrality measure to the security risk levels of the plurality of vendors based on a graph comprising the plurality of vendors.

3 . The system of claim 1 , wherein the one or more network scans do not use credentialed measures to collect the internet telemetry data.

4 . The system of claim 1 , wherein the risk data includes a fingerprint of scan results of a network scan of an IP address that indicates a version of an application associated with the IP address.

5 . The system of claim 1 , wherein the risk data includes scan results of a network scan of an IP address, including one or more types of exploit vulnerabilities associated with the IP address.

6 . The system of claim 1 , wherein the set of security exposures includes security exposures associated with different types of services or protocols, including two or more of:

server message block (SMB) service,

remote desktop protocol (RDP) service,

a file transfer protocol (FTP) service,

a telnet service, and

an android debug bridge (ADB) protocol.

7 . The system of claim 1 , wherein the one or more hardware processors are configured to:

obtain honeypot data collected using a honeypot node network;

determine, from the honeypot data, honeypot connection results for the respective set of one or more IP addresses wherein individual honeypot connection results are based on whether one or more honeypot connections are determined to originate from a respective IP address; and

aggregate the honeypot connection results to the risk data.

8 . The system of claim 7 , wherein the one or more hardware processors are configured to:

determine, based on the honeypot connection results, that the particular vendor has been compromised by a botnet.

9 . The system of claim 1 , wherein the remedial action is one of a plurality of remedial actions displayed on the graphical user interface.

10 . A method comprising:

performing, by one or more hardware processors that implement a vendor-based risk posture assessment system of an organization:

repeatedly determining security risk levels for a plurality of vendors of the organization over a plurality of time intervals, wherein the vendors have privileged access to one or more computer systems of the organization, wherein the determination of a respective security risk level of a respective vendor includes:

identifying a respective set of one or more internet protocol (IP) addresses of the respective vendor;

performing one or more network scans of the one or more IP addresses to collect internet telemetry data for the one or more IP addresses;

generating risk data related to the one or more IP addresses, wherein the risk data includes the internet telemetry data collected for the one or more IP addresses and indications of whether a set of security exposures are evidenced by the internet telemetry data, including:

(a) an expired domain name service (DNS) certificate associated with the one or more IP addresses,

(b) an exposed instance of an unencrypted service,

(c) an exposed network time protocol (NTP) and border gateway protocol (BGP), and

(d) an operating system or application that is no longer supported or patched by a provider; and

determining, based at least in part on the risk data, the respective security risk level of the respective vendor;

determining that a security risk level of a particular vendor has changed from a previous time interval, and in response:

identifying, based on the change and the risk data, one or more security lapses of the particular vendor and one or more security improvement areas to address the one or more security lapses; and

generating a first alert via a graphical user interface indicating the one or more security lapses and the one or more security improvement areas; and

assessing, based at least in part on the security risk levels for the plurality of vendors, a risk posture of the organization, and in response:

determining, based on the risk posture of the organization, a secondary security exposure of the one or more computer systems of the organization through association with the particular vendor;

generating a second alert indicating the secondary security exposure of the organization via the graphical user interface; and

automatically performing one or more remedial actions to mitigate the secondary security exposure, wherein the one or more remedial actions includes terminating or altering a privileged access of the particular vendor to the one or more computer systems.

11 . The method of claim 10 , wherein assessing the risk posture includes determining that the risk posture of the organization is one of:

relatively high risk responsive to classifying multiple vendors as relatively high-risk vendors based on the respective security risk levels; or

relatively low risk responsive to classifying multiple vendors as relatively low-risk vendors based on the respective security risk levels.

12 . The method of claim 11 , wherein the one or more network scans do not use credentialed measures to collect the internet telemetry data.

13 . The method of claim 10 , wherein the one or more remedial actions includes altering or terminating an engagement relationship with the particular vendor.

14 . The method of claim 10 , wherein the first alert is generated responsive to a change in the risk posture of the organization from a first time interval to a second time interval.

15 . The method of claim 10 , wherein the first alert is generated responsive to the risk posture of the organization changing from relatively low risk to relatively high risk.

16 . One or more non-transitory computer-accessible storage media storing program instructions that, when executed on or across one or more processors, implement at least a portion of a vendor-based risk posture assessment system of an organization and cause the vendor-based risk posture assessment system to:

repeatedly determine security risk levels for a plurality of vendors of the organization over a plurality of time intervals, wherein the vendors have privileged access to one or more computer systems of the organization, wherein the determination of a respective security risk level of a respective vendor includes to:

identify a respective set of one or more internet protocol (IP) addresses of the respective vendor;

perform one or more network scans of the one or more IP addresses to collect internet telemetry data for the one or more IP addresses;

generate risk data related to the one or more IP addresses, wherein the risk data includes the internet telemetry data collected for the one or more IP addresses and indications of whether a set of security exposures are evidenced by the internet telemetry data, including:

(a) an expired domain name service (DNS) certificate associated with the one or more IP addresses,

(b) an exposed instance of an unencrypted service,

(c) an exposed network time protocol (NTP) and border gateway protocol (BGP), and

(d) an operating system or application that is no longer supported or patched by a provider; and

determine, based at least in part on the risk data, the respective security risk level of the respective vendor;

determine that a security risk level of a particular vendor has changed from a previous time interval, and in response:

identify, based on the change and the risk data, one or more security lapses of the particular vendor and one or more security improvement areas to address the one or more security lapses; and

generate a first alert via a graphical user interface indicating the one or more security lapses and the one or more security improvement areas; and

assess, based at least in part on the security risk levels for the plurality of vendors, a risk posture of the organization, and in response:

determine, based on the risk posture of the organization, a secondary security exposure of the one or more computer systems of the organization through association with the particular vendor;

generate a second alert indicating the secondary security exposure of the organization via the graphical user interface; and

automatically perform one or more remedial actions to mitigate the secondary security exposure, wherein the one or more remedial actions includes terminating or altering a privileged access of the particular vendor to the one or more computer systems.

17 . The one or more non-transitory computer-accessible storage media of claim 16 , wherein the remedial action is one of a plurality of remedial actions displayed on the graphical user interface.

18 . The one or more non-transitory computer-accessible storage media of claim 16 , wherein the risk posture of the organization is one of relatively high risk or relatively low risk, and the risk posture is determined responsive to at least a subset of the vendors being classified as relatively high-risk vendors based on the respective security risk levels.

19 . The one or more non-transitory computer-accessible storage media of claim 18 , wherein the second alert identifies at least the relatively high-risk vendors via the graphical user interface.

20 . The one or more non-transitory computer-accessible storage media of claim 16 , wherein the program instructions when executed on or across one or more processors cause the vendor-based risk posture assessment system to:

identify, based on a network scan of the particular vendor, a particular version of an application used by the particular vendor that includes a vulnerability to a particular exploit; and

determine, based on another network scan of the particular vendor, that the vulnerability has been addressed by a subsequent patch of the application.

References Cited (7)
US 10949543B1 · Bolukbas · 2021 [cited by examiner]
US 20160088021A1 · Jayanti Venkata · 2016 [cited by examiner]
US 20160173521A1 · Yampolskiy · 2016 [cited by examiner]
US 20170272255A1 · Larson · 2017 [cited by examiner]
US 20200004938A1 · Brannon · 2020 [cited by examiner]
WO WO2004104793A2 · 2004 [cited by examiner]
Axel Buecker et al. Stopping Internet Threats Before They Affect Your Business by Using the IBM Security Network Intrusion Prevention System. 2011 IBM Corp. (Year: 2011). [cited by examiner]