IP Library Granted Patent US 12,726,504
Granted Patent B2
US 12,726,504 · App. 18/908,753 · Granted Sep 1, 2026

Generative systems and methods for adaptive vulnerability management

Inventor: James Cooper Richard (Overland Park, KS)
Assignee: T-Mobile USA, Inc.
H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,726,504
App. No.
18/908,753
Granted
Sep 1, 2026
Kind
B2
Abstract

Systems and methods are disclosed comprising instructions to collect vulnerability information over a network from a publishing source, collect network asset information of a communications network, generate a self-executing scanner agent configured to automatically scan the communications network for a known vulnerability based on an input including the collected vulnerability information and the collected network asset information, deploy the scanner agent at any network assets of the communications network that match a particular type of network asset indicated in the collected vulnerability information, generate a record including an indication of a particular network asset of the communications network in association with the known vulnerability in response to the scanner agent executing and detecting the known vulnerability in the particular network asset, and store the record in a data repository that aggregates records of detected known vulnerabilities in association with network assets of the communications network.

Claims (87)

1 . A method for generating custom scanner agents for vulnerability management of a computer system, the method comprising:

collecting vulnerability information over a network from a publishing source,

wherein the vulnerability information includes common vulnerabilities and exposures (CVEs) published on a public repository, and

wherein the CVEs include a known vulnerability for a particular type of network asset;

collecting network asset information of a communications network, the communications network being subject to the vulnerability management, wherein the network asset information includes information about multiple types of network assets deployed in the communications network;

generating, using a generative artificial intelligence (AI) system, based on an input including the collected vulnerability information and the collected network asset information, a self-executing scanner agent configured to automatically scan the communications network for the known vulnerability;

deploying the scanner agent at any network assets of the communications network that match the particular type of network asset indicated in the collected vulnerability information;

in response to the scanner agent executing and detecting the known vulnerability in a particular network asset of the communications network, generating a record including an indication of the particular network asset in association with the known vulnerability; and

storing the record in a data repository that aggregates records of detected known vulnerabilities in association with network assets of the communications network.

2 . The method of claim 1 further comprising:

configuring a similarity parameter between the multiple types of network assets deployed in the communications network and the particular type of network asset;

configuring a first threshold for the similarity parameter that, when exceeded, associates the scanner agent with a network asset of the communications network; and

configuring a second threshold for the scanner agent that, when exceeded, causes the scanner agent to self-execute scanning the network asset that exceeds the first threshold.

3 . The method of claim 1 , wherein the scanner agent is a first scanner agent and the particular type of network asset is a first type of network asset, the method further comprising:

calculating a correlation value between the known vulnerability and a second type of network asset of the communications network;

discovering a potential vulnerability for the second type of network asset based on the correlation value;

generating a second scanner agent configured to self-execute scanning of the communications network for the potential vulnerability; and

training the generative AI system based on the records aggregated at the data repository and the potential vulnerability.

4 . The method of claim 3 , wherein calculating the correlation value comprises:

calculating a similarity score between the first type of network asset and the second type of network asset; or

calculating a relevance score for the second type of network asset relative to the known vulnerability; and

identifying the potential vulnerability based on the similarity score or the relevance score.

5 . The method of claim 1 , wherein the publishing source comprises:

a public national vulnerability database (NVD) that obtains the vulnerability information from a vendor of the particular type of network asset; or

a vendor of the particular type of network asset and the vulnerability information is obtained directly from the vendor.

6 . The method of claim 5 , wherein the publishing source comprises a vendor of the particular type of network asset, and collecting the vulnerability information comprises:

automatically obtaining vulnerability information periodically from a website administered by the vendor.

7 . The method of claim 1 , wherein the particular network asset is a software asset, the method further comprising:

deploying a software patch for the software asset to remove a risk of the known vulnerability.

8 . The method of claim 1 further comprising:

estimating a financial risk of the known vulnerability to an operator of the communications network by performing a risk valuation of the known vulnerability on the particular network asset.

9 . A vulnerability management system comprising:

at least one hardware processor; and

at least one non-transitory memory storing instructions, which, when executed by the at least one hardware processor, cause the vulnerability management system to:

collect vulnerability information over a network from a publishing source, wherein the vulnerability information includes common vulnerabilities and exposures (CVEs) published on a public repository, and

wherein the CVEs include a known vulnerability for a particular type of network asset;

collect network asset information of a communications network, the communications network being subject to the vulnerability management system,

wherein the network asset information includes information about multiple types of network assets deployed in the communications network;

generate, using a generative artificial intelligence (AI) system, based on an input including the collected vulnerability information and the collected network asset information, a self-executing scanner agent configured to automatically scan the communications network for the known vulnerability;

deploy the scanner agent at any network assets of the communications network that match the particular type of network asset indicated in the collected vulnerability information;

in response to the scanner agent executing and detecting the known vulnerability in a particular network asset of the communications network, generate a record including an indication of the particular network asset in association with the known vulnerability; and

store the record in a data repository that aggregates records of detected known vulnerabilities in association with network assets of the communications network.

10 . The vulnerability management system of claim 9 further caused to:

configure a similarity parameter between the multiple types of network assets deployed in the communications network and the particular type of network asset;

configure a first threshold for the similarity parameter that, when exceeded, associates the scanner agent with a network asset of the communications network; and

configure a second threshold for the scanner agent that, when exceeded, causes the scanner agent to self-execute scanning the network asset that exceeds the first threshold.

11 . The vulnerability management system of claim 9 , wherein the scanner agent is a first scanner agent and the particular type of network asset is a first type of network asset, the system further caused to:

calculate a correlation value between the known vulnerability and a second type of network asset of the communications network;

discover a potential vulnerability for the second type of network asset based on the correlation value;

generate a second scanner agent configured to self-execute scanning of the communications network for the potential vulnerability; and

train the generative AI system based on the records aggregated at the data repository and the potential vulnerability.

12 . The vulnerability management system of claim 11 , wherein calculating the correlation value comprises causing the system to:

calculate a similarity score between the first type of network asset and the second type of network asset; or

calculate a relevance score for the second type of network asset relative to the known vulnerability; and

identify the potential vulnerability based on the similarity score or the relevance score.

13 . The vulnerability management system of claim 9 , wherein the publishing source comprises:

a public national vulnerability database (NVD) that obtains the vulnerability information from a vendor of the particular type of network asset; or

a vendor of the particular type of network asset and the vulnerability information is obtained directly from the vendor.

14 . The vulnerability management system of claim 13 , wherein the publishing source comprises a vendor of the particular type of network asset, and collecting the vulnerability information comprises causing the system to:

automatically obtain vulnerability information periodically from a website administered by the vendor.

15 . At least one non-transitory, computer-readable storage medium carrying instructions, which, when executed by a vulnerability management system, cause the vulnerability management system to perform operations for identifying a vulnerability of a computer asset, the operations comprising:

collecting vulnerability information over a network from a publishing source,

wherein the vulnerability information includes common vulnerabilities and exposures (CVEs) published on a public repository, and

wherein the CVEs include a known vulnerability for a particular type of network asset;

collecting network asset information of a communications network, the communications network being subject to the vulnerability management system,

wherein the network asset information includes information about multiple types of network assets deployed in the communications network;

generating, using a generative artificial intelligence (AI) system, based on an input including the collected vulnerability information and the collected network asset information, a self-executing scanner agent configured to automatically scan the communications network for the known vulnerability;

deploying the scanner agent at any network assets of the communications network that match the particular type of network asset indicated in the collected vulnerability information;

in response to the scanner agent executing and detecting the known vulnerability in a particular network asset of the communications network, generating a record including an indication of the particular network asset in association with the known vulnerability; and

storing the record in a data repository that aggregates records of detected known vulnerabilities in association with network assets of the communications network.

16 . The non-transitory, computer-readable storage medium of claim 15 , wherein the system is further caused to:

configure a similarity parameter between the multiple types of network assets deployed in the communications network and the particular type of network asset;

configure a first threshold for the similarity parameter that, when exceeded, associates the scanner agent with a network asset of the communications network; and

configure a second threshold for the scanner agent that, when exceeded, causes the scanner agent to self-execute scanning the network asset that exceeds the first threshold.

17 . The non-transitory, computer-readable storage medium of claim 15 , wherein the scanner agent is a first scanner agent and the particular type of network asset is a first type of network asset, the system further caused to:

calculate a correlation value between the known vulnerability and a second type of network asset of the communications network;

discover a potential vulnerability for the second type of network asset based on the correlation value;

generate a second scanner agent configured to self-execute scanning of the communications network for the potential vulnerability; and

train the generative AI system based on the records aggregated at the data repository and the potential vulnerability.

18 . The non-transitory, computer-readable storage medium of claim 17 , wherein calculating the correlation value comprises causing the system to:

calculate a similarity score between the first type of network asset and the second type of network asset; or

calculate a relevance score for the second type of network asset relative to the known vulnerability; and

identify the potential vulnerability based on the similarity score or the relevance score.

19 . The non-transitory, computer-readable storage medium of claim 15 , wherein the particular network asset is a software asset, the system further caused to:

deploy a software patch for the software asset to remove a risk of the known vulnerability.

20 . The non-transitory, computer-readable storage medium of claim 15 , wherein the system is further caused to:

estimate a financial risk of the known vulnerability to an operator of the communications network by performing a risk valuation of the known vulnerability on the particular network asset.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 8, 2024
From: RICHARD, JAMES COOPER
To: T-MOBILE USA, INC.
Reel/Frame 068829/0122 →
Continuity (1)
Related Publication 20260100964A1 · Apr 9, 2026
References Cited (108)
US 7260844B1 · Tidwell et al. · 2007 [cited by applicant]
US 7451488B2 · Cooper et al. · 2008 [cited by applicant]
US 7698275B2 · Obrien et al. · 2010 [cited by applicant]
US 7712138B2 · Zobel et al. · 2010 [cited by applicant]
US 7743421B2 · Cosquer et al. · 2010 [cited by applicant]
US 8095984B2 · Mcfarlane et al. · 2012 [cited by applicant]
US 8201257B1 · Andres et al. · 2012 [cited by applicant]
US 8495745B1 · Schrecker et al. · 2013 [cited by applicant]
US 8549650B2 · Hanson · 2013 [cited by applicant]
US 8595845B2 · Basavapatna et al. · 2013 [cited by applicant]
US 8621637B2 · Al-harbi et al. · 2013 [cited by applicant]
US 8789190B2 · Russell et al. · 2014 [cited by applicant]
US 8789192B2 · Labumbard · 2014 [cited by applicant]
US 8966639B1 · Roytman et al. · 2015 [cited by applicant]
US 9246935B2 · Lietz et al. · 2016 [cited by applicant]
US 9251351B2 · Hugard et al. · 2016 [cited by applicant]
US 9270695B2 · Roytman et al. · 2016 [cited by applicant]
US 9298927B2 · Lietz et al. · 2016 [cited by applicant]
US 9467464B2 · Gula et al. · 2016 [cited by applicant]
US 9602550B2 · Bezilla et al. · 2017 [cited by applicant]
US 9628501B2 · Datta et al. · 2017 [cited by applicant]
US 9692778B1 · Mohanty · 2017 [cited by applicant]
US 9699209B2 · Ng et al. · 2017 [cited by applicant]
US 9846780B2 · Tonn et al. · 2017 [cited by applicant]
US 9886582B2 · Hovor et al. · 2018 [cited by applicant]
US 9990499B2 · Chan et al. · 2018 [cited by applicant]
US 10185832B2 · Cam · 2019 [cited by applicant]
US 10284589B2 · Hamdi · 2019 [cited by applicant]
US 10454963B1 · Smith · 2019 [cited by applicant]
US 10542050B2 · Castel · 2020 [cited by applicant]
US 10713586B2 · Lim · 2020 [cited by applicant]
US 11005876B2 · Moore et al. · 2021 [cited by applicant]
US 11057418B2 · Ocepek et al. · 2021 [cited by applicant]
US 11277429B2 · Ababtain et al. · 2022 [cited by applicant]
US 11363041B2 · Paquin et al. · 2022 [cited by applicant]
US 11381590B2 · Alsaeed et al. · 2022 [cited by applicant]
US 11388184B2 · Siddiq · 2022 [cited by applicant]
US 11425157B2 · Tan et al. · 2022 [cited by applicant]
US 11438362B2 · Aleidan · 2022 [cited by applicant]
US 11526614B2 · Fang · 2022 [cited by applicant]
US 11611562B2 · Tiwari et al. · 2023 [cited by applicant]
US 11677773B2 · Iyer et al. · 2023 [cited by applicant]
US 11729197B2 · Cruz et al. · 2023 [cited by applicant]
US 11824886B2 · Lekies · 2023 [cited by examiner]
US 11930031B2 · Smith et al. · 2024 [cited by applicant]
US 12015631B2 · Morgan · 2024 [cited by applicant]
US 20060031938A1 · Choi · 2006 [cited by applicant]
US 20060265324A1 · Leclerc et al. · 2006 [cited by applicant]
US 20090099885A1 · Sung et al. · 2009 [cited by applicant]
US 20100064362A1 · Materna et al. · 2010 [cited by applicant]
US 20130074188A1 · Giakouminakis et al. · 2013 [cited by applicant]
US 20130096980A1 · Basavapatna et al. · 2013 [cited by applicant]
US 20140075564A1 · Singla et al. · 2014 [cited by applicant]
US 20210152588A1 · Cruz · 2021 [cited by examiner]
US 20220159028A1 · Kumar et al. · 2022 [cited by applicant]
US 20230054912A1 · Dixit J et al. · 2023 [cited by applicant]
US 20230156030A1 · Bassi · 2023 [cited by examiner]
US 20230205891A1 · Yellapragada et al. · 2023 [cited by applicant]
US 20230216875A1 · Barbosa et al. · 2023 [cited by applicant]
US 20230336581A1 · Dunn et al. · 2023 [cited by applicant]
US 20240037245A1 · Kahan · 2024 [cited by examiner]
US 20240098107A1 · Al Jarri et al. · 2024 [cited by applicant]
US 20240333746A1 · Williams · 2024 [cited by examiner]
CN 107277021A · 2017 [cited by applicant]
CN 108011893A · 2018 [cited by applicant]
CN 108712396A · 2018 [cited by applicant]
CN 109167799A · 2019 [cited by applicant]
CN 109327461A · 2019 [cited by applicant]
CN 111199042A · 2020 [cited by applicant]
CN 107094158B · 2020 [cited by applicant]
CN 107239705B · 2020 [cited by applicant]
CN 111447224A · 2020 [cited by applicant]
CN 111695770A · 2020 [cited by applicant]
CN 112100545A · 2020 [cited by applicant]
CN 112257070A · 2021 [cited by applicant]
CN 108183895B · 2021 [cited by applicant]
CN 112491874A · 2021 [cited by applicant]
CN 112511512A · 2021 [cited by applicant]
CN 112532647A · 2021 [cited by applicant]
CN 111865981B · 2021 [cited by applicant]
CN 108737425B · 2021 [cited by applicant]
CN 112995207B · 2021 [cited by applicant]
CN 113468542A · 2021 [cited by applicant]
CN 113542275A · 2021 [cited by applicant]
CN 113392409B · 2021 [cited by applicant]
CN 110719300B · 2022 [cited by applicant]
CN 113238536B · 2022 [cited by applicant]
CN 112839047B · 2023 [cited by applicant]
CN 115408701B · 2023 [cited by applicant]
CN 115314276B · 2023 [cited by applicant]
CN 113949565B · 2023 [cited by applicant]
CN 114826726B · 2024 [cited by applicant]
CN 117473512B · 2024 [cited by applicant]
CN 116822804B · 2024 [cited by applicant]
JP 6023121B2 · 2016 [cited by applicant]
KR 100656351B1 · 2006 [cited by applicant]
KR 101022167B1 · 2011 [cited by applicant]
KR 101292640B1 · 2013 [cited by applicant]
KR 101310487B1 · 2013 [cited by applicant]
KR 102159292B1 · 2020 [cited by applicant]
KR 102439817B1 · 2022 [cited by applicant]
KR 102507464B1 · 2023 [cited by applicant]
WO 2014107104A1 · 2014 [cited by applicant]
WO 2015127170A2 · 2015 [cited by applicant]
WO 2015134572A1 · 2015 [cited by applicant]
WO 2016186662A1 · 2016 [cited by applicant]
WO 2017059279A1 · 2017 [cited by applicant]
WO 2018049437A2 · 2018 [cited by applicant]