IP Library › Granted Patent US 12,730,648
Granted Patent B2
US 12,730,648 · App. 18/450,259 · Granted Sep 8, 2026

Modular network scan orchestration

Inventors: Mark Jonathan Austin, II (Greensboro, NC); Asheley Shawn Lee (Collegeville, PA); Kelley Arthur (Madison, GA)
Assignee: Wells Fargo Bank, N.A.
G06F9/3867
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,730,648
App. No.
18/450,259
Granted
Sep 8, 2026
Kind
B2
Abstract

An example of the modular outpost pipeline can make complex branching decisions at stages along the pipeline based on attributes of the data already gathered. This allows modifications to scans in progress within the outpost-based pipeline, and near-real-time sharing of specific scan data to external tools. The logic necessary can be implemented in any outpost pipeline stage but is preferentially accomplished by using secondary orchestrator stages inserted after the pipeline stages where relevant data has been acquired.

Claims (32)

1 . A modular outpost system comprising:

a server; and

a memory with instructions which, when executed by a processor, cause the system to create a modular outpost engine having:

a primary orchestrator module configured to generate an initial pipeline for a scan or set of scans, wherein the initial pipeline is based upon a static target list of addresses;

a plurality of secondary orchestrator modules;

a plurality of scan stages; and

an avoid list that is used by the primary orchestrator module to avoid certain target addresses during network scanning, wherein the avoid list is hierarchical such that multiple avoid list entries for a single target address are combined to create a composite avoid entry;

wherein the primary orchestrator module is configured to randomize addresses across the static target list to minimize impact to bandwidth within contiguous network segments, minimize load on network devices, and reduce false alarms in Intrusion Detection systems;

wherein the primary orchestrator module conducts a covering search for a target address in the static target list against the avoid list that returns nodes that cover the target address;

wherein avoid list entries from the returned nodes are subdivided by scan stage and merged through delegation; and

wherein the plurality of secondary orchestrator modules is associated with the plurality of scan stages and dynamically defines a modular outpost pipeline.

2 . The modular outpost system of claim 1 , wherein the initial pipeline is further based upon one or more of the group consisting of: ranges and Classless Inter-Domain Routing-formatted addresses.

3 . The modular outpost system of claim 1 , wherein the modular outpost pipeline is a single pipeline.

4 . The modular outpost system of claim 1 , wherein the modular outpost pipeline is a branching pipeline.

5 . The modular outpost system of claim 1 , wherein at least some of the plurality of secondary orchestrator modules and the plurality of scan stages are configured to publish specific attributes from scan results of hierarchical topics.

6 . The modular outpost system of claim 5 , wherein at least some of the plurality of secondary orchestrator modules and the plurality of scan stages are subscribers to the specific attributes from the scan results of hierarchical topics.

7 . The modular outpost system of claim 1 , further comprising a user device coupled to the server and the modular outpost engine via a network.

8 . The modular outpost system of claim 7 , wherein the user device is usable by an operator to set or modify the modular outpost pipeline.

9 . The modular outpost system of claim 1 , wherein the avoid list comprises a list of targets that react adversely to being scanned and can be configured to require wholesale avoidance of a given target or stage, selective avoidance of some stages, configuration of a single address, or configuration of multiple addresses.

10 . The modular outpost system of claim 9 , wherein the avoid list is modular such that adding new stages to the plurality of scan stages does not require changes to the primary orchestrator module, the plurality of secondary orchestrator modules, or existing ones of the plurality of scan stages.

11 . A method comprising:

assigning a pipeline for scanning a plurality of targets at a primary orchestrator module based upon a static target list of IP addresses;

generating an avoid list that is used by the primary orchestrator module to avoid certain target addresses during network scanning, wherein the avoid list is hierarchical such that multiple avoid list entries for a single target address are combined to create a composite avoid entry;

scanning the plurality of targets at a plurality of stages as defined by the pipeline, wherein the primary orchestrator module is configured to randomize addresses across the static target list to minimize impact to bandwidth within contiguous network segments, minimize load on network devices, and reduce false alarms in Intrusion Detection systems, wherein the primary orchestrator module conducts a covering search for a target address in the static target list against the avoid list that returns nodes that cover the target address, and wherein avoid list entries from the returned nodes are subdivided by scan stage and merged through delegation; and

modifying the pipeline at one of a plurality of secondary orchestrator modules.

12 . The method of claim 11 , wherein modifying the pipeline comprises updating a single pipeline.

13 . The method of claim 11 , wherein modifying the pipeline comprises updating a branching pipeline.

14 . The method of claim 11 , further comprising:

publishing, by at least some of the plurality of secondary orchestrator modules and the plurality of stages, specific attributes from scan results of hierarchical topics; and

obtaining the specific attributes from the scan results of hierarchical topics by others of the plurality of secondary orchestrator modules and the plurality of stages.

15 . The method of claim 11 , wherein the avoid list comprises a list of targets that react adversely to being scanned and can be configured to require wholesale avoidance of a given target or stage, selective avoidance of some stages, configuration of a single address, or configuration of multiple addresses.

16 . The method of claim 11 , wherein the avoid list is modular such that adding new stages to the plurality of stages does not require changes to the primary orchestrator module, the plurality of secondary orchestrator modules, or existing ones of the plurality of stages.

Assignments (2)
STATEMENT OF CHANGE OF ADDRESS OF ASSIGNEE Recorded Jun 17, 2025
From: WELLS FARGO BANK, N.A.
To: WELLS FARGO BANK, N.A.
Reel/Frame 071644/0971 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 2, 2023
From: AUSTIN, MARK JONATHAN, II; LEE, ASHELEY SHAWN; ARTHUR, KELLEY
To: WELLS FARGO BANK, N.A.
Reel/Frame 065440/0689 →
Continuity (1)
Related Publication 20250060969A1 · Feb 20, 2025
References Cited (54)
US 6205552B1 · Fudge · 2001 [cited by examiner]
US 8095961B1 · Morley · 2012 [cited by examiner]
US 8644314B2 · Suri · 2014 [cited by examiner]
US 10565372B1 · Stickle · 2020 [cited by examiner]
US 10628914B1 · Donais · 2020 [cited by examiner]
US 10873593B2 · Gandham · 2020 [cited by examiner]
US 11150895B1 · Wall · 2021 [cited by examiner]
US 11500673B2 · Taher · 2022 [cited by examiner]
US 11698915B1 · Yao · 2023 [cited by examiner]
US 12177316B1 · Glozman · 2024 [cited by examiner]
US 12204943B1 · Yembari · 2025 [cited by examiner]
US 20030212779A1 · Boyter · 2003 [cited by examiner]
US 20040015728A1 · Cole · 2004 [cited by examiner]
US 20050138413A1 · Lippmann · 2005 [cited by examiner]
US 20060085852A1 · Sima · 2006 [cited by examiner]
US 20080183688A1 · Chamdani · 2008 [cited by examiner]
US 20090038014A1 · Force · 2009 [cited by examiner]
US 20090254532A1 · Yang · 2009 [cited by examiner]
US 20110161965A1 · Im · 2011 [cited by examiner]
US 20140007241A1 · Gula · 2014 [cited by examiner]
US 20140165077A1 · Martinez Canedo · 2014 [cited by examiner]
US 20170324768A1 · Crabtree · 2017 [cited by examiner]
US 20180048521A1 · Nair · 2018 [cited by examiner]
US 20180191637A1 · Yang · 2018 [cited by examiner]
US 20180278626A1 · Kraning · 2018 [cited by examiner]
US 20180302500A1 · Zhang · 2018 [cited by examiner]
US 20180368007A1 · Cummings · 2018 [cited by examiner]
US 20200059480A1 · Junod · 2020 [cited by examiner]
US 20200104171A1 · Theimer · 2020 [cited by examiner]
US 20200104185A1 · Alvelda, VII · 2020 [cited by examiner]
US 20210014113A1 · Guim Bernat · 2021 [cited by examiner]
US 20210014133A1 · Maciocco · 2021 [cited by examiner]
US 20210124611A1 · Saillet · 2021 [cited by examiner]
US 20210191898A1 · Khan · 2021 [cited by examiner]
US 20220014418A1 · Gerö · 2022 [cited by examiner]
US 20220060498A1 · Head, Jr. · 2022 [cited by examiner]
US 20220255956A1 · Hodgman · 2022 [cited by examiner]
US 20230060348A1 · Huang · 2023 [cited by examiner]
US 20230104129A1 · Miriyala · 2023 [cited by examiner]
US 20230275909A1 · Shivamoggi · 2023 [cited by examiner]
US 20230362056A1 · Lucas · 2023 [cited by examiner]
US 20230393892A1 · Pasupathi · 2023 [cited by examiner]
US 20240385888A1 · Lee et al. · 2024 [cited by applicant]
US 20250060969A1 · Austin, II · 2025 [cited by examiner]
US 20250214614A1 · Urtasun · 2025 [cited by examiner]
US 20250244988A1 · Waichal · 2025 [cited by examiner]
US 20250247391A1 · Ladelsky Lellouch · 2025 [cited by examiner]
CN 103685279A · 2014 [cited by examiner]
CN 118250255A · 2024 [cited by examiner]
CN 118337520A · 2024 [cited by examiner]
RU 2679179C1 · 2019 [cited by examiner]
WO WO2013149174A1 · 2013 [cited by examiner]
WO WO2022061022A1 · 2022 [cited by examiner]
“15 Best Network Scanning Tools (Network and IP Scanner) of 2023,” Software Testing Help, available at https://www.softwaretestinghelp.com/network-scanning-tools/, accessed Aug. 15, 2023. [cited by applicant]