IP Library › Granted Patent US 12,739,273
Granted Patent B2
US 12,739,273 · App. 18/968,550 · Granted Sep 15, 2026

Network asset matching across network penetration tests

Inventors: Robert George Alderman (Lafayette, CO); Levi Dyrek Payne (Woodlawn, VA); Chad Glinsky (Boulder, CO)
Assignee: Horizon 3 AI, Inc.
H04L63/1433H04L63/145H04L63/1466
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,739,273
App. No.
18/968,550
Granted
Sep 15, 2026
Kind
B2
Abstract

An autonomous pentesting agent may execute multiple autonomous pentests to gain access to network assets and obtain sets of attributes of the network assets and match network assets across the multiple autonomous pentests according to similarities between the sets of attributes. The autonomous pentesting agent may perform a network asset matching procedure to match one or more first network assets of a first set of network assets with one or more second network assets of a second set of network assets, the network asset matching procedure based on similarity scores between respective first sets of attributes of the first set of network assets and respective second sets of attributes of the second set of network assets. The autonomous pentesting agent may output a network assessment report indicating network security information associated with the network based on the network asset matching procedure.

Claims (61)

1 . A method for network asset matching, comprising:

executing a first autonomous penetration test of a network, wherein executing the first autonomous penetration test comprises:

gaining unauthorized access to a first set of network assets of the network; and

obtaining respective first sets of attributes for the first set of network assets;

executing a second autonomous penetration test of the network, wherein executing the second autonomous penetration test comprises:

gaining unauthorized access to a second set of network assets of the network; and

obtaining respective second sets of attributes for the second set of network assets;

performing a network asset matching procedure to match one or more first network assets of the first set of network assets with one or more second network assets of the second set of network assets, the network asset matching procedure being based at least in part on similarity scores between the respective first sets of attributes and the respective second sets of attributes, wherein the network asset matching procedure excludes a match between a first network asset of the first set of network assets and a second network asset of the second set of network assets from the match of the one or more first network assets with the one or more second network assets based at least in part on a similarity score between the first network asset and the second network asset being below a threshold; and

outputting a network assessment report indicating network security information associated with the network based at least in part on the network asset matching procedure.

2 . The method of claim 1 , further comprising:

assigning a respective weighting factor to each attribute of the respective first sets of attributes and of the respective second sets of attributes, wherein performing the network asset matching procedure comprises:

generating the similarity scores based at least in part on respective weighting factors.

3 . The method of claim 2 , wherein assigning the respective weighting factor to each attribute comprises:

assigning a first weighting factor to a first attribute; and

assigning a second weighting factor to a second attribute, wherein the first weighting factor is greater than the second weighting factor, and wherein the first attribute is static over time relative to the second attribute.

4 . The method of claim 2 , wherein the respective weighting factors are determined based at least in part on a configuration of the network and on one or more services running on the network.

5 . The method of claim 2 , wherein assigning the respective weighting factor comprises:

assigning a weighting factor to a composite attribute, the composite attribute comprising two or more attributes of the respective first sets of attributes and of the respective second sets of attributes.

6 . The method of claim 2 , further comprising:

receiving one or more user inputs that indicate the respective weighting factors, wherein assigning the respective weighting factor to each attribute is in accordance with the one or more user inputs.

7 . The method of claim 1 , wherein performing the network asset matching procedure comprises:

generating a matrix having a first dimension corresponding to the first set of network assets and having a second dimension corresponding to the second set of network assets, wherein respective entries of the matrix comprise the similarity scores between the respective first sets of attributes of each network asset along the first dimension and the respective second sets of attributes of each network asset along the second dimension.

8 . The method of claim 1 , wherein performing the network asset matching procedure comprises:

identifying a mismatch between a first attribute of the first network asset of the first set of network assets and a second attribute of the second network asset of the second set of network assets, wherein the match between the first network asset and the second network asset is excluded from the match of the one or more first network assets with the one or more second network assets based at least in part on the mismatch.

9 . The method of claim 1 , further comprising:

calculating the similarity scores based at least in part on:

calculating correlation factors between the respective first sets of attributes and the respective second sets of attributes;

weighting the correlation factors based at least in part on weighting factors of each respective attribute; and

calculating summations of the weighted correlation factors, wherein the similarity scores comprise the summations of the weighted correlation factors.

10 . The method of claim 1 , wherein outputting the network assessment report comprises:

outputting the network assessment report indicating the first set of network assets accessed during the first autonomous penetration test and the second set of network assets accessed during the second autonomous penetration test.

11 . The method of claim 10 , wherein the network assessment report further indicates the respective first sets of attributes of each network asset of the first set of network assets and the respective second sets of attributes of each network asset of the second set of network assets.

12 . The method of claim 1 , wherein the respective first sets of attributes, the respective second sets of attributes, or both comprise a domain name system (DNS) hostname, a hostname, a network basic input/output (NetBIOS) name, a media access control (MAC) address, an internet protocol (IP) address, machine identifier, a virtual host, a virtual machine identifier, a device fingerprint, a hardware fingerprint, a subnet, a lightweight directory access protocol (LDAP) host name, elastic compute cloud instance identifier, a resource identifier associated with cloud assets, a set of services, open ports, certificate names, secure sockets layer (SSL) certificates, a set of fileshares, a set of applications, application data, operating systems, flags, penetration test configuration attributes, or any combination thereof.

13 . The method of claim 1 , wherein the first set of network assets is at least partially different from the second set of network assets.

14 . The method of claim 1 , wherein the first set of network assets, the second set of network assets, or both comprise sets of hosts of the network.

15 . The method of claim 1 , wherein performing the network asset matching procedure is based at least in part on an assignment algorithm.

16 . An apparatus for network asset matching, comprising:

one or more memories storing processor-executable code; and

one or more processors coupled with the one or more memories and individually or collectively operable to execute the code to cause the apparatus to:

execute a first autonomous penetration test of a network, wherein, to execute the first autonomous penetration test, the one or more processors are individually or collectively operable to execute the code to cause the apparatus to:

gain unauthorized access to a first set of network assets of the network; and

obtain respective first sets of attributes for the first set of network assets;

execute a second autonomous penetration test of the network, wherein, to execute the second autonomous penetration test, the one or more processors are individually or collectively operable to execute the code to cause the apparatus to:

gain unauthorized access to a second set of network assets of the network; and

obtain respective second sets of attributes for the second set of network assets;

perform a network asset matching procedure to match one or more first network assets of the first set of network assets with one or more second network assets of the second set of network assets, the network asset matching procedure being based at least in part on similarity scores between the respective first sets of attributes and the respective second sets of attributes, wherein the network asset matching procedure excludes a match between a first network asset of the first set of network assets and a second network asset of the second set of network assets from the match of the one or more first network assets with the one or more second network assets based at least in part on a similarity score between the first network asset and the second network asset being below a threshold; and

output a network assessment report indicating network security information associated with the network based at least in part on the network asset matching procedure.

17 . The apparatus of claim 16 , wherein the one or more processors are individually or collectively further operable to execute the code to cause the apparatus to:

assign a respective weighting factor to each attribute of the respective first sets of attributes and of the respective second sets of attributes, wherein performing the network asset matching procedure comprises:

generate the similarity scores based at least in part on respective weighting factors.

18 . A non-transitory computer-readable medium storing code for network asset matching, the code comprising instructions executable by one or more processors to:

execute a first autonomous penetration test of a network, wherein the instructions to execute the first autonomous penetration test are executable to:

gain unauthorized access to a first set of network assets of the network; and

obtain respective first sets of attributes for the first set of network assets;

execute a second autonomous penetration test of the network, wherein the instructions to execute the second autonomous penetration test are executable to:

gain unauthorized access to a second set of network assets of the network; and

obtain respective second sets of attributes for the second set of network assets;

perform a network asset matching procedure to match one or more first network assets of the first set of network assets with one or more second network assets of the second set of network assets, the network asset matching procedure being based at least in part on similarity scores between the respective first sets of attributes and the respective second sets of attributes, wherein the network asset matching procedure excludes a match between a first network asset of the first set of network assets and a second network asset of the second set of network assets from the match of the one or more first network assets with the one or more second network assets based at least in part on a similarity score between the first network asset and the second network asset being below a threshold; and

output a network assessment report indicating network security information associated with the network based at least in part on the network asset matching procedure.

19 . The non-transitory computer-readable medium of claim 18 , wherein the instructions to perform the network asset matching procedure are executable by the one or more processors to:

generate a matrix having a first dimension corresponding to the first set of network assets and having a second dimension corresponding to the second set of network assets, wherein respective entries of the matrix comprise the similarity scores between the respective first sets of attributes of each network asset along the first dimension and the respective second sets of attributes of each network asset along the second dimension.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 6, 2024
From: ALDERMAN, ROBERT GEORGE; PAYNE, LEVI DYREK; GLINSKY, CHAD
To: HORIZON 3 AI, INC.
Reel/Frame 069513/0596 →
Continuity (1)
Related Publication 20260156135A1 · Jun 4, 2026
References Cited (2)
US 10320624B1 · Roth · 2019 [cited by examiner]
US 11501013B1 · Das · 2022 [cited by examiner]