IP Library Patent Application 18765262
Patent Application
App. No. 18/765,262

AUTOMATED INTERNET-SCALE WEB APPLICATION VULNERABILITY SCANNING AND ENHANCED SECURITY PROFILING

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
18/765,262
Filed
Jul 7, 2024
Art Unit
2497
USPC
726/22
Abstract

A system and methods for automated Internet-scale vulnerability scanning and enhanced security profiling. The system utilizes a scheduler that directs web crawlers to scan domains retrieved from a database, interact with the contents of any retrieved web pages using fuzz testing, index and store the results of the scan, and provide the indexed results via an API for inclusion in cybersecurity scoring.

Claims (57)

1 . A computing system for automated Internet-scale vulnerability scanning and enhanced security profiling, the computing system comprising:

one or more hardware processors configured for:

performing a reconnaissance search using a cyber-physical graph, the cyber-physical graph comprising nodes representing entities and edges representing relationships between the entities by:

retrieving a plurality of domains, the plurality of domains being associated with an organization;

requesting a web page associated with at least one of the retrieved domains;

receiving a response to the request from a web server;

providing input to an interactive element of the web page;

receiving a result from the web server, the result being based on the provided input; and

indexing the result; and

applying some or all of the results of the reconnaissance search to the cyber-physical graph to create a cybersecurity profile of the organization associated with the cyber-physical graph by:

identifying a plurality of cybersecurity risks associated with the organization, the cybersecurity risks being based on the indexed results;

determining a business impact for each cybersecurity risk identified;

assigning a network resilience rating to the organization; and

determining a functional cybersecurity score for the organization based at least on the network resilience rating.

2 . The system of claim 1 , wherein the input is generated by a fuzzer.

3 . A method for automated Internet-scale vulnerability scanning and enhanced security profiling, comprising the steps of:

performing a reconnaissance search using a cyber-physical graph, the cyber-physical graph comprising nodes representing entities and edges representing relationships between the entities by:

retrieving a plurality of domains, the plurality of domains being associated with an organization;

requesting a web page associated with at least one of the retrieved domains;

receiving a response to the request from a web server;

providing input to an interactive element of the web page;

receiving a result from the web server, the result being based on the provided input; and

indexing the result; and

applying some or all of the results of the reconnaissance search to the cyber-physical graph to create a cybersecurity profile of the organization associated with the cyber-physical graph by:

identifying a plurality of cybersecurity risks associated with the organization, the cybersecurity risks being based on the indexed results;

determining a business impact for each cybersecurity risk identified;

assigning a network resilience rating to the organization; and

determining a functional cybersecurity score for the organization based at least on the network resilience rating.

4 . The method of claim 3 , wherein the input is generated by a fuzzer.

5 . A system for automated Internet-scale vulnerability scanning and enhanced security profiling, comprising one or more computers with executable instructions that, when executed, cause the system to:

perform a reconnaissance search using a cyber-physical graph, the cyber-physical graph comprising nodes representing entities and edges representing relationships between the entities by:

retrieving a plurality of domains, the plurality of domains being associated with an organization;

requesting a web page associated with at least one of the retrieved domains;

receiving a response to the request from a web server;

providing input to an interactive element of the web page;

receiving a result from the web server, the result being based on the provided input; and

indexing the result; and

apply some or all of the results of the reconnaissance search to the cyber-physical graph to create a cybersecurity profile of the organization associated with the cyber-physical graph by:

identifying a plurality of cybersecurity risks associated with the organization, the cybersecurity risks being based on the indexed results;

determining a business impact for each cybersecurity risk identified;

assigning a network resilience rating to the organization; and

determining a functional cybersecurity score for the organization based at least on the network resilience rating.

6 . The system of claim 5 , wherein the input is generated by a fuzzer.

7 . Non-transitory, computer-readable storage media having computer executable instructions embodied thereon that, when executed by one or more processors of a computing system for automated Internet-scale vulnerability scanning and enhanced security profiling, causes the computing system to:

perform a reconnaissance search using a cyber-physical graph, the cyber-physical graph comprising nodes representing entities and edges representing relationships between the entities by:

retrieving a plurality of domains, the plurality of domains being associated with an organization;

requesting a web page associated with at least one of the retrieved domains;

receiving a response to the request from a web server;

providing input to an interactive element of the web page;

receiving a result from the web server, the result being based on the provided input; and

indexing the result; and

apply some or all of the results of the reconnaissance search to the cyber-physical graph to create a cybersecurity profile of the organization associated with the cyber-physical graph by:

identifying a plurality of cybersecurity risks associated with the organization, the cybersecurity risks being based on the indexed results;

determining a business impact for each cybersecurity risk identified;

assigning a network resilience rating to the organization; and

determining a functional cybersecurity score for the organization based at least on the network resilience rating.

8 . The media of claim 7 , wherein the input is generated by a fuzzer.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Aug 13, 2024
From: CRABTREE, JASON; KELLEY, RICHARD; SELLERS, ANDREW; CACERES, ALEJANDRO; FORNARA, TOMAS
To: QOMPLX, INC.
Reel/Frame 068272/0705 →