US2022368716A1PendingUtilityA1

Systems and methods for improved network vulnerability scanning and reporting

Assignee: TechSlayers LLCPriority: Feb 1, 2021Filed: Jul 19, 2022Published: Nov 17, 2022
Est. expiryFeb 1, 2041(~14.5 yrs left)· nominal 20-yr term from priority
G06F 18/214G06N 20/00H04L 43/50H04L 41/16H04L 43/045H04L 63/0272H04L 63/1416H04L 63/1425H04L 63/1408H04L 41/40H04L 63/1433G06K 9/6256
54
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Vulnerability scanning systems and methods are provided for automatically performing the steps necessary for compliance testing and auditing of an organization's systems, and determining security posture in real time. A Machine-in-the-Middle Microserviced Security Engine (MiMMSE) is provided that provides one-way traffic for command execution and security improvement, management for automating services in OS containers, the elimination of multiple connections to services per client to give users more control of network access, total data destruction after each run to reduce attack surfaces, encryption over container services, reverse tunnel or VPN traffic between pods, clusters, and other separated networks, and machine learning (e.g., neural-network-based) maps for command execution order.

Claims

exact text as granted — not AI-modified
1 . A system for performing penetration testing, comprising:
 a customer network comprising a plurality of devices;   a server providing a user interface that prompts a customer to provide a request for vulnerability testing;   a management system to create an on-demand, temporary, zero-trust testing environment including one or more testing kits selected based on one or more attributes of the customer network and the requested vulnerability testing, the testing kits including one or more commands;   wherein the zero-trust testing environment is configured to: execute the commands within each test kit against the customer network; transfer, over a one-way connection, results of the executed testing kits to the server; and provide a user interface that allows the customer to download the results.   
     
     
         2 . The system of  claim 1 , wherein the customer network includes at least one virtual private network (VPN) providing access to the plurality of devices. 
     
     
         3 . The system of  claim 1 , wherein the zero-trust testing environment executes the commands in an order that is adaptive based on the result of at least one previous command. 
     
     
         4 . The system of  claim 2 , wherein the zero-trust testing environment executes the commands in an order determined by a previously trained machine learning model. 
     
     
         5 . The system of  claim 1 , wherein the zero-trust testing environment uses distro-less containers to execute the commands. 
     
     
         6 . The system of  claim 1 , wherein the zero-trust testing environment is destroyed based on a predetermined schedule. 
     
     
         7 . A method for performing penetration testing, comprising:
 providing a customer network comprising a plurality of devices;   prompting, via a server providing a user interface, a customer to provide a request for vulnerability testing;   creating, with a management system, an on-demand, temporary, zero-trust testing environment including one or more testing kits selected based on one or more attributes of the customer network and the requested vulnerability testing, the testing kits including one or more commands;   executing the commands within each test kit against the customer network;   transferring, over a one-way connection, results of the executed testing kits to the server; and   allowing the customer to download the results in an encrypted form.   
     
     
         8 . The method of  claim 7 , wherein the customer network includes at least one virtual private network (VPN) providing access to the plurality of devices. 
     
     
         9 . The method of  claim 7 , wherein the zero-trust testing environment is configured to execute the commands in an order that is adaptive based on the result of at least one previous command. 
     
     
         10 . The method of  claim 9 , wherein the zero-trust testing environment executes the commands in an order determined by a previously trained machine learning model. 
     
     
         11 . The method of  claim 9 , wherein the zero-trust testing environment uses distro-less containers to execute the commands. 
     
     
         12 . The method of  claim 7 , wherein the zero-trust testing environment is destroyed based on a predetermined schedule. 
     
     
         13 . A machine-in-the-middle microserviced security engine comprising:
 a server providing a user interface that prompts a customer to provide a request for vulnerability testing of a customer network comprising a plurality of devices;   a management system to create an on-demand, temporary, zero-trust testing environment including one or more testing kits selected based on one or more attributes of the customer network and the requested vulnerability testing, the testing kits including one or more commands;   wherein the zero-trust testing environment is configured to: execute the commands within each test kit against the customer network; transfer, over a one-way connection, results of the executed testing kits to the server; and provide a user interface that allows the customer to download the results in an encrypted form.   
     
     
         14 . The security engine of  claim 13 , including at least one virtual private network (VPN) providing access to the plurality of devices. 
     
     
         15 . The security engine of  claim 13 , wherein the zero-trust testing environment executes the commands in an order that is adaptive based on the result of at least one previous command. 
     
     
         16 . The security engine of  claim 15 , wherein the zero-trust testing environment executes the commands in an order determined by a previously trained machine learning model. 
     
     
         17 . The security engine of  claim 13 , wherein the zero-trust testing environment uses distro-less containers to execute the commands. 
     
     
         18 . The security engine of  claim 13 , wherein the zero-trust testing environment is destroyed based on a predetermined schedule.

Join the waitlist — get patent alerts

Track US2022368716A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.