Patents Assigned to RAPID7, INC.
-
Patent number: 12719912Abstract: Various embodiments include systems and methods of implementing automated assessment scheduling. A particular automated assessment may be automatically performed based at least in part on an assessment configuration and scan engine resource(s) of an organization. Based at least in part on performance of the particular automated assessment, a scan engine utilization assessment may be performed to determine a scan engine utilization value that represents utilization of the scan engine resource(s) with respect to resource requirements that are based at least in part on the set of attributes of the assessment configuration. Based at least in part on the scan engine utilization assessment, a particular resource utilization recommendation may be generated. The particular resource utilization recommendation may correspond to a first resource utilization recommendation to allocate additional scan engine resources or a second resource utilization recommendation to allocate fewer scan engine resources.Type: GrantFiled: July 16, 2024Date of Patent: August 25, 2026Assignee: Rapid7, Inc.Inventors: Paul Miseiko, James Cancilla
-
Patent number: 12717568Abstract: An access policy analysis system is disclosed, configured to analyze access policies defined in a computer network to generate effective access data (EAD) for individual pairs of principals and resources in the network, and performing a differential update process to selectively refresh portions of the EAD that are affected by later changes of the access policies. In embodiments, the update process also updates the EAD for principals and resources that exceed a staleness limit (e.g. principals and resources that have not been updated for a specified period of time). The update process is managed via a management interface that allows users to view, control, and configure the update process, and examine various metrics data associated with the update process.Type: GrantFiled: April 18, 2023Date of Patent: August 25, 2026Assignee: Rapid7, Inc.Inventors: Nadia Mounzih, Joseph Buell, Val Komarov
-
Patent number: 12719908Abstract: As an example, a server may determine a first set of assets using an internal scan engine, determine a second set of assets using an external scan engine, perform a proxy de-obfuscation process to determine a third set of assets, and combine them to create a set of combined assets that includes records of multiple hosts in an enterprise network. The server performs a correlation process using the set of combined assets to create a set of correlated assets by comparing attributes of an asset with other attributes of other assets to reduce duplicate entries. An artificial intelligence may be used to determine a risk of attack for individual assets in the set of correlated assets and to suggest a solution to address the risk of attack for at least one correlated asset in the set of correlated assets.Type: GrantFiled: March 1, 2023Date of Patent: August 25, 2026Assignee: Rapid7, Inc.Inventor: Paul Deardorff
-
Patent number: 12719858Abstract: An automated login framework for dynamic application security testing is disclosed. A web application executing on a computing device is accessed and an automated login framework (ALF) is injected into an onload event of a web browser associated with the web application. The ALF is then accessed with a credential associated with the web application. A login page associated with application is identified by matching links or buttons with a user-defined regular expression and a user-defined wordlist. Then, a login form in the login page is detected by executing a signature technique, a dictionary technique, and a multistep signature technique. The login form is populated using the credential and submitted for authentication, and a status with a confidence score is received indicating whether the authentication was successful or failed.Type: GrantFiled: September 4, 2024Date of Patent: August 25, 2026Assignee: Rapid7, Inc.Inventors: Jijo John, Dan Kuykendall
-
Patent number: 12695782Abstract: Various embodiments include systems and methods of implementing vulnerability check synchronization. Vulnerability check synchronization may occur between computing resources at multiple different locations including a first location and a second location. Custom vulnerability check information associated with a particular security vulnerability may be received via a security console user interface that is located at the first location. A selection may be received, via the security console user interface, of a particular distributed engine to be utilized to perform a scan of one or more assets based at least in part on the custom vulnerability check information. Responsive to a determination to initiate the scan of the one or more assets, transfer of the custom vulnerability check information to the particular distributed engine via one or more networks may be automatically initiated.Type: GrantFiled: December 9, 2024Date of Patent: July 28, 2026Assignee: Rapid7, Inc.Inventor: Jack Steers
-
Patent number: 12689637Abstract: An entity tracking system and method for a computer network employs proactive data collection and enrichment driven by configurable rules and workflows responsive to the discovery of new entities, changes to existing entities, and specifics about the entities' attributes. The data collection is used in conjunction with graph technologies to map interactions and relationships between various entities interacting in the computer environment and deduce interactions and relationships between the entities. Machine learning techniques further identify, group or categorize entities and identify patterns which are indicative of anomalies that might be due to nefarious actions or compromised security.Type: GrantFiled: May 6, 2021Date of Patent: July 21, 2026Assignee: Rapid7, Inc.Inventors: Kenneth Allen Rogers, Allen D. Hadden, Craig Roberts, Hugh Pyle
-
Patent number: 12689662Abstract: A script generation service is disclosed that parses a security policy to identify data objects controlled by the policy and generate data collection commands in a shell scripting language to collect states of the data objects from machines. In embodiments, the security policy is written in a policy specification language that allows data objects to be specified using references to object entities, variables, other objects, transformation functions, and/or state filters. The generation service is capable of resolving these types of references either during the script generation process or using commands in the generated script. In embodiments, the generated scripts are pushed to data collection agents executing on machines in a monitored network, which can execute the scripts as authenticated processes to collect and return machine state data about the machines. The machine state data is then assessed to identify possible security policy violations.Type: GrantFiled: August 20, 2024Date of Patent: July 21, 2026Assignee: Rapid7, Inc.Inventor: Mitesh Lad
-
Patent number: 12682080Abstract: Some embodiments provide techniques for generating common vulnerability scoring system (CVSS) vectors for vulnerabilities to use in scanning a computing environment for vulnerabilities. The techniques involve obtaining a textual description of a vulnerability; generating inputs for a plurality of ML models using the textual description of the vulnerability; providing the inputs to the plurality of ML models to obtain outputs indicating values of CVSS risk metrics; and storing the values of the CVSS risk metrics indicated by the outputs of the plurality of ML models in a vector to obtain the CVSS vector for the vulnerability.Type: GrantFiled: October 30, 2024Date of Patent: July 14, 2026Assignee: Rapid7, Inc.Inventors: Gudlaugur Finnbogason, Stuart Millar
-
Patent number: 12683981Abstract: Various embodiments include systems and methods to implement profiling of cyberattacks, where the profiling is performed by a security platform. Profiling of cyberattacks may be performed by determining sets of access attempts that are associated with one or more cyberattacks, where the sets of access attempts are used to profile subsequent access attempts. The security platform may determine whether a given set of access attempts is similar to previous sets of access attempts determined to be cyberattacks using various techniques, including set similarity, set overlap coefficients, or equality of hash data associated with different sets of access attempts.Type: GrantFiled: June 28, 2022Date of Patent: July 14, 2026Assignee: Rapid7, Inc.Inventors: Erick Jason Galinkin, Curtis Paul Barnard
-
Patent number: 12634329Abstract: Various embodiments include systems and methods to implement network scanner timeouts based at least in part on historical network conditions. The implementing comprises initiating, using one or more network scanners and according to a first set of timeout parameters, a first security assessment of one or more scan targets in a network, wherein the first set of timeout parameters comprises a first initial round trip time (RTT)-timeout parameter value to which a dynamic RTT-timeout value is initially set. The implementing comprises determining a first set of RTT statistics for the first security assessment. The implementing comprises determining, based at least in part on the first set of RTT statistics, a second set of timeout parameters for a second security assessment of the one or more scan targets. The implementing comprises initiating, according to the second set of timeout parameters, the second security assessment of the one or more scan targets.Type: GrantFiled: July 17, 2024Date of Patent: May 19, 2026Assignee: Rapid7, Inc.Inventors: Emmett Kelly, Paul Miseiko
-
Patent number: 12634319Abstract: A software agent executing on a computing device receives a request from a client to provide data associated with neighboring devices to the computing device. The client includes a scan engine to perform a network scan of a network that includes the computing device. The software agent accesses device data in a cache of an operating system command, determines, based on the device data, an identifier associated with each device that is neighboring the computing device, converts the device data into a standardized format to create neighboring device data, and sends the neighboring device data to the client.Type: GrantFiled: September 12, 2024Date of Patent: May 19, 2026Assignee: Rapid7, Inc.Inventors: Emmett Kelly, Ross Kirk
-
Patent number: 12632436Abstract: Systems and methods are disclosed to implement an adaptive indexing system for a data store that dynamically selects which query keys to include in the index based on observed query statistics of the data store. In embodiments, the system monitors the query statistics to determine when a query key exceeds a usage threshold, and then dynamically adds the query key to the index. The addition causes subsequent data to be indexed by the query key, and may also cause a reindexing of existing data in the data store, for example a recent window of data selected based on the query statistics. In embodiments, the index is repeatedly modified to continuously adapt the index to changing querying patterns. Advantageously, the disclosed system autonomously selects a small set of the most frequently used query keys in the index, which limits the size of the index without sacrificing query performance.Type: GrantFiled: August 20, 2024Date of Patent: May 19, 2026Assignee: Rapid7, Inc.Inventors: David Tracey, Seamus Cawley
-
Patent number: 12632448Abstract: A SQL database system is disclosed for reading and writing a non-SQL document store using SQL. The database system includes a SQL query engine configured to use different types of dynamically loadable connectors adapted to communicate with the non-SQL document store via its data access interface. The connectors may include a first connector that treats data within an individual document in the document store as multiple table rows, and a second connector that treats individual documents as individual table rows. In some embodiments, both types of document access modes may be implemented by a single multi-modal connector. In some embodiments, the connector may enable a table to be stored across multiple documents and provide the document identifier of the documents as an attribute of the table. Advantageously, by allowing multiple rows to be stored in individual documents, a table can be stored using less storage space and accessed more efficiently.Type: GrantFiled: August 26, 2021Date of Patent: May 19, 2026Assignee: Rapid7, Inc.Inventor: Austin Lee
-
Patent number: 12634307Abstract: Systems and methods are disclosed to implement a network data interpretation pipeline to recognize machine operations (MOs) and machine activities (MAs) from network traffic data observed in a monitored network. In embodiments, a MO recognition engine is implemented in the network to recognize MOs from network sensor events (NSEs) based on defined recognition patterns. The MOs and any unrecognized NSEs are uploaded to a network monitoring system, where they are further analyzed by a MA recognition engine to recognize higher-level machine activities performed by machines. The NSEs, MOs, and MAs are used by the network monitoring system to implement a variety of security threat detection processes. Advantageously, the pipeline may be used to add rich contextual information about the raw network data to facilitate security threat detection processes. Additionally, the MOs and MAs can be used to present the raw network data in a variety of intuitive user interfaces.Type: GrantFiled: July 16, 2024Date of Patent: May 19, 2026Assignee: Rapid7, Inc.Inventor: Luis Ramos dos Santos Lopes
-
Patent number: 12632585Abstract: Various embodiments include systems and methods to implement a security platform providing query transformations and layered filtering. Security data associated with a client deployment of assets may be determined and analyzed for identifying security vulnerabilities. The security platform may support an application programming interface that provides a flexible query format that allows multiple layers of filtering logic at various layers of a frontend query. The filtering logic may be translated into a backend query format used to retrieve security data specified by the frontend query.Type: GrantFiled: September 7, 2022Date of Patent: May 19, 2026Assignee: Rapid7, Inc.Inventors: Jessica Koe, Alex Gurvets, Michael Huffman, Rahul Monga, Afrin Subair, Courtney Wood
-
Patent number: 12614138Abstract: Various embodiments include systems and methods of assessing vendor risk. One or more sets of IP address(es) associated with one or more vendors is identified. Risk data related to the set(s) of IP address(es) is obtained using internet telemetry data. Based at least in part on the risk data, security risk level(s) are determined for the vendor(s). Some embodiments include systems and methods of implementing a vendor-based risk posture assessment of an organization. The vendor-based risk posture assessment may be based at least in part on one or more security risk levels determined for the vendor(s) of the organization.Type: GrantFiled: June 28, 2021Date of Patent: April 28, 2026Assignee: Rapid7, Inc.Inventors: Wah-Kwan Lin, Harley Ray Rogers
-
Patent number: 12615281Abstract: Disclosed herein are systems, methods, and processes for a machine learned alert triaging classification (ATC) system that uses machine learning techniques to generate an alert triage classification model that can be trained and deployed in modern security operation centers to optimize alert triaging and cyber threat classification. A training dataset of classified records is obtained. Each classified record in the training dataset includes detection characteristics data of a set of machines and threat classification results produced by performing alert triage classification of detection messages associated with the set of machines. An ATC model is trained using the training dataset according to a machine learning technique. The training tunes the ATC model to classify, based on at least the detection characteristics data, a new detection message associated with a machine from the set of machines as a threat or as not a threat.Type: GrantFiled: August 6, 2024Date of Patent: April 28, 2026Assignee: Rapid7, Inc.Inventor: Carlos Manuel Pastor Sánchez
-
Patent number: 12615294Abstract: Embodiments disclose a honeyrepo implemented in a cybersecurity computing environment. A honey repository is configured for inclusion in a source control system by a detection and response server that is communicatively coupled to a continuous integration system that accesses a shared repository and has access to individual repositories of the source control system by generating a honey repository configuration package that includes decoy metadata to entice an attacker to initiate a request to access the honey repository. The honey repository configuration package that includes the decoy metadata is transmitted to the source control system to generate the honey repository and access to the source control system is monitored at the detection and response server. If an attacker initiates the request to access the honey repository, access is disabled for the attacker to the individual repositories of the source control system and the shared repository managed by the continuous integration system.Type: GrantFiled: October 12, 2022Date of Patent: April 28, 2026Assignee: Rapid7, Inc.Inventors: Owen Stewart, Ashwin Anand
-
Patent number: 12609947Abstract: Various embodiments include systems and methods pertaining to a security service platform that detects security threats based on a security service that operates on structurally deduplicated network data. The security service platform, based on using the structure, or data model, of data being deduplicated, generates structurally deduplicated event data that is more compact than traditionally compressed data or traditionally deduplicated data stored in a structured data format. The security service may perform a security analysis that includes rule matching to detect threats to a network, where the rule matching operates on the structurally deduplicated data.Type: GrantFiled: May 30, 2023Date of Patent: April 21, 2026Assignee: Rapid7, Inc.Inventors: Luke Coughlan, Gianni Tedesco, Morgan Nally, Sai Krishna Lakshminarayanan
-
Patent number: 12592956Abstract: Various embodiments include systems and methods to implement processing of web content for vulnerability assessments. A plurality of documents comprising web content may be obtained from multiple different web sources, and the documents may be parsed to determine a set of discrete document chunks. Parsing the documents includes determining whether a document satisfies a segmentation condition for segmenting the document into multiple discrete document chunks using a named-entity recognition system configured to segment the document based at least in part on a vulnerability identification. The discrete document chunks may be stored in a database, where vulnerability information is indexed such that each respective entry in the database corresponds to a respective vulnerability identification and a respective discrete document chunk.Type: GrantFiled: June 25, 2024Date of Patent: March 31, 2026Assignee: Rapid7, Inc.Inventor: Erick Galinkin