Outer Rim Archives
Archives · 2021 · 20210185073

Application (pre-grant publication)

TECHNIQUES FOR ANALYZING NETWORK VULNERABILITIES

Number
20210185073
Published
2021-06-17
Filed
2019-12-13
Assignee
DISNEY ENTERPRISES, INC.
Inventors
EWAIDA; Bashar H. M., BUTLER; Brent Chandler, FAITH; Arleena, RYAN; Joseph Tadashi
CPC
H04L63/1433; H04L63/1416; H04L63/20; H04L63/1425; H04L61/4511
Verdict
Set aside network vulnerability analysis, cybersecurity
Source
Google Patents · FreePatentsOnline

Abstract

One embodiment of the present disclosure sets forth a technique for analyzing network vulnerabilities. The technique includes determining an address for each target device included in a plurality of target devices; for each target device, assigning a port scanning task to an associated port scanning service, the port scanning task being associated with the target device via the address of the target device; for each port scanning task, receiving a port scanning result from the port scanning service assigned to the port scanning task, the port scanning result including a list of open ports for the target device associated with the port scanning task; for each open port included in each port scanning result, assigning a vulnerability scanning task to an associated vulnerability service; receiving a vulnerability scanning result for each vulnerability scanning task; and generating a report based on the port scanning results or the vulnerability scanning results.

Background

BACKGROUND OF THE INVENTION Field of the Invention

The various embodiments relate generally to security of computing devices and, more particularly, to techniques for analyzing network vulnerabilities. Description of the Related Art

Network connected computing devices, including devices providing content and/or services for other computing devices over networks, such as the Internet, are often subject to attack by hackers, malware, and/or the like. One common form of attack is based on port scanning. In a port scanning attack, a port scanning toolkit is used to systematically scan each of the network ports at a target IP address to determine which ports have a service that is open and listening on the port. Once a port is determined to be open, malware tools are used to initiate various attacks on the listening service to see if the listening service is susceptible to any vulnerability that may be used to gain unauthorized access to the computing device.

To help safeguard against these types of attacks, the information technology (IT) team of the owner of a computing system typically performs a port scanning “attack” on each computing device of the computing system to assess whether any of the computing devices has one or more vulnerabilities on one or more of the ports of the computing device. Once the one or more vulnerabilities are identified, the IT team can then follow up by closing ports that are unnecessarily open, installing patches and/or securit

Claims

1. A computer-implemented method for analyzing network vulnerabilities, the method comprising: determining an address for each target device included in a plurality of target devices; for each target device included in the plurality of target devices, assigning a port scanning task to an associated port scanning service, the port scanning task being associated with the target device via the address of the target device; for each port scanning task, receiving a port scanning result from the port scanning service assigned to the port scanning task, the port scanning result including a list of one or more open ports for the target device associated with the port scanning task; for each open port included in each port scanning result, assigning a vulnerability scanning task to an associated vulnerability service; receiving a vulnerability scanning result for each vulnerability scanning task; and generating a report based on at least one of the port scanning results or the vulnerability scanning results. || 11. A non-transitory computer-readable storage medium including instructions that, when executed by a processor, cause the processor to analyze network vulnerabilities by performing steps comprising: determining an IP address for each computing device included in a plurality of computing devices; for each computing device included in the plurality of computing devices, assigning a port scanning task to an associated port scanning service, the port scanning task being associated with the computing device via the IP address of the computing device; for each port scanning task, receiving a port scanning result from the port scanning service assigned to the port scanning task, the port scanning result including a list of one or more open ports for the computing device associated with the port scanning task; for each open port included in each port scanning result, assigning a vulnerability scanning task to an associated vulnerability service, the port scanning task being associated with the IP address of the computing device associated the port scanning result and the open port; receiving a vulnerability scanning result for each vulnerability scanning task; and generating a report based on the port scanning results, the vulnerability scanning results, or both the port scanning results and the vulnerability scanning results. || 16. A computing device, comprising: a memory; and a processor coupled to the memory; wherein the processor is configured to: determine an IP address for each target device included in a plurality of target devices; for each target device included in the plurality of target devices, assign a port scanning task to an associated port scanner, the port scanning task being associated with the target device via the IP address of the target device and a duration in which the port scanning task is to be completed; for each port scanning task, receiving a port scanning result from the port scanner assigned to the port scanning task, the port scanning result including a list of one or more open ports for the target device associated with the port scanning task; for each open port included in each port scanning result, assigning a vulnerability scanning task to an associated vulnerability scanner; receiving a vulnerability scanning result for each vulnerability scanning task; and generating a report based on at least one of the port scanning results, at least one of the vulnerability scanning results, or at least one of both the port scanning results and at least one of the vulnerability scanning results; wherein each port scanning task requests that the port scanner associated with the port scanning task perform a two-pass port scan, wherein a first pass identifies the open ports and a second pass identifies a service listening at each of the open ports.