Selectively Choosing Between Actual-Attack and Simulation/Evaluation for Validating a Vulnerability of a Network Node During Execution of a Penetration Testing Campaign
Patent №
US 11,206,282
Granted
2021-12-21
Filed 2020
Owner
XM CYBER LTD.
Lab
—
AI components
1
kr
Assignment
Recorded
Dataset
AIPD
2023_r1 edition
Application
17133683
Methods and systems for penetration testing of a networked system by a penetration testing system. In some embodiments, both active and passive validation methods are used during a single penetration testing campaign in a single networked system. In other embodiments, a first penetration testing campaign uses only active validation and a second penetration campaign uses only passive validation, where both campaigns are performed by a single penetration testing system in a single networked system. Node-by-node determination of whether to use active or passive validation can be based on expected extent and/or likelihood of damage from actually compromising a network node using active validation.
AI classification
Ownership
XM CYBER LTD.
assignment · 573880792
Assignors
GORODISSKY, BOAZ, ASHKENAZY, ADI, SEGAL, RONEN, LASSER, MENAHEM
On an employer assignment, the assignors are typically the inventors.