US 11,855,869 B2
Secure configuration of a network sensor on a network sensor host
John Brosnan, Galway (IE); Jeff Myers, Somerville, MA (US); Andriy Lyubka, Galway (IE); Darragh Delaney, Claremorris (IE); Erran Carey, Newtownabbey (GB); Martin Hutchings, Lisburn (GB); Ralph McTeggart, Belfast (GB); Ryan Williams, Belfast (GB); Daniel Skelton, Belfast (GB); Luke Coughlan, Galway (IE); Gianpaolo Tedesco, Seoul (KR); Luis Ramos Dos Santos Lopes, Galway (IE); Lars-Kristian Svenoy, Belfast (GB); Dan-Adrian Moinescu, Braila (RO); Niall Cochrane, Belfast (GB); Morgan Doyle, Kinvara (IE); and Sarah Addis, Belfast (GB)
Assigned to Rapid7, Inc., Boston, MA (US)
Filed by Rapid7, Inc., Boston, MA (US)
Filed on Jun. 29, 2022, as Appl. No. 17/852,754.
Application 17/852,754 is a continuation of application No. 17/462,100, filed on Aug. 31, 2021, granted, now 11,411,851.
Prior Publication US 2023/0064145 A1, Mar. 2, 2023
This patent is subject to a terminal disclaimer.
Int. Cl. G06F 9/445 (2018.01); G06F 9/455 (2018.01); H04L 41/046 (2022.01); H04L 41/0806 (2022.01); H04L 43/0894 (2022.01); H04L 9/40 (2022.01); H04L 43/028 (2022.01); H04L 69/16 (2022.01)
CPC H04L 43/0894 (2013.01) [G06F 9/445 (2013.01); G06F 9/455 (2013.01); H04L 43/028 (2013.01); H04L 63/14 (2013.01); H04L 69/16 (2013.01); H04L 41/046 (2013.01); H04L 41/0806 (2013.01)] 18 Claims
OG exemplary drawing
 
1. A method, comprising:
performing, by one or more processors that implement a network sensor deployment (NSD) server:
identifying a network sensor host in a network to deploy a network sensor;
sending a network sensor package and a token to the network sensor host, wherein the network sensor package is configured to:
obtain a certificate and a private key using the token,
establish a secure connection with the NSD server using the certificate and the private key, and
deploy the network sensor on the network sensor host based on configuration information received via the secure connection;
receiving, from the network sensor package and over the secure connection, information about the network sensor host comprising an enumeration of network interfaces on the network sensor host; and
sending, to the network sensor host and over the secure connection, configuration information used to configure the network sensor that specifies one of the network interfaces as a dedicated sensor interface of the network sensor.