Vendor Risk Assessment via Internet Telemetry

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing vendor risk assessment methods rely on independent certifications, compliance standards, and vendor disclosures, which are not always verifiable, independent, or objective, leading to inadequate assessment of vendor security posture.

Innovation Solution

The use of internet telemetry and fingerprinting to assess vendor risk by collecting and analyzing publicly available data on security exposures and honeypot connections, providing a verifiable, independent, and objective reflection of a vendor's security posture.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If conventional vendor risk assessment methods (independent certifications, compliance standards, vendor disclosures) are used, then vendor risk assessment can be performed, but the assessment lacks verifiability, independence, and objectivity

Engineering Contradiction:
Improveassessment accuracyVSAvoidverifiability and independence
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent introduces an intermediary automated scanning system that independently collects security telemetry data from vendors' public-facing assets. This intermediary system acts as an unbiased third party that objectively measures vendor security posture through automated scans of port accessibility, service vulnerabilities, and security configurations, eliminating reliance on self-reported vendor disclosures while maintaining assessment capability

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces manual, human-dependent assessment methods (credentials, surveys, certifications) with automated computational systems that continuously scan and analyze vendor infrastructure. This substitution uses algorithmic analysis of security telemetry data, port scanning results, and vulnerability assessments to objectively determine risk levels, improving both precision and reliability through consistent, repeatable measurements

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If automated internet scanning and telemetry collection are implemented, then verifiable and objective security assessment is achieved, but system complexity and resource requirements increase

Engineering Contradiction:
ImproveverifiabilityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a multi-functional automated scanning platform that performs multiple assessment tasks through unified systems: port scanning, service vulnerability detection, security configuration analysis, and continuous monitoring. This universal system consolidates what would otherwise require separate tools and processes, achieving verifiable security assessment while managing complexity through integrated architecture

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The scanning system is designed to autonomously execute security assessments without requiring extensive manual intervention. The system self-manages scan scheduling, data collection, analysis, and report generation, reducing operational complexity while maintaining high reliability through automated verification processes that continuously monitor vendor security postures

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12205059B1Vendor risk assessment using internet telemetry
Publication Date: 2025.01.21 RAPID7 INC
  • US12205059B1 patent drawing
  • US12205059B1 patent drawing
  • US12205059B1 patent drawing

AI summary

Various embodiments include systems and methods of assessing vendor risk. One or more sets of IP address(es) associated with one or more vendors is identified. Risk data related to the set(s) of IP address(es) is obtained using internet telemetry data. Based at least in part on the risk data, security risk level(s) are determined for the vendor(s). Some embodiments include systems and methods of implementing a vendor-based risk posture assessment of an organization. The vendor-based risk posture assessment may be based at least in part on one or more security risk levels determined for the vendor(s) of the organization.