Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

114 results about "Vulnerability (computing)" patented technology

In computer security, a vulnerability is a weakness which can be exploited by a threat actor, such as an attacker, to perform unauthorized actions within a computer system. To exploit a vulnerability, an attacker must have at least one applicable tool or technique that can connect to a system weakness. In this frame, vulnerability is also known as the attack surface.

Systems and methods for advanced vulnerability detection and remediation within computer networks

A system for dynamic vulnerability detection and remediation is provided. The system includes a memory device and at least one processor coupled to the memory device. The at least one processor is programmed to: (a) store within a database an inventory of computer assets included within a computer ecosystem; (b) retrieve a vulnerability report including vulnerability definitions; (c) analyze the database to identify a potential vulnerability by comparing the computer assets stored within the database to the vulnerability definitions; (d) upon detecting the potential vulnerability, determine a service owner associated with the computer assets identified as being involved in the potential vulnerability; and (e) provide content to a user computing device associated with the service owner causing the user device to display a notification alert advising the service owner of the potential vulnerability and providing a remediation plan to address the potential vulnerability.
Owner:MASTERCARD INT INC

Threat policy fine-tuning based on the vulnerability of a subnet as a source of a malicious attack

An embodiment includes detecting by a system a request, responsive to the detecting of the request, computing by a Compute component of the system a plurality of internet protocol addresses in a subnet. The embodiment includes computing by an Analysis component of the system a threat metric for each of the plurality of internet protocol addresses. The embodiment includes determining by the Reputation component of the system a threat score for the subnet where the threat score is based on the threat metric. The embodiment also includes sending by the system the threat score representative of a vulnerability of the subnet as a source of a malicious attack.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Code Vulnerability Evaluator

A computing platform provides code vulnerability detection and evaluation. The computing platform may use a quantum graph categorizer along with quantum polymorphism execution channels to reduce false positives and provide optimized real-time vulnerability evaluation of code and code segments. The computing platform may use a hybrid approach comprising a mix of static and dynamic vulnerability validation and real-time parallel technique execution.
Owner:BANK OF AMERICA CORP

Mimicry intrusion detection method and system for household equipment

InactiveCN120896797APhysical realisationSecuring communicationPathPingNeuromorphic hardware
The invention relates to the technical field of household equipment intrusion detection, in particular to a mimicry intrusion detection method and system for household equipment, and the method comprises the steps: S0, starting credible verification and initialization; the method comprises the following steps: S1, carrying out multi-modal feature fusion processing; s2, disturbance type joint detection; s3, graded elastic response is carried out; s4, updating the self-adaptive model; s5, identifying a semantic exception instruction; and S6, neural morphology calculation is accelerated. According to the method, damage attack path dependence is detected through dynamic disturbance, multi-modal features are fused through a modal alignment mechanism, low-power-consumption acceleration is achieved through neuromorphic hardware, semantic anomaly instruction recognition and brain-like feedback offline optimization are combined, and the core problem that high-precision detection and high robustness cannot be considered at the same time in the prior art is solved; and particularly, real-time attacks and semantic spoofing attacks of unknown vulnerabilities are effectively resisted.
Owner:DONGGUAN LAIMSEN TECH BUILDING MATERIAL CO LTD

Edge computing and distributed zero-trust architecture system and data processing method

The invention discloses an edge computing and distributed zero-trust architecture system and a data processing method. The system comprises an edge computing device cluster, a distributed zero-trust control center, an edge security gateway and a block chain identity infrastructure. The edge computing node collects hardware state, vulnerability and behavior data through the terminal security agent module; the block chain identity infrastructure provides distributed identity identification and verifiable credential service; the edge security gateway executes data packet filtering and single packet authentication; and the distributed zero-trust control center calculates a real-time security coefficient and generates a differentiation strategy, and the log is synchronized to the alliance chain for evidence storage. According to the data processing method, security access is realized through access request initiation, single packet authentication, data acquisition, trust evaluation, strategy execution and log evidence storage. According to the method, the edge device state and distributed zero trust are deeply fused, the problems of incomplete identity authentication and static permission control in an edge scene are solved, and the security and traceability of an edge computing network are improved.
Owner:BEIJING ANCHEN INFORMATION TECHNOLOGY CO LTD

Proactive protection of computer networks against unexploited vulnerabilities

A server determines vulnerabilities associated with components of a computing device. The server determines attributes associated with individual vulnerabilities. The server determines a subset of the vulnerabilities that includes unexploited vulnerabilities. The server executes a machine learning model to predict a probability of an exploit being created for a particular unexploited vulnerability in the subset. The server sends to a device: information identifying the particular unexploited vulnerability, particular attributes associated with the particular unexploited vulnerability, and the probability of an exploit being created for the particular unexploited vulnerability.
Owner:RAPID7 INC

Systems and methods for determining current risk of cybersecurity vulnerabilities

Techniques for analyzing cybersecurity vulnerabilities in a computing environment, including: using at least one computer hardware processor to perform: (A) identifying a first cybersecurity vulnerability associated with a resource in the computing environment; (B) obtaining data related to one or more factors related to risk posed by the first cybersecurity vulnerability, the one or more factors including at least one factor indicative of a degree of current exploitation of the first cybersecurity vulnerability; (C) determining, using the obtained data, one or more factor weights for the one or more factors related to the risk posed by the first cybersecurity vulnerability; (D) determining a first score for the first cybersecurity vulnerability using the determined one or more factor weights; and (E) performing one or more security actions based on the determined first score for the first cybersecurity vulnerability.
Owner:RAPID7 INC

Threat model assistant for software development

The present disclosure of the various embodiments relates to using a large language model to assistant with the creation of secure code and / or the completion of threat modeling tasks in software development. In one example, a system comprises a computing device configure to identify a prompt that requests generating secure source code for source code with a security vulnerability. A security data source is queried for a security threat embedding. The security threat embedding is received from the security data source and an augmented prompt is generated. The augmented prompt is transmitted to the large language model. A secure source code is received from the large language model and imported into application source code in a software development environment.
Owner:AMERICAN EXPRESS TRAVEL RELATED SERVICES CO INC

System for software code cyber security based on machine learning vulnerability detection and generation and implementation of vulnerability test

An end-to-end approach for (i) identifying potential vulnerabilities in software applications, including security vulnerabilities, (ii) verifying / confirming the potential vulnerabilities as actual vulnerabilities and (iii) in response, identifying the necessary remedial actions necessary to eliminate or at least mitigate the vulnerabilities. An intelligent agent is implemented that is configured to detect a change to the application's code or computing environment and, as a result of detection of changes to the code or computing environment, identify potential vulnerabilities, verify / confirm the potential vulnerabilities as actual vulnerabilities through determination / creation of vulnerability test cases and automatically identify the necessary remedial actions necessary to eliminate or mitigate the vulnerabilities.
Owner:BANK OF AMERICA CORP

Methods, systems, and apparatus for enhancing data security for computing devices over a network

A method for enhancing data security for computing devices over a network is provided. The method performs an automated data security process for at least one external computing device, according to a schedule, including: performing a scan of the at least one external computing device using one or more third-party software applications; obtaining classification data for potential security vulnerabilities applicable to the at least one external computing device; identifying an actual security vulnerability, based on the scan and the classification data; accessing a first database storing organizational data associated with the potential security vulnerabilities; determining current ownership for the actual security vulnerability, based on the organizational data; and determining a priority level for the actual security vulnerability. The method also presents a dashboard including graphical elements and text associated with the actual security vulnerability, and transmits a notification or ticket to the current ownership, based on the priority level.
Owner:EVERNORTH STRATEGIC DEVELOPMENT INC

Application discovery engine in a security management system

Methods, systems, and computer storage media for providing data security posture management using an application discovery engine in a security management system. Application discovery supports identifying and mapping various applications within a computing environment. In particular, application discovery can be provided as part of security management operations to assess security posture of applications, identify vulnerabilities, and ensure compliance with regulations. In operation, application discovery data associated with a plurality computing resources of a computing environment is accessed. An annotated application discovery graph comprising a plurality of entities that represent the plurality of computing resources is generated. The annotated application discovery graph is deployed to support generating security postures for computing environments. A request is received for a security posture of the computing environment. A security posture visualization that includes an application discovery graph annotation is generated. The security posture visualization is communicated to cause display of the security posture visualization.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Automated back-propagation of a fix using a reproducible build, test, and validation process to create a patched artifact

In some implementations, a computing device determines that project code in a development system references an older version of a component in a third-party library, determines that the older version of the component has a vulnerability, determines that a newer version of the component in the third-party library addresses the vulnerability, determines code changes associated with the fix commit, determines a subset of the code changes associated with the fix commit that addresses the vulnerability, creates a patch based on the subset of the code changes associated with the fix commit, applies the patch to the older version of the component to create a patched component, validates the patch, and based on successfully validating the patch, builds the patched component and uploads the patched component and information associated with the patch to a registry to enable a software developer to download the patched component.
Owner:ENDOR LABS INC

Systems and methods for determining current risk of cybersecurity vulnerabilities

Techniques for analyzing cybersecurity vulnerabilities in a computing environment, including: using at least one computer hardware processor to perform: (A) identifying a first cybersecurity vulnerability associated with a resource in the computing environment; (B) obtaining data related to one or more factors related to risk posed by the first cybersecurity vulnerability, the one or more factors including at least one factor indicative of a degree of current exploitation of the first cybersecurity vulnerability; (C) determining, using the obtained data, one or more factor weights for the one or more factors related to the risk posed by the first cybersecurity vulnerability; (D) determining a first score for the first cybersecurity vulnerability using the determined one or more factor weights; and (E) performing one or more security actions based on the determined first score for the first cybersecurity vulnerability.
Owner:RAPID7 INC

System and methods for detecting security vulnerability fixes

A method for detecting vulnerability fixes in software code is disclosed. A source code file containing source code is obtained. The source code file may, for example, be one of the files of a source code commit. The code changes associated with the file are determined, the code changes indicating differences between a previous version and a current version of the source code. Based on the code changes, a first code representation of the previous version of the source code and a second code representation of the current version of the source code are determined. A first embedding of the first code representation and a second embedding of the second code representation are obtained. By computing a distance between the first and second embeddings, a file-level code change representation for the source code is determined, and the source code file is classified based on the file-level code change representation.
Owner:HUAWEI TECH CO LTD

Assessing computer system vulnerabilities and exposures

Assessing computer system vulnerabilities and exposures by periodically querying data sources to gather information pertaining to computing system vulnerabilities and exposures (CVEs), such as, for each CVE, an identification of the CVE, a number of corresponding references to the CVE, and a number of code repositories that can be used to exploit the CVE. Compiling a datastore of the information. Periodically querying the datastore about the information and generating one or more views of a lifecycle of each CVE in response thereto.
Owner:CROWDSTRIKE

Systems and Methods for Accurate Assessment of Application Vulnerabilities

Techniques for accurately assessing the vulnerability status of a collection of software applications are disclosed herein. An example computer-implemented method includes computing a metric indicative of time-to-vulnerability-remediation for each software application in the collection of software applications. The method further includes classifying each software application as one of a predefined set of classifications using at least the computed metrics indicative of time-to-vulnerability-remediation. The method also predicts at least one future classification for each software application in the collection of software applications. The method also outputs at least one data object indicative of, for each software application in the collection of software applications, the software application, the classification of the software application, and the predicted classification(s) of the software application.
Owner:OPTUM INC

Vulnerability management via a graphical interface

A computing machine displays a first interface region including indications of original software blocks and corresponding original vulnerability metrics, and a second interface region including subregions respectively associated with the original software blocks, each subregion presenting selectable compatible replacement software blocks and associated replacement vulnerability metrics. The computing machine presents aggregate vulnerability metrics including a first aggregate metric representing a count of vulnerabilities across the original software blocks and a second aggregate metric representing a count of vulnerabilities across indicated replacement software blocks. The computing machine receives a user selection of replacement software blocks for a selected subregion and responsively updates the associated replacement vulnerability metrics and the second aggregate metric to reflect vulnerabilities of the selected replacement software blocks. The computing machine displays a severity breakdown of vulnerabilities associated with at least one of the first aggregate metric or the second aggregate metric.
Owner:RAPIDFORT INC

A large model-based automated code generation and optimization method and system

The application provides a large model-based automatic code generation and optimization method and system. Among them, the application generates an initial logical framework by a large model, forms a symbolic structure through symbolic processing, and generates a code intermediate representation that retains key semantics, and finally outputs source code. An index set is constructed using a vulnerability knowledge graph, a source code instruction sequence is scanned through parallel computing, and risk instruction positions and vulnerability details are marked by combining semantic similarity and path pattern matching. Based on vulnerability information, a historical case database is retrieved, a matching relationship is established, and an optimization strategy containing repair operations and constraints is generated. A semantic analysis model is loaded at the risk position, a difference graph of execution mode is constructed to generate features, a large model parameter is fine-tuned based on the constructed adversarial sample, and the newly generated code is rechecked for vulnerabilities. The application realizes intelligent generation from requirements to code, and completes the loop of vulnerability identification, repair strategy generation, large model dynamic optimization, and post-repair verification.
Owner:LUSTER LIGHTWAVE CO LTD

Adaptive security architecture based on state of posture

Systems, methods, and computer-readable storage media. One system includes a readiness system configured to access entity data of an entity and determine a security posture of the entity based on the entity data. The system includes an incident system configured to model, based on the security posture, at least one security risk or security vulnerability. The system includes an action system configured to execute one or more actions associated with at least one entity computing system or computing network of the entity. The system includes an output system configured to provide a user interface to the at least one entity computing system or the computing network of the entity, the user interface including at least one of (i) posture data associated with the security posture, (ii) incident data associated with the at least one cyber incident, or (iii) action data associated with the one or more actions.
Owner:AS0001 INC

An automatic inspection method and system for server security self-check

PendingCN122372311ASecure stateSecurity check
This invention discloses an automatic inspection method and system for server security self-testing. The method includes the following steps: S1, acquiring distributed node information and initial security configuration parameters of a server group, and establishing a global security inspection topology; S2, deploying an adaptive inspection agent on each server node, wherein the agent initializes a local inspection strategy based on the global security configuration parameters; S3, through a distributed computing architecture, each adaptive inspection agent independently performs local security checks and generates node security status data. This invention relates to the field of server security technology. This automatic inspection method and system for server security self-testing, through collaborative communication between agents, enables the system to share threat information, vulnerability remediation suggestions, and system status data in real time, constructing a global security data pool, and deriving a global security posture value based on weighted calculation. This allows the system to promptly understand the security status of the entire server group and provide accurate security posture awareness.
Owner:SHANGHAI ZHIZHONGLIAN INTELLIGENT TERMINAL CO LTD

Method of enhancing cyber resilience and system thereof

A method and system of enhancing cyber resilience performed by a computing system is disclosed. According to one embodiment of the present disclosure, the method may comprise a step of acquiring vulnerability data of a target system based on resilience feature data including a quantitative assessment vector and a non-quantitative assessment text of the target system, a step of inputting input data including the vulnerability data into an artificial intelligence model and generating an enhancement strategy for the target system based on output of the artificial intelligence model and a step of controlling a security layer of the target system based on the enhancement strategy.
Owner:KOREA INTERNET & SECURITY AGENCY

Vulnerability chain mapping using graph modeling

Mechanisms are provided for identifying vulnerability chains in a computing system. Computer system vulnerability characteristics for a plurality of computer system vulnerabilities from a vulnerability registry are retrieved. For each vulnerability, a threat score is calculated indicating a level of risk of the vulnerability to security of the computing system. Based on the vulnerability characteristics and the threat score, a directed acyclic graph (DAG) data structure is generated having a plurality of vulnerability chains, each vulnerability chain having a plurality of vulnerabilities, represented as nodes of the DAG, linked to each other from a root node to a terminating node. Links of the DAG have weights corresponding to a function of the threat scores of the nodes directly connected by the link. A graphical representation of the DAG is generated that depicts the weights of the links to thereby represent relative threat of the vulnerabilities linked by the links.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Managing diagnostic testing of computing hardware at an information handling system

PendingUS20260252687A1Third partyHandling system
Managing diagnostic testing of computing hardware, including: identifying a particular computing hardware for performing a diagnostic test at, the particular computing hardware associated with a shared library; receiving telemetry data associated with the particular computing hardware; determining that the telemetry data indicates a possible security event associated with the particular computing hardware, and in response: providing data indicating the shared library to a third-party vulnerability scanning service; receiving, from the third-party vulnerability scanning service, data indicating a security vulnerability of the shared library, and in response: identifying a diagnostic test that is implemented at the particular computing hardware via side band communication channel of the particular computing hardware; implementing, through the side band communication channel, the diagnostic test at the particular computing hardware; determining that the diagnostic test failed at the particular computing device, and in response, performing, independent of user action, a corrective action at the particular computing hardware.
Owner:DELL PROD LP

A security testing method, device, computer equipment and storage medium

The present application provides a security testing method, device, computer equipment and storage medium, which can be applied to cloud computing or intelligent transportation fields, etc., to solve the problem of low accuracy and reliability of security test results. The method includes: in a cloud-native security testing environment, performing a cloud-native security attack test on a target host to obtain a first attack test result; based on the first attack test result, obtaining a first usage permission of the target host, and accessing the local area network security testing environment corresponding to the target host based on the first usage permission; in the local area network security testing environment, performing a local area network security attack test on a core network server to obtain a second attack test result; using the first attack test result and the second attack test result as the target security test result to avoid destroying the correlation between the vulnerabilities and improve the accuracy and reliability of the security test results obtained in the cloud-native scenario.
Owner:TENCENT TECHNOLOGY (SHENZHEN) CO LTD

Method, computing device, and storage medium for determining a security status of a gateway request behavior

Embodiments of the present invention relate to a method, computing device, and storage medium for determining the security status of gateway request behaviors. The method includes generating a request behavior time series table based on the occurrence times of multiple request behaviors of the gateway received in real time; determining the current request behavior, the current time window, and multiple request behaviors within the current time window based on a predetermined sliding time window for the request behavior time series table; extracting multiple behavior attribute data for each of the multiple request behaviors within the current time window to generate multiple groups of behavior attribute data for the multiple request behaviors; generating multiple security features for the current request behavior based on the multiple groups of behavior attribute data for the multiple request behaviors within the current time window via a security perception model; and determining the security label and security level of the current request behavior based on the multiple security features of the current request behavior. The method can effectively improve the accuracy of security status determination and effectively respond to zero-day vulnerability attacks.
Owner:ZHONGZHI AIAITONG (NANJING) INFORMATION TECH CO LTD +1

Techniques for chronological vulnerability event recognition

Techniques for identifying vulnerabilities in a computing environment, including: using at least one computer hardware processor to perform: obtaining first vulnerability data for a first event from external data source(s); associating the first event with a particular vulnerability in a vulnerability dictionary using at least some of the first vulnerability data, the particular vulnerability being associated with one or more historical events; enriching the first vulnerability data with first metadata comprising one or more time-based feature values to obtain first enriched vulnerability data; generating a first set of feature values for the first event using both: the first enriched vulnerability data; and enriched vulnerability data for at least some of the one or more historical events; determining, using the first set of feature values, that a vulnerability mitigation action is to be triggered for the first event; and triggering performance of the vulnerability mitigation action for the first event.
Owner:RAPID7 INC

Automated back-propagation of a fix using a reproducible build, test, and validation process to create a patched artifact

In some implementations, a computing device determines that project code in a development system references an older version of a component in a third-party library, determines that the older version of the component has a vulnerability, determines that a newer version of the component in the third-party library addresses the vulnerability, determines code changes associated with the fix commit, determines a subset of the code changes associated with the fix commit that addresses the vulnerability, creates a patch based on the subset of the code changes associated with the fix commit, applies the patch to the older version of the component to create a patched component, validates the patch, and based on successfully validating the patch, builds the patched component and uploads the patched component and information associated with the patch to a registry to enable a software developer to download the patched component.
Owner:ENDOR LABS INC

System security and network data flow by utilizing a vulnerability score for a service pack

Systems and methods are disclosed that improve system security and network data flow by utilizing a vulnerability score for a service pack. The system comprises a computing system with at least one processing device and at least one memory device, wherein the computing system executes computer-readable instructions. A network connection operatively connects the devices of the computing system. Upon execution of the computer-readable instructions, the computing system is configured to develop a service pack including a plurality of security measures for the computing system; generate a vulnerability score for the service pack based on specific data, wherein the specific data includes a security measure data set; comparing the vulnerability score for the service pack to a predefined threshold value; and implement the service pack when the vulnerability score is less than the predefined threshold value.
Owner:TRUIST BANK

Device security with online configuration check

According to one embodiment, computer-implemented method, a system, and a computer program product for security validation of a network device in a networked computing environment is disclosed. The embodiment may include receiving information about a security vulnerability of a network device, filtering the received information to identify a specific security vulnerability associated with the network device, and extracting a command based on the filtered information, where a returned response of the command when executed is indicative of a specific vulnerability impacting an operation of the network device. The embodiment may include generating a report specifying at least one detail of the network device being affected by a known vulnerability and generating an alert signal indicative of the device security vulnerability status.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Vulnerability rating method and computing device

The embodiment of the invention provides a vulnerability rating method and computing equipment. The method comprises the following steps: acquiring to-be-detected vulnerability information; the to-be-detected vulnerability information is detected through multiple different types of models, multiple detection results are obtained, the multiple different types of models at least comprise a first model based on a machine learning algorithm, and the detection results are used for indicating the risk level of the to-be-detected vulnerability information; and based on a majority voting strategy, performing voting processing on the plurality of detection results to obtain a target detection result, the target detection result being used for training the first model. According to the method, the target detection result of the to-be-detected vulnerability information can be determined through the majority voting strategy, and the first model is trained based on the target detection result, so that the training degradation of the first model is avoided, and the detection processing accuracy of the to-be-detected vulnerability information is improved.
Owner:XFUSION DIGITAL TECH CO LTD