Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

72 results about "Vulnerability (computing)" patented technology

In computer security, a vulnerability is a weakness which can be exploited by a threat actor, such as an attacker, to perform unauthorized actions within a computer system. To exploit a vulnerability, an attacker must have at least one applicable tool or technique that can connect to a system weakness. In this frame, vulnerability is also known as the attack surface.

Edge computing and distributed zero-trust architecture system and data processing method

The invention discloses an edge computing and distributed zero-trust architecture system and a data processing method. The system comprises an edge computing device cluster, a distributed zero-trust control center, an edge security gateway and a block chain identity infrastructure. The edge computing node collects hardware state, vulnerability and behavior data through the terminal security agent module; the block chain identity infrastructure provides distributed identity identification and verifiable credential service; the edge security gateway executes data packet filtering and single packet authentication; and the distributed zero-trust control center calculates a real-time security coefficient and generates a differentiation strategy, and the log is synchronized to the alliance chain for evidence storage. According to the data processing method, security access is realized through access request initiation, single packet authentication, data acquisition, trust evaluation, strategy execution and log evidence storage. According to the method, the edge device state and distributed zero trust are deeply fused, the problems of incomplete identity authentication and static permission control in an edge scene are solved, and the security and traceability of an edge computing network are improved.
Owner:BEIJING ANCHEN INFORMATION TECHNOLOGY CO LTD

Threat model assistant for software development

The present disclosure of the various embodiments relates to using a large language model to assistant with the creation of secure code and / or the completion of threat modeling tasks in software development. In one example, a system comprises a computing device configure to identify a prompt that requests generating secure source code for source code with a security vulnerability. A security data source is queried for a security threat embedding. The security threat embedding is received from the security data source and an augmented prompt is generated. The augmented prompt is transmitted to the large language model. A secure source code is received from the large language model and imported into application source code in a software development environment.
Owner:AMERICAN EXPRESS TRAVEL RELATED SERVICES CO INC

Application discovery engine in a security management system

Methods, systems, and computer storage media for providing data security posture management using an application discovery engine in a security management system. Application discovery supports identifying and mapping various applications within a computing environment. In particular, application discovery can be provided as part of security management operations to assess security posture of applications, identify vulnerabilities, and ensure compliance with regulations. In operation, application discovery data associated with a plurality computing resources of a computing environment is accessed. An annotated application discovery graph comprising a plurality of entities that represent the plurality of computing resources is generated. The annotated application discovery graph is deployed to support generating security postures for computing environments. A request is received for a security posture of the computing environment. A security posture visualization that includes an application discovery graph annotation is generated. The security posture visualization is communicated to cause display of the security posture visualization.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

System and methods for detecting security vulnerability fixes

A method for detecting vulnerability fixes in software code is disclosed. A source code file containing source code is obtained. The source code file may, for example, be one of the files of a source code commit. The code changes associated with the file are determined, the code changes indicating differences between a previous version and a current version of the source code. Based on the code changes, a first code representation of the previous version of the source code and a second code representation of the current version of the source code are determined. A first embedding of the first code representation and a second embedding of the second code representation are obtained. By computing a distance between the first and second embeddings, a file-level code change representation for the source code is determined, and the source code file is classified based on the file-level code change representation.
Owner:HUAWEI TECH CO LTD

Assessing computer system vulnerabilities and exposures

Assessing computer system vulnerabilities and exposures by periodically querying data sources to gather information pertaining to computing system vulnerabilities and exposures (CVEs), such as, for each CVE, an identification of the CVE, a number of corresponding references to the CVE, and a number of code repositories that can be used to exploit the CVE. Compiling a datastore of the information. Periodically querying the datastore about the information and generating one or more views of a lifecycle of each CVE in response thereto.
Owner:CROWDSTRIKE

Systems and Methods for Accurate Assessment of Application Vulnerabilities

Techniques for accurately assessing the vulnerability status of a collection of software applications are disclosed herein. An example computer-implemented method includes computing a metric indicative of time-to-vulnerability-remediation for each software application in the collection of software applications. The method further includes classifying each software application as one of a predefined set of classifications using at least the computed metrics indicative of time-to-vulnerability-remediation. The method also predicts at least one future classification for each software application in the collection of software applications. The method also outputs at least one data object indicative of, for each software application in the collection of software applications, the software application, the classification of the software application, and the predicted classification(s) of the software application.
Owner:OPTUM INC

Vulnerability management via a graphical interface

ActiveUS12699780B1Vulnerability managementSoftware engineering
A computing machine displays a first interface region including indications of original software blocks and corresponding original vulnerability metrics, and a second interface region including subregions respectively associated with the original software blocks, each subregion presenting selectable compatible replacement software blocks and associated replacement vulnerability metrics. The computing machine presents aggregate vulnerability metrics including a first aggregate metric representing a count of vulnerabilities across the original software blocks and a second aggregate metric representing a count of vulnerabilities across indicated replacement software blocks. The computing machine receives a user selection of replacement software blocks for a selected subregion and responsively updates the associated replacement vulnerability metrics and the second aggregate metric to reflect vulnerabilities of the selected replacement software blocks. The computing machine displays a severity breakdown of vulnerabilities associated with at least one of the first aggregate metric or the second aggregate metric.
Owner:RAPIDFORT INC

A large model-based automated code generation and optimization method and system

The application provides a large model-based automatic code generation and optimization method and system. Among them, the application generates an initial logical framework by a large model, forms a symbolic structure through symbolic processing, and generates a code intermediate representation that retains key semantics, and finally outputs source code. An index set is constructed using a vulnerability knowledge graph, a source code instruction sequence is scanned through parallel computing, and risk instruction positions and vulnerability details are marked by combining semantic similarity and path pattern matching. Based on vulnerability information, a historical case database is retrieved, a matching relationship is established, and an optimization strategy containing repair operations and constraints is generated. A semantic analysis model is loaded at the risk position, a difference graph of execution mode is constructed to generate features, a large model parameter is fine-tuned based on the constructed adversarial sample, and the newly generated code is rechecked for vulnerabilities. The application realizes intelligent generation from requirements to code, and completes the loop of vulnerability identification, repair strategy generation, large model dynamic optimization, and post-repair verification.
Owner:LUSTER LIGHTWAVE CO LTD

Adaptive security architecture based on state of posture

Systems, methods, and computer-readable storage media. One system includes a readiness system configured to access entity data of an entity and determine a security posture of the entity based on the entity data. The system includes an incident system configured to model, based on the security posture, at least one security risk or security vulnerability. The system includes an action system configured to execute one or more actions associated with at least one entity computing system or computing network of the entity. The system includes an output system configured to provide a user interface to the at least one entity computing system or the computing network of the entity, the user interface including at least one of (i) posture data associated with the security posture, (ii) incident data associated with the at least one cyber incident, or (iii) action data associated with the one or more actions.
Owner:AS0001 INC

An automatic inspection method and system for server security self-check

PendingCN122372311ASecure stateSecurity check
This invention discloses an automatic inspection method and system for server security self-testing. The method includes the following steps: S1, acquiring distributed node information and initial security configuration parameters of a server group, and establishing a global security inspection topology; S2, deploying an adaptive inspection agent on each server node, wherein the agent initializes a local inspection strategy based on the global security configuration parameters; S3, through a distributed computing architecture, each adaptive inspection agent independently performs local security checks and generates node security status data. This invention relates to the field of server security technology. This automatic inspection method and system for server security self-testing, through collaborative communication between agents, enables the system to share threat information, vulnerability remediation suggestions, and system status data in real time, constructing a global security data pool, and deriving a global security posture value based on weighted calculation. This allows the system to promptly understand the security status of the entire server group and provide accurate security posture awareness.
Owner:SHANGHAI ZHIZHONGLIAN INTELLIGENT TERMINAL CO LTD

Method of enhancing cyber resilience and system thereof

A method and system of enhancing cyber resilience performed by a computing system is disclosed. According to one embodiment of the present disclosure, the method may comprise a step of acquiring vulnerability data of a target system based on resilience feature data including a quantitative assessment vector and a non-quantitative assessment text of the target system, a step of inputting input data including the vulnerability data into an artificial intelligence model and generating an enhancement strategy for the target system based on output of the artificial intelligence model and a step of controlling a security layer of the target system based on the enhancement strategy.
Owner:KOREA INTERNET & SECURITY AGENCY

Vulnerability chain mapping using graph modeling

Mechanisms are provided for identifying vulnerability chains in a computing system. Computer system vulnerability characteristics for a plurality of computer system vulnerabilities from a vulnerability registry are retrieved. For each vulnerability, a threat score is calculated indicating a level of risk of the vulnerability to security of the computing system. Based on the vulnerability characteristics and the threat score, a directed acyclic graph (DAG) data structure is generated having a plurality of vulnerability chains, each vulnerability chain having a plurality of vulnerabilities, represented as nodes of the DAG, linked to each other from a root node to a terminating node. Links of the DAG have weights corresponding to a function of the threat scores of the nodes directly connected by the link. A graphical representation of the DAG is generated that depicts the weights of the links to thereby represent relative threat of the vulnerabilities linked by the links.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Managing diagnostic testing of computing hardware at an information handling system

PendingUS20260252687A1Third partyHandling system
Managing diagnostic testing of computing hardware, including: identifying a particular computing hardware for performing a diagnostic test at, the particular computing hardware associated with a shared library; receiving telemetry data associated with the particular computing hardware; determining that the telemetry data indicates a possible security event associated with the particular computing hardware, and in response: providing data indicating the shared library to a third-party vulnerability scanning service; receiving, from the third-party vulnerability scanning service, data indicating a security vulnerability of the shared library, and in response: identifying a diagnostic test that is implemented at the particular computing hardware via side band communication channel of the particular computing hardware; implementing, through the side band communication channel, the diagnostic test at the particular computing hardware; determining that the diagnostic test failed at the particular computing device, and in response, performing, independent of user action, a corrective action at the particular computing hardware.
Owner:DELL PROD LP

Techniques for chronological vulnerability event recognition

Techniques for identifying vulnerabilities in a computing environment, including: using at least one computer hardware processor to perform: obtaining first vulnerability data for a first event from external data source(s); associating the first event with a particular vulnerability in a vulnerability dictionary using at least some of the first vulnerability data, the particular vulnerability being associated with one or more historical events; enriching the first vulnerability data with first metadata comprising one or more time-based feature values to obtain first enriched vulnerability data; generating a first set of feature values for the first event using both: the first enriched vulnerability data; and enriched vulnerability data for at least some of the one or more historical events; determining, using the first set of feature values, that a vulnerability mitigation action is to be triggered for the first event; and triggering performance of the vulnerability mitigation action for the first event.
Owner:RAPID7 INC

Automated back-propagation of a fix using a reproducible build, test, and validation process to create a patched artifact

In some implementations, a computing device determines that project code in a development system references an older version of a component in a third-party library, determines that the older version of the component has a vulnerability, determines that a newer version of the component in the third-party library addresses the vulnerability, determines code changes associated with the fix commit, determines a subset of the code changes associated with the fix commit that addresses the vulnerability, creates a patch based on the subset of the code changes associated with the fix commit, applies the patch to the older version of the component to create a patched component, validates the patch, and based on successfully validating the patch, builds the patched component and uploads the patched component and information associated with the patch to a registry to enable a software developer to download the patched component.
Owner:ENDOR LABS INC

System security and network data flow by utilizing a vulnerability score for a service pack

Systems and methods are disclosed that improve system security and network data flow by utilizing a vulnerability score for a service pack. The system comprises a computing system with at least one processing device and at least one memory device, wherein the computing system executes computer-readable instructions. A network connection operatively connects the devices of the computing system. Upon execution of the computer-readable instructions, the computing system is configured to develop a service pack including a plurality of security measures for the computing system; generate a vulnerability score for the service pack based on specific data, wherein the specific data includes a security measure data set; comparing the vulnerability score for the service pack to a predefined threshold value; and implement the service pack when the vulnerability score is less than the predefined threshold value.
Owner:TRUIST BANK

Device security with online configuration check

According to one embodiment, computer-implemented method, a system, and a computer program product for security validation of a network device in a networked computing environment is disclosed. The embodiment may include receiving information about a security vulnerability of a network device, filtering the received information to identify a specific security vulnerability associated with the network device, and extracting a command based on the filtered information, where a returned response of the command when executed is indicative of a specific vulnerability impacting an operation of the network device. The embodiment may include generating a report specifying at least one detail of the network device being affected by a known vulnerability and generating an alert signal indicative of the device security vulnerability status.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Source code high-order vulnerability detection method and system based on execution path analysis

The invention relates to the technical field of software security, and provides a source code high-order vulnerability detection method and system based on execution path analysis, and the method comprises the steps: obtaining a to-be-analyzed source code, and constructing a function execution graph for each function in the source code; on the function execution graph, starting from a function entry node, generating a function execution path according to an execution sequence edge, and applying bounded constraint to a function execution path generation process; calculating a priority score for any function execution path by adopting a path priority function, and sorting and screening the function execution paths based on the priority scores to obtain candidate execution paths; and obtaining a vulnerability type and vulnerability location through a path coding model, a statement encoder, an attention mechanism and a vulnerability detection model. And the vulnerability detection accuracy and the positioning interpretability are improved under the controllable calculation overhead.
Owner:QILU UNIVERSITY OF TECHNOLOGY (SHANDONG ACADEMY OF SCIENCES) +1

A vulnerability detection method, apparatus, device, medium, and product

PendingCN122339728ACiphertextTimestamping
This application relates to a vulnerability detection method, apparatus, device, medium, and product, and pertains to the field of cloud computing technology. The method includes: splitting an encrypted version string to obtain encrypted ciphertext, sending timestamp information, and obfuscation feature string; verifying the encrypted ciphertext, sending timestamp information, and obfuscation feature string to obtain a verification result, and retrieving the decryption key if the result passes; decrypting the encrypted ciphertext with the decryption key to obtain target format version information; retrieving the software name, major version number, minor version number, and patch version number from the target format version information, and matching the software name against a pre-stored rule base list of target vulnerability data; obtaining a vulnerability risk assessment result and a remediation result based on the major version number, minor version number, patch version number, vulnerability impact scope, and the target version for remediation; and generating a vulnerability detection report based on the vulnerability risk assessment result and the remediation result. Decrypting the encrypted version string and matching the vulnerability scope effectively improves the timeliness of vulnerability detection.
Owner:INDUSTRIAL AND COMMERCIAL BANK OF CHINA

Systems and methods for advanced vulnerability detection and remediation within computer networks

A system for dynamic vulnerability detection and remediation is provided. The system includes a memory device and at least one processor coupled to the memory device. The at least one processor is programmed to: (a) store within a database an inventory of computer assets included within a computer ecosystem; (b) retrieve a vulnerability report including vulnerability definitions; (c) analyze the database to identify a potential vulnerability by comparing the computer assets stored within the database to the vulnerability definitions; (d) upon detecting the potential vulnerability, determine a service owner associated with the computer assets identified as being involved in the potential vulnerability; and (e) provide content to a user computing device associated with the service owner causing the user device to display a notification alert advising the service owner of the potential vulnerability and providing a remediation plan to address the potential vulnerability.
Owner:MASTERCARD INT INC

A method for continuous automated vulnerability mining based on log data

The application discloses a kind of based on log data's continuous automation vulnerability mining method, belong to network and information security technical field.The application can penetrate application surface layer, accurately identify dynamic generation interface, hidden application program interface and deep vulnerability parameter that traditional technology cannot touch, to significantly improve attack entry point coverage in real traffic, realize panoramic coverage of attack surface by quantitative information flow analysis and topology discovery based on data tracing.The application can capture, understand and verify new attack mode including zero-day attack from real traffic in near real time based on static semantics-dynamic time sequence double-layer learning model and closed-loop feedback mechanism, shorten threat response time from several days to several hours, build adaptive threat immunity ability;Through the risk intelligent scheduling mechanism driven by multi-objective genetic algorithm, test resources are preferentially allocated to business critical and highest risk attack entry, to significantly optimize computing resource allocation.
Owner:UNIV OF ELECTRONICS SCI & TECH OF CHINA

Vulnerability detection for cloud computing systems

Systems, devices, and techniques are disclosed for vulnerability detection for cloud computing systems. A security inventory of a cloud computing server system may be received. A graph database may be generated based on the security inventory of the cloud computing server system. A natural language description of a security vulnerability may be received. A graph query may be generated from the natural language description of a security vulnerability using a generative neural network. The security vulnerability may be detected in the cloud computing server system by running the graph query against the graph database. A report indicating the presence of the security vulnerability in the cloud computing server system may be generated. An action to remediate the security vulnerability in the cloud computing server system may be performed.
Owner:SALESFORCE INC

Computer-implemented method for identifying potential denial of service attack vulnerabilities in network protocol program

A computer-implemented method for identifying potential denial of service attack vulnerabilities in a network protocol program (10) installed on a computing device having limited computing resources, the network protocol program (10) comprising a plurality of network protocol states (12), these network protocol states may be traversed by corresponding inputs (14) executed by the network protocol program (10) and cause the network protocol program (10) to undergo network protocol translations (16) from one network protocol state (12) to another, each network protocol translation (16) having a consumption and / or allocation (18) of computing resources.
Owner:OMOWE GMBH +1

Method For Detecting Vulnerabilities In A Program

According to an embodiment of the present disclosure, a method for detecting vulnerability in program containing a plurality of source code files, performed by a computing device is disclosed. The method may comprises: extracting at least one of a vulnerability file name corresponding to a pre-stored vulnerability file or a vulnerability function name corresponding to a pre-stored vulnerability function, from a description of pre-stored vulnerabilities; extracting at least one candidate source code file from among the plurality of source code files in the program, the candidate source code file being subject to determination of whether it contains a vulnerability; and determining at least one of a target file or a target function having a vulnerability within the program, by using the candidate source code file and at least one of the vulnerability file name or the vulnerability function name.
Owner:LABRADOR LABS INC

Process vulnerability assessment

PendingUS20260252703A1Software engineeringWorkflow analysis
Method and apparatus for analyzing operational processes to detect vulnerabilities are provided. The method includes generating a documented workflow by processing a plurality of unstructured documents associated with an operational process, generating an implemented workflow by analyzing source code that implements the operational process in a computing system, generating an executed workflow by processing real-world execution data for the operational process, analyzing the documented workflow, the implemented workflow, and the executed workflow to identify one or more inconsistencies among the workflows and one or more exploits within the operational process, and generating one or more recommended actions to remedy at least one of the one or more identified inconsistencies or the one or more identified exploits.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Systems, methods, and storage media that compute a frequency of network risk loss within a computing system

Systems, methods, and storage media for determining the probability of network risk-related losses within a computing system comprised of one or more computing elements are disclosed. Exemplary implementations may: assess vulnerability by determining an exposure window of the computing element based on the number of discrete times within a given time frame in which the computing element is vulnerable; determine the frequency of contact between the computing element and threat actors; normalize the exposure window and the contact frequency; calculate the frequency of loss events by dividing the normalized exposure window by the normalized contact frequency; and repeat these steps for multiple elements. When combined with liability data implied by the magnitude of losses describing these events, organizations can prioritize elements based on loss exposure and take action to prevent loss exposure.
Owner:RISKLENS INC

Machine learning techniques for generating common vulnerability scoring system vectors

ActiveUS20260119675A1Platform integrity maintainanceRating systemEngineering
Some embodiments provide techniques for generating common vulnerability scoring system (CVSS) vectors for vulnerabilities to use in scanning a computing environment for vulnerabilities. The techniques involve obtaining a textual description of a vulnerability; generating inputs for a plurality of ML models using the textual description of the vulnerability; providing the inputs to the plurality of ML models to obtain outputs indicating values of CVSS risk metrics; and storing the values of the CVSS risk metrics indicated by the outputs of the plurality of ML models in a vector to obtain the CVSS vector for the vulnerability.
Owner:RAPID7 INC

Proactively determining security risks and deployment impacts across cloud computing environments

This disclosure describes a proactive deployment impact system that detects and addresses the security impact of candidate code-based infrastructure changes before they are deployed in a production environment within a cloud computing system. The proactive deployment impact system implements a lightweight preemptive security framework, based on runtime resource information, to determine whether a requested candidate code-based infrastructure change would introduce new security risks, attack patterns, or breach vulnerabilities. Furthermore, the proactive deployment impact system can actively block the deployment of negatively impacting candidate changes, report potential security breaches, and / or automatically modify the candidate changes to eliminate security vulnerabilities.
Owner:MICROSOFT TECHNOLOGY LICENSING LLC

Method, device and storage medium for detecting lateral privilege escalation vulnerabilities

This application discloses a method, apparatus, and storage medium for detecting lateral privilege escalation vulnerabilities, belonging to the field of cloud computing. The method is applied to a computing device, which includes an application and a first data table of the application. The method includes: obtaining interface functions included in the application, each interface function including at least one first variable; obtaining a function call chain based on the interface functions, the function call chain including multiple functions in the application, the function call chain being used to access the first data table based on the at least one first variable; and detecting whether the application has a lateral privilege escalation vulnerability based on the function call chain. This application can improve the accuracy of detecting lateral privilege escalation vulnerabilities.
Owner:HUAWEI TECH CO LTD +1

Systems and methods for accurate assessment of application vulnerabilities

Techniques for accurately assessing the vulnerability status of a collection of software applications are disclosed herein. An example computer-implemented method includes computing a metric indicative of time-to-vulnerability-remediation for each software application in the collection of software applications. The method further includes classifying each software application as one of a predefined set of classifications using at least the computed metrics indicative of time-to-vulnerability-remediation. The method also predicts at least one future classification for each software application in the collection of software applications. The method also outputs at least one data object indicative of, for each software application in the collection of software applications, the software application, the classification of the software application, and the predicted classification(s) of the software application.
Owner:OPTUM INC