Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

17 results about "Vulnerability scanner" patented technology

A vulnerability scanner is a computer program designed to assess computers, networks or applications for known weaknesses. In plain words, these scanners are used to discover the weaknesses of a given system.

Exposure and Attack Surface Management Using a Data Fabric

The disclosed embodiments provide systems and methods for continuous exposure and attack surface management using a data fabric. Data from multiple heterogeneous cybersecurity sources, including vulnerability scanners, threat intelligence, cloud security tools, and endpoint monitoring systems, is ingested and integrated into a semantically harmonized representation, such as a security knowledge graph. This unified data model normalizes, correlates, and contextualizes diverse cybersecurity information, enabling comprehensive and real-time assessment of an organization's cybersecurity risk posture. Automated workflows trigger proactive remediation actions based on dynamically calculated exposure metrics. Additional embodiments leverage the same data fabric architecture to support specialized cybersecurity use cases, including unified vulnerability management (UVM), cyber asset attack surface management (CAASM), continuous threat exposure management (CTEM), and asset exposure management (AEM).
Owner:AVALOR TECH LTD

Techniques for detecting exploitation of manufacturing device vulnerabilities

A system and method for determining device attributes using a classifier hierarchy. The method includes determining exploitation conditions for a manufacturing device based on a first set of device attributes of the manufacturing device and a second set of device attributes indicated in a vulnerabilities database; analyzing behavior and configuration of the manufacturing device to detect an exploitable vulnerability for the manufacturing device, wherein the exploitable vulnerability is a behavior or configuration of the manufacturing device which meets the exploitation conditions; and performing mitigation actions based on the exploitable vulnerability. The vulnerabilities database further indicates known exploits for the second set of device attributes. Analyzing the behavior and configuration of the manufacturing device includes identifying that a port is open and querying a vulnerability scanner for identifying information of the open port, wherein the currently exploitable vulnerability is detected based further on the identifying information of the open port.
Owner:ARMIS SECURITY LTD

Webpage API (Application Program Interface) depth discovery method

The invention relates to a webpage API (Application Program Interface) depth discovery method, which comprises the following steps of: injecting a self-defined JS (JavaScript) code into a chromium browser which is started in a headless mode, triggering a webpage event and realizing request interception and hijack monitoring, and gradually triggering and completely traversing a functional process aiming at DOM0 and DOM2 events in the webpage code, meanwhile, a specific execution result is returned through a special DOM event of a HOOK part, the webpage is locked to avoid jumping in the triggering process, the DOM event on the webpage is triggered as completely as possible with the assistance of a field automatic filling function, and meanwhile, URL requests of webpage event functions are recorded and summarized. Compared with the prior art, the method has higher API discovery capability; according to the model, a browser event triggering and function HOOK technology method is adopted, the problems that a vulnerability scanner discovers and captures webpage URL paths and APIs are missing and incomplete are well solved, and the capacity of discovering the APIs and the vulnerabilities in the field of automatic vulnerability discovering is improved.
Owner:SHANGHAI WEIDAO INFORMATION TECH CO LTD

Mandatory vulnerability update method, mandatory vulnerability scanning method, and related device

The application provides a mandatory vulnerability updating method, a mandatory vulnerability scanning method and related equipment, and relates to the technical field of network vulnerability scanning. The application obtains a plurality of vulnerability matching rules of a plurality of to-be-identified network vulnerabilities, calls a content distribution network platform to obtain historical network traffic data in a target time period, then performs vulnerability matching on the plurality of vulnerability matching rules and the historical network traffic data respectively, screens a plurality of target mandatory vulnerabilities with a higher probability of being exploited from the plurality of to-be-identified network vulnerabilities according to the vulnerability matching results of the plurality of vulnerability matching rules in the historical network traffic data, and finally automatically updates the vulnerability information of the screened plurality of target mandatory vulnerabilities to a target vulnerability scanner, so that an operation and maintenance personnel can directly use the target vulnerability scanner to effectively identify mandatory vulnerabilities existing in an information system, thereby effectively improving system security operation and maintenance efficiency and realizing accurate positioning of mandatory vulnerabilities.
Owner:BEIJING KNOWNSEC INFORMATION TECHNOLOGY CO LTD

Cybersecurity risk intelligence assessment system

ActiveCN118944962BSecuring communicationIntelligence assessmentVulnerability scanning
The application provides a network security risk intelligent evaluation system and relates to the technical field of network security, which comprises a leak scanning capability evaluator, a leak scanning capability scheduler, a vulnerability scanner, a capability verification server and a target network. The leak scanning capability evaluator acquires network information of the target network and informs the leak scanning capability scheduler to create a projection environment according to the network information. The vulnerability scanner is called to perform vulnerability scanning on the projection environment and submit a first leak scanning report of the projection environment. The capability of each vulnerability scanner is evaluated according to the first leak scanning report. The leak scanning capability scheduler calls corresponding vulnerability scanners to scan the target network according to a vulnerability scanning combination scheme and submits a second leak scanning report to the leak scanning capability evaluator. Through the evaluation of the vulnerability detection efficiency and quality, the method for improving the vulnerability detection efficiency and quality by formulating the arrangement and calling strategy of various available leak scanning systems is realized, and the leak scanning quality and efficiency are effectively improved.
Owner:CHINA MOBILE GRP GUANGDONG CO LTD +1

Quantitative assessment method for cyber security risk of distribution network cyber-physical system

An automated network security risk quantitative assessment method for a power distribution network cyber-physical system includes: using the Nessus vulnerability scanner to perform a vulnerability scan on a target network; using the MulVAL tool to generate an attack graph using the vulnerability scan results and input network topology and security policies; searching a vulnerability library for corresponding vulnerability descriptions based on the vulnerability scan results, and outputting the vulnerability's CVSS metric classification using a CVSS metric classification prediction model; performing a quantitative system risk assessment based on the attack graph, CVSS metrics, and input physical consequences, and calculating the risk value of each node in the target network. The present invention utilizes open source tools to address the problem of automatic attack graph generation, and uses a CVSS metric classification prediction model to address the problem of CVSS information dependency. Furthermore, by designing multiple classifiers that share a multi-layer network, synchronous classification prediction and classification feature sharing of each CVSS metric are achieved.
Owner:BEIJING JIAOTONG UNIV

Vulnerability and remediation validation automation

A method of qualifying a vulnerability detection for remediation comprising: obtaining a vulnerability detection from a vulnerability scanner for a target system; determining qualification data qualifying the vulnerability detection, wherein the qualification data is based on a configuration of the target system excluded in the vulnerability detection from the vulnerability scanner; and associating the qualification data with the vulnerability detection.
Owner:DISNEY ENTERPRISES INC

Heterogeneous vulnerability scanner scheduling method and system based on intelligent scheduling strategy

The invention relates to the technical field of network security, and discloses a heterogeneous vulnerability scanner scheduling method and system based on an intelligent scheduling strategy, and the method comprises the steps: connecting different vulnerability scanners, carrying out the service registration and state monitoring through a unified API gateway, and collecting the operation indexes of all scanners in real time; setting a scanning scheduling strategy to allocate scanning tasks to scanners for execution, and obtaining task execution results; and obtaining scanning result data of each scanner, and generating a vulnerability scanning report. According to the invention, centralized scheduling management can be carried out uniformly, the utilization rate of the vulnerability scanner is improved, the scanning missing channel monitoring capability is provided, and when the content of our unit cannot be processed due to overtime unprocessed tasks or channel blockage, early warning is carried out in advance and related personnel of our unit are notified to process, so that the queuing waiting condition of users is relieved, and the user experience is improved. Different types of report data fusing heterogeneous scanning tasks are supported, a standardized scanning report is provided, and self-definition of a report format is supported.
Owner:JIANGSU PUBLIC INFORMATION CO LTD

Interface security test method and device, storage medium and product

The embodiment of the invention relates to the technical field of information, and discloses an interface security test method and device, a storage medium and a product, the interface security test method comprises the steps that a plurality of vulnerability detection plug-ins are constructed, the vulnerability detection plug-ins correspond to different interface security test categories, and the vulnerability detection plug-ins comprise basic principles of vulnerability types; obtaining interface information of the target interface and an interface associated with the target interface through the first intelligent agent; constructing a vulnerability scanning process through the first agent according to the interface information and the vulnerability arrangement information; performing vulnerability scanning on the target interface through the second agent according to the vulnerability scanning process to obtain a scanning result; therefore, by means of the endogenous ability of multiple agents, the workflow of a human penetration test engineer is simulated, through multi-step Web API calling, fine and meticulous vulnerability verification conforming to human thinking is achieved, the accuracy rate far higher than that of a traditional vulnerability scanner is achieved, and multiple vulnerability types difficult to cover by the traditional scanner can be covered.
Owner:SHANGHAI JIEYUE JIYUAN INTELLIGENT TECHNOLOGY CO LTD

Intranet asset vulnerability scanning method, electronic equipment, storage medium and program product

The application provides an internal network asset vulnerability scanning method, an electronic device, a storage medium and a program product. The method comprises the following steps: receiving a vulnerability scanning request; the vulnerability scanning request comprises to-be-scanned asset information, and the asset corresponding to the to-be-scanned asset information is an internal network asset; determining an access terminal based on the to-be-scanned asset information; the access terminal is used to realize the communication connection between a cloud service platform and the internal network; determining a vulnerability scanner on the cloud service platform according to the access terminal; sending vulnerability scanning traffic to the access terminal through the vulnerability scanner, so that the access terminal forwards the vulnerability scanning traffic to the asset corresponding to the to-be-scanned asset information, to realize the vulnerability scanning of the asset. Through the access terminal, the communication channel between the cloud service platform and the internal network asset is opened, so that the purpose of using the vulnerability scanner on the cloud service platform to perform the vulnerability scanning on the internal network asset is realized.
Owner:BEIJING TOPSEC NETWORK SECURITY TECH +2

Vulnerability scanning method, device and system, vulnerability scanner and electronic equipment

The embodiment of the invention discloses a vulnerability scanning method, device and system, a vulnerability scanner and electronic equipment, and relates to the field of cloud technology and computer technology. The method comprises the following steps: before sending a vulnerability scanning request to a scanned object, determining a response result of the scanned object to a historical scanning request; wherein the response result indicates whether a historical scanning request which is not responded by the scanned object exists or not; the historical scanning request comprises a historical vulnerability scanning request or a historical detection scanning request; and according to the response result, determining whether to send a vulnerability scanning request to the scanned object. By adopting the embodiment of the invention, whether the vulnerability scanning request is continuously sent to the scanned object or not can be determined according to the service performance of the scanned object, so that the scanned object is subjected to security check while stable operation of the scanned object is ensured, the scanned object is prevented from processing more vulnerability scanning requests under the condition of high load, and the security of the scanned object is improved. The scanning and hanging risk is reduced, and the applicability is high.
Owner:TENCENT TECHNOLOGY (SHENZHEN) CO LTD

Method, device and medium for generating and verifying vulnerability rules based on intermediate components

This disclosure provides a method, device, and medium for vulnerability rule generation and verification based on an intermediate component, relating to the field of computer technology, particularly artificial intelligence and network security. The specific implementation scheme includes: running the simulation environment constructed through the intermediate component; converting a vulnerability scanner tool template into an executable vulnerability detection service within the simulation environment, wherein the vulnerability detection service is a simulated service executed by a vulnerable web server; generating vulnerability detection rules in the simulation environment based on the vulnerability scanner tool template; and verifying the validity of the rules in the simulation environment based on the vulnerability detection rules and the vulnerability detection service.
Owner:BEIJING BAIDU NETCOM SCI & TECH CO LTD

Attack surface management cybersecurity platform and methods

An exploit assessment and pentesting program tests assets of a network being protected by an ASM cloud platform against known CVE. The vulnerability scanner performs pentesting by selecting CVE test templates from the database of CVE test templates and running the CVE test templates to conduct one or more common vulnerabilities and exposures tests on an asset to see whether the asset is actually vulnerable or not. The vulnerability scanner can cooperate with at least one of a user interface, a display, and a report generator to both i) report a results of the augmented pentesting on the assets of the network as well as ii) present an attack surface of the assets of the network being protected by the ASM cloud platform detected by the exploit assessment and pentesting program in order to show actual CVE risks present in the assets in the network.
Owner:DARKTRACE INC

Offense type network vulnerability scanner

Techniques for deploying and using offense-type network vulnerability scanners are disclosed herein. Network vulnerability scanners can be deployed at multiple locations in a network. The network vulnerability scanners can cause equipment with external connections to the network, such as user equipment which is configured for testing purposes, or other device(s) with or without external network connections to perform network vulnerability test operations. The network vulnerability test operations can expose network vulnerability information associated with external connections of the user equipment to the network.
Owner:T MOBILE US INC

Traffic extraction method and apparatus for vulnerability scanner, and electronic device and storage medium

PCT designated stageWO2025190232A1Securing communicationScannerComputer network
The present application relates to the technical field of traffic extraction. Disclosed are a traffic extraction method and apparatus for a vulnerability scanner, and an electronic device and a storage medium. The method comprises: triggering a vulnerability scanner to send request traffic; determining whether the request traffic is redundant traffic, wherein the redundant traffic comprises universal traffic and / or repeated traffic, the repeated traffic being traffic identical to the previously received request traffic, and the universal traffic being request traffic for the vulnerability scanner to verify the survival of a site; and if the request traffic is non-redundant traffic, storing the request traffic. In this way, in the present application, whether request traffic is redundant traffic is determined, i.e., whether the request traffic is invalid traffic is determined, such that the request traffic that is not invalid traffic is stored, thereby reducing invalid traffic among stored request traffic.
Owner:SHANGHAI DOUXIANG INFORMATION TECHNOLOGY CO LTD

A novel power system APT attack graph generation method based on GD-DQN algorithm

ActiveCN115271029BPathPingAlgorithm
The application relates to a novel power system APT attack graph generation method based on a GD-DQN algorithm, first, based on a novel power system network topology structure, network vulnerability scanners are used for scanning detection to generate vulnerability information of the novel power system; second, an intelligent agent in the GD-DQN algorithm is used for carrying out vulnerability state scanning on the vulnerability information to form network perception T of the novel power system environment; and then, the intelligent agent constructs an attack graph through a training process according to the network perception T. In the application, the intelligent agent in the GD-DQN algorithm is used to improve the efficiency and scale of attack graph generation, and the attack graph can be dynamically and real-timely generated; the Dueling DQN algorithm is introduced, each learning process of the intelligent agent does not necessarily depend on other learning scenes; the GRU model is introduced, the intelligent agent achieves better training effect, and a better attack path can be obtained.
Owner:NORTH CHINA ELECTRIC POWER UNIV +1

Systems and methods for tracking virtual machine image vulnerabilities in a distributed network

Systems, computer program products, and methods are described herein for tracking virtual machine image vulnerabilities in a distributed network. The present disclosure is configured to identify a virtual machine (VM) image; apply the identified VM image to a VM vulnerability scanner; determine, by the VM vulnerability scanner, the VM image is safe from a list of known vulnerabilities; update, based on the VM vulnerability scanner, an approved repository with the VM image that is determined as safe from known vulnerabilities; generate, by a VM provisioning engine, at least one VM from the approved repository; identify at least one address identifier associated with the generated VM; and update the approved repository with the identified at least one address identifier and link the at least one address identifier to the associated VM image the generated VM is based on.
Owner:BANK OF AMERICA CORP