Application Upgrade Vulnerability Detection and Filtering
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Users are unaware of potential vulnerabilities in application upgrades before performing them, leading to potential security risks.
Innovation Solution
A method and system that proactively detect and filter out vulnerabilities by using a vulnerability validator and device emulation orchestration engine to generate an application upgrade strategy for secure upgrades.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If application upgrades are performed to protect from security vulnerabilities, then security reliability is improved, but users may inadvertently install vulnerable versions due to lack of awareness
Solution Approach 1:
The vulnerability validator performs preliminary validation of application upgrades before they are installed on client devices. The system proactively detects vulnerabilities in candidate upgrade versions and generates reports indicating which versions are safe, allowing administrators to make informed decisions before deployment, thus preventing the installation of vulnerable upgrades.
Solution Approach 2:
The vulnerability validator acts as an intermediary between the application upgrade process and the client devices. It receives upgrade information, validates it against known vulnerability data, and provides guidance on safe upgrades, mediating between the need for updates and the risk of introducing vulnerabilities.
2Productivity
If all available application upgrades are deployed to maintain software currency, then system modernization is improved, but vulnerable versions may be distributed
Solution Approach 1:
The system implements feedback by generating vulnerability reports that provide information about which upgrade versions contain vulnerabilities. This feedback loop allows organizations to identify safe upgrade paths and make informed decisions about which upgrades to deploy, balancing modernization goals with security requirements.
Data Source
AI summary
In general, embodiments relate to a method for proactively detecting and filtering vulnerabilities of an application upgrade, comprising: receiving an application upgrade request to upgrade an application to a version from a client device; sending information related to the application upgrade to a vulnerability validator; determining, based on the impact score information, that the version of the application has vulnerabilities and that a second version of the application does not have vulnerabilities; filtering, based on the determining, the version of the application that has vulnerabilities; generating an application upgrade strategy by only considering the second version of the application; and sending information related to the version of the application to a vendor to fix the vulnerabilities.


