Application Upgrade Vulnerability Detection and Filtering

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Users are unaware of potential vulnerabilities in application upgrades before performing them, leading to potential security risks.

Innovation Solution

A method and system that proactively detect and filter out vulnerabilities by using a vulnerability validator and device emulation orchestration engine to generate an application upgrade strategy for secure upgrades.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If application upgrades are performed to protect from security vulnerabilities, then security reliability is improved, but users may inadvertently install vulnerable versions due to lack of awareness

Engineering Contradiction:
Improvesecurity reliabilityVSAvoidsecurity risks from vulnerable upgrades
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The vulnerability validator performs preliminary validation of application upgrades before they are installed on client devices. The system proactively detects vulnerabilities in candidate upgrade versions and generates reports indicating which versions are safe, allowing administrators to make informed decisions before deployment, thus preventing the installation of vulnerable upgrades.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The vulnerability validator acts as an intermediary between the application upgrade process and the client devices. It receives upgrade information, validates it against known vulnerability data, and provides guidance on safe upgrades, mediating between the need for updates and the risk of introducing vulnerabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If all available application upgrades are deployed to maintain software currency, then system modernization is improved, but vulnerable versions may be distributed

Engineering Contradiction:
Improvesystem modernizationVSAvoidsecurity reliability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system implements feedback by generating vulnerability reports that provide information about which upgrade versions contain vulnerabilities. This feedback loop allows organizations to identify safe upgrade paths and make informed decisions about which upgrades to deploy, balancing modernization goals with security requirements.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12141293B2Method and system for proactively detecting and filtering vulnerabilities of an application upgrade before performing the application upgrade
Publication Date: 2024.11.12 DELL PROD LP
  • US12141293B2 patent drawing
  • US12141293B2 patent drawing
  • US12141293B2 patent drawing

AI summary

In general, embodiments relate to a method for proactively detecting and filtering vulnerabilities of an application upgrade, comprising: receiving an application upgrade request to upgrade an application to a version from a client device; sending information related to the application upgrade to a vulnerability validator; determining, based on the impact score information, that the version of the application has vulnerabilities and that a second version of the application does not have vulnerabilities; filtering, based on the determining, the version of the application that has vulnerabilities; generating an application upgrade strategy by only considering the second version of the application; and sending information related to the version of the application to a vendor to fix the vulnerabilities.