Application Security Posture Mapping Through FQDN Infrastructure Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing vulnerability management systems fail to provide a holistic view of an application's security posture by separately analyzing the application and its underlying infrastructure, leading to tedious and error-prone processes in deriving overall security status.

Innovation Solution

A system and method that correlates and maps software applications to their infrastructure, integrating with vulnerability scanners to identify and combine vulnerabilities of both, using techniques such as FQDN mapping, CMDB integration, and tag-based mapping to provide a unified security posture assessment.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If vulnerability scanning is performed separately on applications and infrastructure, then each component can be scanned independently, but the overall security posture cannot be comprehensively assessed

Engineering Contradiction:
Improvesecurity posture assessment accuracyVSAvoidvulnerability correlation system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent merges application vulnerability scanning and infrastructure vulnerability scanning into a unified system that correlates and combines vulnerability data from both sources. The vulnerability management system integrates results from scanning the application code and the infrastructure (servers, networks, databases) to provide a comprehensive security posture assessment, resolving the contradiction by combining separate scanning processes into a coordinated unified approach.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The patent introduces a vulnerability correlation engine as an intermediary component that receives vulnerability data from separate scanning processes and correlates it with application-infrastructure mappings. This mediator synthesizes the separate vulnerability lists into a unified security posture assessment, enabling comprehensive evaluation without requiring direct integration of all scanning components.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If manual processes are used to derive overall security status, then flexibility is maintained, but the process becomes tedious and error-prone

Engineering Contradiction:
Improvesecurity assessment efficiencyVSAvoidsecurity status derivation accuracy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The vulnerability management system performs self-service by automatically correlating vulnerability data with application-infrastructure mappings and generating security posture assessments without requiring manual intervention. The system self-processes vulnerability scan results, cross-references them with infrastructure data, and produces comprehensive security reports, thereby improving both productivity and reliability by eliminating manual errors.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback mechanisms where vulnerability assessment results are continuously fed back into the vulnerability management process. The correlated vulnerability data and security posture information are used to update risk assessments and prioritize remediation efforts, creating a closed-loop system that improves accuracy and efficiency through continuous feedback and automatic adjustment.

Inventive Principle:
Principle #23Feedback

3Loss of information

If separate vulnerability reports are generated for application and infrastructure, then detailed analysis of each component is possible, but integrating them into a unified view is difficult

Engineering Contradiction:
Improvesecurity context completenessVSAvoidsecurity posture derivation ease
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The patent maintains segmentation by keeping separate vulnerability scanning and analysis processes for applications and infrastructure, allowing detailed component-specific analysis. However, it segments the data flow by creating distinct vulnerability lists that are then fed into a correlation engine, maintaining the benefits of detailed analysis while enabling integrated assessment through structured data separation and systematic reintegration.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The vulnerability management system achieves universality by serving multiple functions: it scans applications, scans infrastructure, correlates vulnerability data, generates detailed reports, and provides unified security posture assessments. This multi-functional approach eliminates the need for separate manual analysis processes and provides a single comprehensive view of security status, improving ease of operation while maintaining complete security context.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS12355795B2Application security posture identifier
Publication Date: 2025.07.08 HARNESS INC
  • US12355795B2 patent drawing
  • US12355795B2 patent drawing
  • US12355795B2 patent drawing

AI summary

Methods, systems, and apparatus, including computer programs encoded on a computer storage medium, for determining the security posture of an application are disclosed. In one aspect, a method includes the actions of receiving data identifying an application. The actions further include determining an FQDN of the application. The actions further include receiving data identifying a computing infrastructure. The actions further include determining a computing instance of the computing infrastructure. The actions further include determining an FQDN of the computing instance. The actions further include determining whether to provide, for output, data indicating whether the FQDN of the application matches the FQDN of the computing instance. The actions further include combining data indicating the vulnerabilities of the application and data indicating the vulnerabilities of the computing instance. The actions further include outputting, to a user associated with the application and to a user associated with the computing infrastructure, the combined data.