Application Vulnerability Scanning Using Relevancy-Based Data Selection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems fail to effectively monitor and manage vulnerabilities in internet resources associated with entities, such as enterprises, organizations, and individuals, necessitating an integrated platform for comprehensive vulnerability assessment and reporting.

Innovation Solution

A monitoring system that includes a scanning engine and relevancy determinator to obtain and analyze data items from target applications, automatically scanning at predetermined times to identify vulnerabilities based on relevancy conditions, and generating a vulnerability report.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual vulnerability assessment methods are used, then detection precision can be maintained, but productivity is severely limited and time-consuming

Engineering Contradiction:
Improvevulnerability assessment throughputVSAvoidtime for vulnerability detection
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system enables automated self-assessment of vulnerabilities through the scanning engine that automatically scans target applications using obtained data items, eliminating the need for continuous manual intervention while maintaining comprehensive detection coverage

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The monitoring system performs preliminary data collection and storage in advance by obtaining and storing data items from target applications in categorized storage, preparing the foundation for subsequent automated vulnerability scanning and assessment

Inventive Principle:
Principle #10Preliminary action

2Measurement precision

If comprehensive data collection is performed to improve vulnerability detection accuracy, then measurement precision improves, but device complexity increases

Engineering Contradiction:
Improvevulnerability detection accuracyVSAvoidsystem architecture complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system segments data items into different categories using categorized storage, organizing collected data by type and relevance to facilitate systematic vulnerability analysis while maintaining manageable system complexity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The relevancy determinator acts as an intermediary component that analyzes obtained data items to determine their relevance to potential vulnerabilities, filtering and prioritizing data before passing it to the scanning engine for detailed assessment

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of operation

If automated scanning is implemented to improve productivity, then ease of operation improves, but measurement precision may deteriorate due to automation limitations

Engineering Contradiction:
Improveautomation levelVSAvoidvulnerability detection accuracy
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The system incorporates feedback mechanisms where the relevancy determinator continuously analyzes scanning results and adjusts the selection of data items for scanning, refining the detection process based on observed patterns and improving both automation effectiveness and detection precision

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The scanning process is made dynamic by allowing the system to adaptively select which data items to scan based on relevancy analysis, changing the scanning scope and focus according to the specific characteristics of the target application and identified vulnerabilities

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS12596809B2Method for detecting vulnerabilities of target applications, device, and medium thereof
Publication Date: 2026.04.07 RMOUR LLC
  • US12596809B2 patent drawing
  • US12596809B2 patent drawing
  • US12596809B2 patent drawing

AI summary

A method for obtaining target data items from a target application to determine vulnerabilities of the target application is provided. The method includes obtaining a plurality of first data items from the target application; analyzing the plurality of first data items to obtain relevancies for the plurality of first data items; when the relevancies satisfy a first condition, automatically scanning the target application at first pre-determined times to obtain a plurality of first target data items associated with the input data; when relevancies satisfy a second condition, selecting one or more second data items from the plurality of first data items, and scanning the target application at second pre-determined times to obtain a plurality of second target data items associated with input data; obtaining target data items associated with the target application and determining whether the target application is vulnerable based on the target data items that are obtained.