Application Vulnerability Scanning Using Relevancy-Based Data Selection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing systems fail to effectively monitor and manage vulnerabilities in internet resources associated with entities, such as enterprises, organizations, and individuals, necessitating an integrated platform for comprehensive vulnerability assessment and reporting.
Innovation Solution
A monitoring system that includes a scanning engine and relevancy determinator to obtain and analyze data items from target applications, automatically scanning at predetermined times to identify vulnerabilities based on relevancy conditions, and generating a vulnerability report.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If manual vulnerability assessment methods are used, then detection precision can be maintained, but productivity is severely limited and time-consuming
Solution Approach 1:
The system enables automated self-assessment of vulnerabilities through the scanning engine that automatically scans target applications using obtained data items, eliminating the need for continuous manual intervention while maintaining comprehensive detection coverage
Solution Approach 2:
The monitoring system performs preliminary data collection and storage in advance by obtaining and storing data items from target applications in categorized storage, preparing the foundation for subsequent automated vulnerability scanning and assessment
2Measurement precision
If comprehensive data collection is performed to improve vulnerability detection accuracy, then measurement precision improves, but device complexity increases
Solution Approach 1:
The system segments data items into different categories using categorized storage, organizing collected data by type and relevance to facilitate systematic vulnerability analysis while maintaining manageable system complexity
Solution Approach 2:
The relevancy determinator acts as an intermediary component that analyzes obtained data items to determine their relevance to potential vulnerabilities, filtering and prioritizing data before passing it to the scanning engine for detailed assessment
3Ease of operation
If automated scanning is implemented to improve productivity, then ease of operation improves, but measurement precision may deteriorate due to automation limitations
Solution Approach 1:
The system incorporates feedback mechanisms where the relevancy determinator continuously analyzes scanning results and adjusts the selection of data items for scanning, refining the detection process based on observed patterns and improving both automation effectiveness and detection precision
Solution Approach 2:
The scanning process is made dynamic by allowing the system to adaptively select which data items to scan based on relevancy analysis, changing the scanning scope and focus according to the specific characteristics of the target application and identified vulnerabilities
Data Source
AI summary
A method for obtaining target data items from a target application to determine vulnerabilities of the target application is provided. The method includes obtaining a plurality of first data items from the target application; analyzing the plurality of first data items to obtain relevancies for the plurality of first data items; when the relevancies satisfy a first condition, automatically scanning the target application at first pre-determined times to obtain a plurality of first target data items associated with the input data; when relevancies satisfy a second condition, selecting one or more second data items from the plurality of first data items, and scanning the target application at second pre-determined times to obtain a plurality of second target data items associated with input data; obtaining target data items associated with the target application and determining whether the target application is vulnerable based on the target data items that are obtained.


