Crowdsourced Vulnerability Detection via Attack Surface Feature Vectors

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity methods fail to fully leverage the potential of crowds and online communities for detecting IT vulnerabilities, particularly in identifying vulnerabilities in target systems among multiple IT assets and establishing attack surfaces as feature vectors for effective similarity-based detection.

Innovation Solution

A system and method that utilize a corpus of known vulnerabilities from various IT assets to establish a similarity measure between a target asset and other assets with known vulnerabilities, leveraging a community of researchers to review and determine unknown vulnerabilities through bounty programs, public discussions, and machine learning techniques.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional vulnerability detection methods are used, then detection capability is limited to known vulnerability patterns, but the ability to detect unknown vulnerabilities in target systems among multiple IT assets deteriorates

Engineering Contradiction:
Improvevulnerability detection capabilityVSAvoidability to detect unknown vulnerabilities
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system dynamically adapts its detection approach by transitioning from static pattern matching to dynamic similarity-based detection. It computes attack surface feature vectors for target systems and compares them against a corpus of known vulnerable systems, enabling the detection capability to evolve and adapt to unknown vulnerability types rather than relying on fixed detection patterns.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The invention changes the detection parameters from traditional vulnerability signature matching to attack surface feature vector comparison. By representing systems as feature vectors based on their attack surfaces and computing similarity measures, the system can detect vulnerabilities based on structural and functional similarities rather than known vulnerability patterns, thereby improving detection of unknown vulnerabilities.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If comprehensive vulnerability analysis is performed on all IT assets, then detection accuracy improves, but computational complexity and time consumption increase

Engineering Contradiction:
Improvevulnerability detection accuracyVSAvoidcomputational complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system extracts only the essential attack surface features from IT assets to create compact feature vectors. Instead of analyzing all possible system attributes, it focuses on extracting relevant attack surface characteristics that are sufficient for vulnerability detection, thereby reducing computational complexity while maintaining detection accuracy through similarity comparison.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The invention creates simplified copies of IT assets in the form of attack surface feature vectors. These vector representations serve as lightweight copies that capture the essential vulnerability-relevant characteristics without requiring full system analysis, enabling efficient similarity-based detection across multiple assets with reduced computational overhead.

Inventive Principle:
Principle #26Copying

3Reliability

If manual vulnerability assessment is conducted by security experts, then detection reliability improves, but productivity and scalability deteriorate

Engineering Contradiction:
Improvevulnerability detection reliabilityVSAvoidvulnerability detection throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system introduces an intermediary automated similarity comparison mechanism that bridges manual expert assessment and automated detection. The attack surface feature vector comparison acts as an intermediary that captures expert-like reasoning in an automated form, enabling scalable vulnerability detection that maintains reliability by using structured feature comparison rather than raw automated scanning or manual review.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Adaptability or versatility

If vulnerability corpus is continuously updated with new data, then detection coverage improves, but data management complexity and storage requirements increase

Engineering Contradiction:
Improvevulnerability detection coverageVSAvoidcorpus data volume
Core Design Contradiction:
Adaptability or versatilityVSQuantity of substance

Solution Approach 1:

The system creates compact vector representations as simplified copies of vulnerability data. Instead of storing and processing full vulnerability reports and system configurations, it maintains a corpus of attack surface feature vectors that capture the essential characteristics needed for detection, thereby improving detection coverage while reducing data management complexity and storage requirements.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11019091B2Vulnerability detection in IT assets by utilizing crowdsourcing techniques
Publication Date: 2021.05.25 BUGCROWD INC
  • US11019091B2 patent drawing
  • US11019091B2 patent drawing
  • US11019091B2 patent drawing

AI summary

This invention discloses systems and methods for detecting vulnerabilities in IT assets by utilizing crowdsourcing techniques. A corpus containing vulnerability data of IT assets with known vulnerabilities is established. Vulnerability data in the corpus comprises security aspects or attributes related to the IT assets. The security aspects of an IT asset constitute its attack surface which is represented as a feature vector in a feature space. A determination is made as to how similar/close a target asset whose unknown vulnerabilities are to be detected, is to the rest of the IT assets in the corpus. This determination is made based on a measure of similarity/distance between the respective feature vectors in the feature space. Based on the review of similarity results by a community of researchers/experts, a determination of unknown vulnerabilities in the target system is made.