Automated Penetration Testing for Release Candidate Certification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Manual penetration testing is time-consuming and reactive, often neglecting internal-facing applications due to resource constraints, and results in poor quality and incomplete regression testing.

Innovation Solution

Implementing rules-based automated penetration testing systems that generate malformed URLs by injecting vulnerabilities into applications, using a URL scanner and malformer, and executing validation algorithms to certify release candidates, integrated into a continuous integration/continuous delivery pipeline.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual penetration testing is performed, then testing depth and quality can be maintained, but testing time increases significantly and resource consumption increases

Engineering Contradiction:
Improvetesting qualityVSAvoidtesting time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent creates automated copies of manual penetration testing processes through virtualized testing environments. Virtual machines replicate the manual tester's actions, allowing repeated and consistent testing without human intervention, thus maintaining quality while reducing time.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The patent replaces manual mechanical testing operations with automated software-based virtualization systems. The manual penetration testing process is converted into automated scripts and virtual machine configurations that execute tests automatically, eliminating the time-consuming manual steps while preserving testing thoroughness.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If manual penetration testing is performed, then testing depth can be maintained, but the scope of testing is limited due to resource constraints

Engineering Contradiction:
Improvetesting depthVSAvoidtesting scope
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent implements a universal automated penetration testing platform that can test multiple application types (web applications, mobile applications, cloud services) using the same virtualized infrastructure. This multi-functional system expands testing scope across different domains while maintaining consistent depth through standardized test templates.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments the penetration testing process into modular components: virtual machine images, test scripts, and configuration templates. This segmentation allows the system to efficiently scale and adapt to different testing scenarios, expanding scope without compromising depth through reusable modular units.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If manual penetration testing is performed, then vulnerability detection accuracy can be maintained, but regression testing quality is poor

Engineering Contradiction:
Improvevulnerability detection accuracyVSAvoidregression testing quality
Core Design Contradiction:
Measurement precisionVSManufacturing precision

Solution Approach 1:

The patent implements automated feedback mechanisms where test results from virtual machines are automatically analyzed and compared against baseline vulnerability data. This feedback loop ensures consistent and accurate regression testing by automatically detecting changes in vulnerability status, maintaining both accuracy and quality.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent uses virtual machine copying to create identical test environments for regression testing. By copying the exact application state and testing configuration, the system ensures that regression tests reproduce previous conditions accurately, maintaining both vulnerability detection accuracy and regression testing quality.

Inventive Principle:
Principle #26Copying

4Productivity

If automated penetration testing is implemented, then testing time is reduced, but system complexity increases

Engineering Contradiction:
Improvetesting speedVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent employs nested virtual machine structures where test virtual machines are contained within a management virtualization layer. This nesting approach organizes complexity hierarchically, allowing the system to achieve high productivity through automation while managing complexity through structured layers of virtualization.

Inventive Principle:
Principle #7Nested doll (Nesting)

Data Source

PatentUS11921862B2Systems and methods for rules-based automated penetration testing to certify release candidates
Publication Date: 2024.03.05 JPMORGAN CHASE BANK NA
  • US11921862B2 patent drawing
  • US11921862B2 patent drawing

AI summary

Systems and methods for rules-based automated penetration testing and regression to certify release candidates against known patterns that inject vulnerabilities are disclosed. In one embodiment, a method for rules-based automated penetration testing to certify release candidates may include: (1) receiving, at a penetration test computer program executed by a computer processor, a plurality of URLs for an application to be tested; (2) retrieving, by the penetration test computer program and from a rules pack in a database, an URL injectible and a URL parameter for the URL injectible; (3) generating, by a URL scanner and malformer computer program, a malformed URL, wherein the malformed URL may include one of the URLs injected with the URL injectible injected at the parameter in the URL; (4) firing, by the penetration test computer program, the malformed URL; (5) receiving, by the penetration test computer program, an output from the application; and (6) executing at least one validation algorithm on the output.