Automated Task Assignment for Vulnerability Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security evaluation methods are primarily responsive and impractical for exhaustively testing all network elements and computing devices for vulnerabilities, leaving enterprise web applications and server computers exposed until an actual security event is identified.

Innovation Solution

A crowd-sourced approach involving globally distributed researchers, where vulnerabilities are identified and incentivized through a taxonomy-based reward system, allowing for rapid and scalable vulnerability assessment and remediation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual security testing and evaluation is performed by network administrators, then security vulnerabilities can be identified and addressed, but the process is time-consuming and cannot keep pace with the variety and frequency of attacks

Engineering Contradiction:
Improvesecurity vulnerability identificationVSAvoidtime to identify and address vulnerabilities
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the security testing workload by dividing it into discrete, manageable tasks that can be independently assigned and executed. Vulnerability assessments are broken down into specific test cases that can be performed by individual researchers, allowing parallel processing and faster overall completion while maintaining thorough coverage.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an automated task management system as an intermediary between vulnerability detection needs and researcher execution. This system automatically generates tasks from vulnerability data, assigns them to appropriate researchers, tracks progress, and consolidates results, eliminating manual coordination overhead and accelerating the security assessment process.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If exhaustive testing of all network elements is attempted to ensure comprehensive security coverage, then all vulnerabilities can be identified, but the complexity and resource requirements become impractical

Engineering Contradiction:
Improvecomprehensive security coverageVSAvoidcomplexity of security testing system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent divides the comprehensive security testing into segmented tasks based on vulnerability types, network elements, and attack vectors. Each task focuses on a specific aspect rather than requiring complete manual testing of all elements, making the overall process manageable while maintaining comprehensive coverage through systematic task distribution.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system enables self-service automation where the task management system automatically generates test tasks, assigns them to researchers, tracks completion status, and consolidates results without requiring manual intervention for each step. This automated self-service approach handles the complexity of coordinating exhaustive testing across multiple researchers and elements.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If manual examination of network configurations is performed to determine security issues, then accurate vulnerability assessment can be made, but the process cannot scale to large enterprises with numerous network elements

Engineering Contradiction:
Improveaccuracy of vulnerability assessmentVSAvoidscalability of security assessment
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent introduces an automated task management intermediary that handles the coordination and tracking of vulnerability assessments across numerous network elements. This system maintains measurement precision by ensuring each element is properly assessed while enabling scalability through automated task distribution, progress tracking, and result consolidation across large numbers of researchers and network elements.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent segments large-scale security assessments into smaller, standardized tasks that can be independently executed and later consolidated. This segmentation allows accurate assessment of each individual element while enabling the overall process to scale to enterprise-level networks by distributing tasks across multiple researchers simultaneously.

Inventive Principle:
Principle #1Segmentation

4Reliability

If responsive security monitoring is implemented to detect actual security events, then security breaches can be identified, but vulnerabilities remain exposed during the period before detection

Engineering Contradiction:
Improvesecurity event detectionVSAvoidperiod of vulnerability exposure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The patent implements preliminary security testing and vulnerability assessment through automated task generation and researcher execution before actual security events occur. By proactively identifying and addressing vulnerabilities through segmented test tasks rather than waiting for responsive detection, the system reduces the period of vulnerability exposure while maintaining reliable security monitoring.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS10628764B1Method of automatically generating tasks using control computer
Publication Date: 2020.04.21 SYNACK
  • US10628764B1 patent drawing
  • US10628764B1 patent drawing
  • US10628764B1 patent drawing

AI summary

In one aspect, the disclosure provides: using a control computer logically positioned between one or more researcher computers and one or more systems under test, obtaining a task that identifies a potential security vulnerability of the one or more systems under test; determining a task type of the task associated with particular skills for investigating the potential security vulnerability; identifying a plurality of researcher computers who each have the particular skills; determining a task expiration of the task; determining a respective availability of the plurality of researcher computers; assigning the task to one or more researcher computers of the plurality of researcher computers determined to be available to complete the task; determining and providing an incentive to the one or more researcher computers in response to successfully validating the reports of the potential security vulnerability of the one or more systems under test.