Automated Vulnerability Management System for Application Source Code
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional vulnerability management techniques for expansive application networks are inefficient, requiring manual checks across multiple repositories, leading to operational inefficiencies and oversight of unresolved vulnerabilities.
Innovation Solution
Implementing automated job scheduling and automated issue ticketing systems that onboard applications, generate scheduled tasks for source code vulnerability analytics, detect vulnerabilities, and automatically initiate mitigation actions, with features like standardized ticketing and graphical dashboards for issue tracking and monitoring.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual vulnerability checks are performed across multiple application repositories, then developers can identify and resolve vulnerabilities, but the process becomes tedious and operationally inefficient
Solution Approach 1:
The system enables self-service vulnerability management by automatically onboarding applications, generating scheduled tasks for vulnerability scanning, detecting vulnerabilities, and creating tickets without requiring manual intervention from developers. The system monitors and manages vulnerabilities autonomously across multiple repositories.
Solution Approach 2:
The patent replaces manual mechanical processes with automated systems. Instead of developers manually checking repositories, the system uses automated job scheduling, vulnerability scanning tools, and ticketing mechanisms to perform vulnerability detection and management tasks automatically.
2Reliability
If developers manually track vulnerabilities across numerous application repositories, then they can resolve vulnerabilities, but oversight of unresolved vulnerabilities becomes difficult
Solution Approach 1:
The system implements continuous feedback mechanisms by automatically monitoring vulnerability status, generating tickets for unresolved vulnerabilities, and providing dashboards that display vulnerability overview and resolution status. This enables real-time oversight of vulnerability management across all applications.
Solution Approach 2:
The system provides a universal vulnerability management platform that handles multiple functions: onboarding applications, scheduling vulnerability scans, detecting vulnerabilities, creating tickets, assigning responsibilities, and monitoring resolution status. This consolidates what would otherwise require multiple separate manual processes into a single unified system.
3Productivity
If automated vulnerability scanning is implemented, then operational efficiency improves, but system complexity increases
Solution Approach 1:
The system segments vulnerability management into distinct modular components: application onboarding module, scheduled task generation module, vulnerability detection module, ticket creation module, and monitoring dashboard module. This segmentation makes the complex automated system more manageable and easier to implement.
Data Source
AI summary
A method for providing vulnerability management to facilitate application development and deployment is disclosed. The method includes receiving a monitoring request that includes an identifier, the identifier corresponding to an application; onboarding the application by using the identifier; generating a scheduled task for the application based on an outcome of the onboarding, the scheduled task relating to source code vulnerability analytics; automatically initiating, via an application programming interface, the scheduled task based on a predetermined parameter; determining whether a set of source codes that corresponds to the application includes a vulnerability based on a result of the automatically initiated scheduled task; and generating a ticket when the vulnerability is included in the set of source codes.


