CPE Tree Keyword Analysis for Open Port Vulnerability Identification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for generating Common Platform Enumeration (CPE) information are limited in analyzing various CPE candidates, making it difficult to rapidly identify and interlock with CVE vulnerability information for software security vulnerabilities.

Innovation Solution

Performing keyword analysis on banner information of an open port using a CPE dictionary to create a CPE tree, search keywords at respective levels, and generate CPEs that match the format of the dictionary, thereby identifying CPE type vulnerability information that can interlock with CVE vulnerability information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Ease of manufacture

If CPE information is generated by searching product information based on a fixed pattern (Integer.Integer.Integer), then the generation process is simple, but the ability to analyze various CPE candidates is limited

Engineering Contradiction:
ImproveCPE information generation simplicityVSAvoidCPE candidate analysis capability
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The patent segments the CPE identification process into multiple hierarchical levels (CPE dictionary, CPE tree with multiple levels, and keyword matching stages). Instead of using a single fixed pattern, the system divides the analysis into structured components that can handle various CPE formats systematically

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transforms the static fixed pattern approach into a dynamic multi-level tree structure that can adapt to different CPE candidates. The CPE tree allows flexible navigation and matching at different levels, enabling the system to handle diverse product information formats dynamically

Inventive Principle:
Principle #15Dynamics

2Adaptability or versatility

If a multi-level CPE tree structure with keyword analysis is implemented, then various CPE candidates can be analyzed comprehensively, but the system complexity increases

Engineering Contradiction:
ImproveCPE candidate analysis capabilityVSAvoidsystem complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The complex CPE analysis task is segmented into manageable components: CPE dictionary acquisition, CPE tree construction with multiple levels, keyword extraction from service information, and hierarchical matching. Each component handles a specific aspect, making the overall complex system manageable and maintainable

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a CPE tree as an intermediary structure between the raw service information and the final CPE identification. This intermediary organizes the analysis process into structured levels, simplifying the complexity by providing a clear hierarchical framework for keyword matching and CPE candidate evaluation

Inventive Principle:
Principle #24Intermediary (Mediator)

3Measurement precision

If comprehensive keyword analysis is performed on banner information, then CPE type vulnerability information can be accurately identified, but the time required for vulnerability identification increases

Engineering Contradiction:
Improvevulnerability identification accuracyVSAvoidvulnerability identification time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by pre-building the CPE tree structure and organizing the CPE dictionary before actual vulnerability scanning. This preparation work is done once, and then during vulnerability identification, the system can quickly match keywords against the pre-organized tree structure, reducing identification time while maintaining comprehensive analysis

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The keyword analysis is segmented into hierarchical levels within the CPE tree, allowing the system to perform targeted matching at each level rather than exhaustive full-text analysis. This segmented approach maintains high accuracy by systematically checking each level while reducing overall processing time through efficient hierarchical navigation

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS10339319B2Method and apparatus for identifying vulnerability information using keyword analysis for banner of open port
Publication Date: 2019.07.02 KOREA INTERNET & SECURITY AGENCY
  • US10339319B2 patent drawing
  • US10339319B2 patent drawing
  • US10339319B2 patent drawing

AI summary

Provided are a method and an apparatus for identifying computer system information which process banner information of an open port of a computer system, create a CPE tree by analyzing a CPE dictionary, and search keywords of respective levels of the CPE tree in a banner and generate one or more CPEs based on the CPE tree observing a format of the CPE dictionary to select CPEs which most match information of an operating system or an application program of a specific computer system among various CPE candidates and rapidly and easily identify CPE type vulnerability information which can interlock with CVE vulnerability information.