CPE Tree Keyword Analysis for Open Port Vulnerability Identification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for generating Common Platform Enumeration (CPE) information are limited in analyzing various CPE candidates, making it difficult to rapidly identify and interlock with CVE vulnerability information for software security vulnerabilities.
Innovation Solution
Performing keyword analysis on banner information of an open port using a CPE dictionary to create a CPE tree, search keywords at respective levels, and generate CPEs that match the format of the dictionary, thereby identifying CPE type vulnerability information that can interlock with CVE vulnerability information.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Ease of manufacture
If CPE information is generated by searching product information based on a fixed pattern (Integer.Integer.Integer), then the generation process is simple, but the ability to analyze various CPE candidates is limited
Solution Approach 1:
The patent segments the CPE identification process into multiple hierarchical levels (CPE dictionary, CPE tree with multiple levels, and keyword matching stages). Instead of using a single fixed pattern, the system divides the analysis into structured components that can handle various CPE formats systematically
Solution Approach 2:
The patent transforms the static fixed pattern approach into a dynamic multi-level tree structure that can adapt to different CPE candidates. The CPE tree allows flexible navigation and matching at different levels, enabling the system to handle diverse product information formats dynamically
2Adaptability or versatility
If a multi-level CPE tree structure with keyword analysis is implemented, then various CPE candidates can be analyzed comprehensively, but the system complexity increases
Solution Approach 1:
The complex CPE analysis task is segmented into manageable components: CPE dictionary acquisition, CPE tree construction with multiple levels, keyword extraction from service information, and hierarchical matching. Each component handles a specific aspect, making the overall complex system manageable and maintainable
Solution Approach 2:
The patent introduces a CPE tree as an intermediary structure between the raw service information and the final CPE identification. This intermediary organizes the analysis process into structured levels, simplifying the complexity by providing a clear hierarchical framework for keyword matching and CPE candidate evaluation
3Measurement precision
If comprehensive keyword analysis is performed on banner information, then CPE type vulnerability information can be accurately identified, but the time required for vulnerability identification increases
Solution Approach 1:
The patent performs preliminary actions by pre-building the CPE tree structure and organizing the CPE dictionary before actual vulnerability scanning. This preparation work is done once, and then during vulnerability identification, the system can quickly match keywords against the pre-organized tree structure, reducing identification time while maintaining comprehensive analysis
Solution Approach 2:
The keyword analysis is segmented into hierarchical levels within the CPE tree, allowing the system to perform targeted matching at each level rather than exhaustive full-text analysis. This segmented approach maintains high accuracy by systematically checking each level while reducing overall processing time through efficient hierarchical navigation
Data Source
AI summary
Provided are a method and an apparatus for identifying computer system information which process banner information of an open port of a computer system, create a CPE tree by analyzing a CPE dictionary, and search keywords of respective levels of the CPE tree in a banner and generate one or more CPEs based on the CPE tree observing a format of the CPE dictionary to select CPEs which most match information of an operating system or an application program of a specific computer system among various CPE candidates and rapidly and easily identify CPE type vulnerability information which can interlock with CVE vulnerability information.


