Crowd-Sourced Security Assessment Platform

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security evaluation methods are primarily responsive and impractical for exhaustive testing of all network elements and computing devices against known attacks, leaving enterprise web applications and server computers vulnerable until a security event is identified and addressed.

Innovation Solution

A crowd-sourced approach involving globally distributed researchers, where reputation and skills are assessed, and incentives are provided for identifying computer vulnerabilities, using a system that monitors communications and validates reports to rapidly discover and remediate security vulnerabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional automated or manual security testing methods are used, then security vulnerabilities can be identified, but the process is too slow and impractical for exhaustive testing of all network elements

Engineering Contradiction:
Improvevulnerability identification accuracyVSAvoidtesting speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent segments the security testing task by dividing the network into multiple discrete elements (web applications, server computers, database systems, etc.) and assigning different elements to different researchers. This segmentation enables parallel testing of multiple network elements simultaneously, dramatically increasing productivity while maintaining thorough coverage through systematic division of the testing scope.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces a new dimension to security testing by transitioning from traditional automated scanning or limited manual testing to a crowd-sourced model that leverages the geographic and skill-based distribution of global security researchers. This dimensional shift transforms the testing approach from a single-point or centralized process to a distributed network of testers, enabling both increased speed and comprehensive coverage.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

2Reliability

If exhaustive testing of all network elements against all known attacks is performed, then complete security coverage is achieved, but the complexity and resources required become impractical

Engineering Contradiction:
Improvesecurity coverage completenessVSAvoidtesting system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by creating a platform that serves multiple functions: it manages researcher recruitment, assignment, monitoring, validation, and incentive distribution. This multi-functional system handles diverse vulnerability types (SQL injection, cross-site scripting, buffer overflows, etc.) across different network elements through a single unified approach, reducing overall system complexity while maintaining comprehensive security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent introduces an intermediary management system that coordinates between security researchers and the network elements being tested. This intermediary handles the complexity of task assignment, progress monitoring, and result validation, shielding the client from the complexity of managing numerous individual researchers while ensuring complete and systematic testing coverage.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Productivity

If a distributed crowd of researchers is used to rapidly identify vulnerabilities, then testing productivity increases, but the system complexity and coordination requirements increase

Engineering Contradiction:
Improvevulnerability discovery speedVSAvoidcoordination system complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent implements feedback mechanisms throughout the testing process: researchers receive feedback on their findings through the platform, the system provides real-time monitoring of testing progress, and validation feedback is given when vulnerabilities are confirmed. This continuous feedback loop coordinates the distributed researchers efficiently, maintaining high productivity while managing system complexity through automated status tracking and result verification.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent manages coordination complexity by dynamically adjusting parameters such as researcher assignment based on expertise, incentive amounts based on vulnerability severity, and task allocation based on current testing progress. These parameter changes are automated through the platform, enabling flexible coordination of a large distributed team without proportionally increasing system complexity.

Inventive Principle:
Principle #35Parameter changes

4Measurement precision

If manual examination of network configurations is performed to address vulnerabilities, then accurate security assessment is achieved, but the response time is too slow to be preventive

Engineering Contradiction:
Improvesecurity assessment accuracyVSAvoidvulnerability response time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent enables preliminary action by proactively identifying and reporting vulnerabilities before they can be exploited in production environments. The crowd-sourced testing continuously scans and assesses network elements, detecting security issues in advance and allowing organizations to remediate them before actual security events occur, transforming security from a reactive to a preventive function.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent establishes continuity of useful action through ongoing, continuous security testing by the distributed researcher network. Rather than periodic assessments, the system maintains constant monitoring and vulnerability detection capabilities, ensuring that security assessment is an ongoing preventive process rather than an intermittent reactive measure, thereby eliminating downtime while maintaining accurate assessment.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS10521593B2Security assessment incentive method for promoting discovery of computer software vulnerabilities
Publication Date: 2019.12.31 SYNACK
  • US10521593B2 patent drawing
  • US10521593B2 patent drawing
  • US10521593B2 patent drawing

AI summary

In one aspect, the disclosure provides: A method comprising: assessing a plurality of researchers as a precondition for receiving an invitation to be a researcher of a distributed plurality of researchers, resulting in the distributed plurality of researchers wherein each researcher is associated with one or more tags in records that identify the researcher for one or more attributes; inviting a subset of the distributed plurality of researchers to participate in one or more computer vulnerability research projects directed to identifying computer vulnerabilities of one or more computers that are owned or operated by a third party, the subset of the distributed plurality of researchers selected based on the one or more tags in records that identify the researcher and a description of the computer vulnerabilities of the one or more computers; using a computer that is communicatively coupled to a particular researcher among the subset of the distributed plurality of researchers and a network under test among the one or more computers, monitoring communications between the particular researcher and the particular third party computer, wherein the communications relate to attempting to identify a candidate security vulnerability of the particular third party computer; in response to a report of the candidate security vulnerability of the particular third party computer that is received from the particular researcher, evaluating the report of the candidate security vulnerability.