Crowd-Sourced Security Assessment Platform
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security evaluation methods are primarily responsive and impractical for exhaustive testing of all network elements and computing devices against known attacks, leaving enterprise web applications and server computers vulnerable until a security event is identified and addressed.
Innovation Solution
A crowd-sourced approach involving globally distributed researchers, where reputation and skills are assessed, and incentives are provided for identifying computer vulnerabilities, using a system that monitors communications and validates reports to rapidly discover and remediate security vulnerabilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional automated or manual security testing methods are used, then security vulnerabilities can be identified, but the process is too slow and impractical for exhaustive testing of all network elements
Solution Approach 1:
The patent segments the security testing task by dividing the network into multiple discrete elements (web applications, server computers, database systems, etc.) and assigning different elements to different researchers. This segmentation enables parallel testing of multiple network elements simultaneously, dramatically increasing productivity while maintaining thorough coverage through systematic division of the testing scope.
Solution Approach 2:
The patent introduces a new dimension to security testing by transitioning from traditional automated scanning or limited manual testing to a crowd-sourced model that leverages the geographic and skill-based distribution of global security researchers. This dimensional shift transforms the testing approach from a single-point or centralized process to a distributed network of testers, enabling both increased speed and comprehensive coverage.
2Reliability
If exhaustive testing of all network elements against all known attacks is performed, then complete security coverage is achieved, but the complexity and resources required become impractical
Solution Approach 1:
The patent applies universality by creating a platform that serves multiple functions: it manages researcher recruitment, assignment, monitoring, validation, and incentive distribution. This multi-functional system handles diverse vulnerability types (SQL injection, cross-site scripting, buffer overflows, etc.) across different network elements through a single unified approach, reducing overall system complexity while maintaining comprehensive security coverage.
Solution Approach 2:
The patent introduces an intermediary management system that coordinates between security researchers and the network elements being tested. This intermediary handles the complexity of task assignment, progress monitoring, and result validation, shielding the client from the complexity of managing numerous individual researchers while ensuring complete and systematic testing coverage.
3Productivity
If a distributed crowd of researchers is used to rapidly identify vulnerabilities, then testing productivity increases, but the system complexity and coordination requirements increase
Solution Approach 1:
The patent implements feedback mechanisms throughout the testing process: researchers receive feedback on their findings through the platform, the system provides real-time monitoring of testing progress, and validation feedback is given when vulnerabilities are confirmed. This continuous feedback loop coordinates the distributed researchers efficiently, maintaining high productivity while managing system complexity through automated status tracking and result verification.
Solution Approach 2:
The patent manages coordination complexity by dynamically adjusting parameters such as researcher assignment based on expertise, incentive amounts based on vulnerability severity, and task allocation based on current testing progress. These parameter changes are automated through the platform, enabling flexible coordination of a large distributed team without proportionally increasing system complexity.
4Measurement precision
If manual examination of network configurations is performed to address vulnerabilities, then accurate security assessment is achieved, but the response time is too slow to be preventive
Solution Approach 1:
The patent enables preliminary action by proactively identifying and reporting vulnerabilities before they can be exploited in production environments. The crowd-sourced testing continuously scans and assesses network elements, detecting security issues in advance and allowing organizations to remediate them before actual security events occur, transforming security from a reactive to a preventive function.
Solution Approach 2:
The patent establishes continuity of useful action through ongoing, continuous security testing by the distributed researcher network. Rather than periodic assessments, the system maintains constant monitoring and vulnerability detection capabilities, ensuring that security assessment is an ongoing preventive process rather than an intermittent reactive measure, thereby eliminating downtime while maintaining accurate assessment.
Data Source
AI summary
In one aspect, the disclosure provides: A method comprising: assessing a plurality of researchers as a precondition for receiving an invitation to be a researcher of a distributed plurality of researchers, resulting in the distributed plurality of researchers wherein each researcher is associated with one or more tags in records that identify the researcher for one or more attributes; inviting a subset of the distributed plurality of researchers to participate in one or more computer vulnerability research projects directed to identifying computer vulnerabilities of one or more computers that are owned or operated by a third party, the subset of the distributed plurality of researchers selected based on the one or more tags in records that identify the researcher and a description of the computer vulnerabilities of the one or more computers; using a computer that is communicatively coupled to a particular researcher among the subset of the distributed plurality of researchers and a network under test among the one or more computers, monitoring communications between the particular researcher and the particular third party computer, wherein the communications relate to attempting to identify a candidate security vulnerability of the particular third party computer; in response to a report of the candidate security vulnerability of the particular third party computer that is received from the particular researcher, evaluating the report of the candidate security vulnerability.


