Dynamic Security Testing for Vulnerability Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional security testing methods are inadequate for dynamically-discoverable security assets, particularly in environments with limited supervision over the attack surface, leading to increased vulnerabilities when components are accessible over insecure networks.

Innovation Solution

A system comprising input collectors, security asset analysis components, test management engines, and reporting components that dynamically discover, analyze, and test security assets for vulnerabilities, allowing for periodic scanning, prioritization, and scheduling of security tests across computer networks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If centralized controls are implemented to approve and authorize new components exposed to insecure networks, then information security is improved, but development progress is stymied

Engineering Contradiction:
Improveinformation securityVSAvoiddevelopment progress
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system performs preliminary security testing and vulnerability scanning on components before they are deployed to production environments. By conducting security assessments in advance during the development phase, the system eliminates the need for centralized approval delays while ensuring security requirements are met before components become operational.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system enables automated self-testing and self-validation of security assets through continuous monitoring and scanning. Components can autonomously undergo security assessments and receive automatic updates, eliminating the need for manual centralized control while maintaining high security standards through persistent automated validation.

Inventive Principle:
Principle #25Self-service

2Object-affected harmful factors

If the attack surface is reduced by turning off unnecessary functionality and components, then security risks are reduced, but adaptability and versatility of the system deteriorate

Engineering Contradiction:
Improvesecurity risksVSAvoidsystem functionality
Core Design Contradiction:
Object-affected harmful factorsVSAdaptability or versatility

Solution Approach 1:

The system dynamically discovers, monitors, and tests security assets in real-time, allowing the attack surface to be adaptively managed rather than statically reduced. The system can identify newly exposed components, assess their security posture, and respond to changing threats without requiring permanent disabling of functionalities, thus maintaining both security and adaptability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system continuously scans and provides feedback on the security status of all components and assets. This real-time feedback mechanism allows the system to identify and address security vulnerabilities in newly added functionalities without requiring pre-approval or permanent reduction of system capabilities, enabling secure adaptability.

Inventive Principle:
Principle #23Feedback

3Ease of operation

If components are made accessible over insecure networks like the Internet, then user access and interaction are improved, but vulnerability to unauthorized uses and attacks increases

Engineering Contradiction:
Improveuser accessVSAvoidvulnerability to attacks
Core Design Contradiction:
Ease of operationVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary security scanning and vulnerability assessment on components before they are made accessible over insecure networks. By conducting security evaluations in advance, the system ensures that components are hardened and secure before exposure, enabling safe remote access without increasing vulnerability to attacks.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous security monitoring and scanning of components accessible over insecure networks. This ongoing security validation ensures that components remain protected against evolving threats while maintaining uninterrupted user access, eliminating the trade-off between accessibility and security.

Inventive Principle:
Principle #20Continuity of useful action

Data Source

PatentUS10769282B2Dynamic security testing
Publication Date: 2020.09.08 NETFLIX INC
  • US10769282B2 patent drawing
  • US10769282B2 patent drawing
  • US10769282B2 patent drawing

AI summary

A method and system for discovering and testing security assets is provided. Based on source definition data describing sources to monitor on the one or more computer networks, an example system scans the sources to identify security assets. The system analyses the security assets to identify characteristics of the server-based applications. The system stores database records describing the security assets and the identified characteristics. The system queries the database records to select, based at least on the identified characteristics, one or more target assets, from the security assets, on which to conduct one or more security tests. Responsive to selecting the one or more target assets, the system conducts the one or more security tests on the one or more target assets. The system identifies one or more security vulnerabilities at the one or more target assets based on the conducted one or more security tests.