Dynamic Security Testing for Vulnerability Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional security testing methods are inadequate for dynamically-discoverable security assets, particularly in environments with limited supervision over the attack surface, leading to increased vulnerabilities when components are accessible over insecure networks.
Innovation Solution
A system comprising input collectors, security asset analysis components, test management engines, and reporting components that dynamically discover, analyze, and test security assets for vulnerabilities, allowing for periodic scanning, prioritization, and scheduling of security tests across computer networks.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If centralized controls are implemented to approve and authorize new components exposed to insecure networks, then information security is improved, but development progress is stymied
Solution Approach 1:
The system performs preliminary security testing and vulnerability scanning on components before they are deployed to production environments. By conducting security assessments in advance during the development phase, the system eliminates the need for centralized approval delays while ensuring security requirements are met before components become operational.
Solution Approach 2:
The system enables automated self-testing and self-validation of security assets through continuous monitoring and scanning. Components can autonomously undergo security assessments and receive automatic updates, eliminating the need for manual centralized control while maintaining high security standards through persistent automated validation.
2Object-affected harmful factors
If the attack surface is reduced by turning off unnecessary functionality and components, then security risks are reduced, but adaptability and versatility of the system deteriorate
Solution Approach 1:
The system dynamically discovers, monitors, and tests security assets in real-time, allowing the attack surface to be adaptively managed rather than statically reduced. The system can identify newly exposed components, assess their security posture, and respond to changing threats without requiring permanent disabling of functionalities, thus maintaining both security and adaptability.
Solution Approach 2:
The system continuously scans and provides feedback on the security status of all components and assets. This real-time feedback mechanism allows the system to identify and address security vulnerabilities in newly added functionalities without requiring pre-approval or permanent reduction of system capabilities, enabling secure adaptability.
3Ease of operation
If components are made accessible over insecure networks like the Internet, then user access and interaction are improved, but vulnerability to unauthorized uses and attacks increases
Solution Approach 1:
The system performs preliminary security scanning and vulnerability assessment on components before they are made accessible over insecure networks. By conducting security evaluations in advance, the system ensures that components are hardened and secure before exposure, enabling safe remote access without increasing vulnerability to attacks.
Solution Approach 2:
The system implements continuous security monitoring and scanning of components accessible over insecure networks. This ongoing security validation ensures that components remain protected against evolving threats while maintaining uninterrupted user access, eliminating the trade-off between accessibility and security.
Data Source
AI summary
A method and system for discovering and testing security assets is provided. Based on source definition data describing sources to monitor on the one or more computer networks, an example system scans the sources to identify security assets. The system analyses the security assets to identify characteristics of the server-based applications. The system stores database records describing the security assets and the identified characteristics. The system queries the database records to select, based at least on the identified characteristics, one or more target assets, from the security assets, on which to conduct one or more security tests. Responsive to selecting the one or more target assets, the system conducts the one or more security tests on the one or more target assets. The system identifies one or more security vulnerabilities at the one or more target assets based on the conducted one or more security tests.


