Entry Point Finder for Patch Impact Assessment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing security measures for business-critical applications, such as ERP systems, face challenges in identifying and addressing vulnerabilities introduced by patch implementations and managing unnecessary privileges, which can lead to security breaches and system instability.
Innovation Solution
The Entry Point Finder (EPF) system analyzes business-critical applications to create a graphical representation of software objects and their relationships, enabling the detection of entry points, impact assessment of patches, identification of unnecessary privileges, and generation of vulnerability detection rules, thereby enhancing security and reducing manual effort.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual analysis methods are used to identify vulnerabilities and assess patch impacts, then thorough security assessment can be achieved, but the time and effort required increases significantly
Solution Approach 1:
The patent replaces manual mechanical analysis with an automated computer-based system that uses algorithms to extract software objects, build dependency graphs, and identify entry points. This substitution maintains thorough vulnerability detection while dramatically reducing the time and human effort required for security assessments.
Solution Approach 2:
The patent introduces an intermediary automated analysis system that acts as a mediator between the complex software system and security assessors. This intermediary automatically performs the tedious work of tracing dependencies and identifying vulnerabilities, allowing security professionals to focus on high-level decision-making while maintaining detection accuracy.
2Reliability
If comprehensive security scanning of all software objects is performed, then all vulnerabilities can be detected, but the complexity of the analysis system increases
Solution Approach 1:
The patent segments the complex security analysis task into distinct automated components: software object extraction, dependency relationship identification, entry point detection, and vulnerability assessment. This segmentation maintains comprehensive security scanning while reducing overall system complexity by making each component specialized and manageable.
Solution Approach 2:
The patent implements a dynamic analysis approach that automatically adapts the scanning depth and focus based on the specific software architecture being analyzed. The system dynamically traces dependencies only where necessary to identify entry points, avoiding unnecessary analysis of unrelated code paths and reducing complexity while maintaining reliability.
3Productivity
If automated entry point detection is implemented, then the time required for vulnerability identification is reduced, but the precision of detecting actual security threats may decrease
Solution Approach 1:
The patent performs preliminary automated extraction and organization of all software objects and their dependencies before the actual vulnerability detection phase. This preliminary action creates a structured foundation that enables fast automated entry point detection while maintaining precision, because the system has already mapped all potential attack paths in advance.
Solution Approach 2:
The patent implements feedback mechanisms where the automated system continuously refines its entry point detection based on analyzed results. The system learns from each analysis cycle, improving its precision in identifying actual security threats versus false positives, while maintaining high productivity through automation.
Data Source
AI summary
A computer-based method is disclosed for assessing impact of a patch on a target business-critical application computer system. The method includes receiving information at a computer-based impact assessment system about end-user activities on the target business-critical application computer system over a specified period of time; identifying, with a computer-based fixed objects identifier, one or more software objects in the target business-critical application computer system fixed by the patch; identifying, with a computer-based entry point finder, one or more entry points associated with the fixed software object(s) at the target business-critical application system; and cross-referencing the information about the end-user activities on the target business-critical application system against the one or more entry points associated with the fixed software object(s) at the target business-critical application system. The cross-referencing may reveal which of the entry points associated with the fixed software object(s) also have been used by the end-users of the target business-critical application system during the specified time period.


