Fusion Analyzer for Application Vulnerability Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for analyzing applications for security and quality issues are inadequate, as they often rely on incomplete or inaccurate approaches such as black box and white box testing, which fail to identify all vulnerabilities and can produce false positives or negatives, and lack comprehensive coverage of complex modern applications.

Innovation Solution

An advanced fusion analyzer system that uses multi-way coordination and orchestration across components to build and refine a detailed model of application behavior, combining reasoning and learning logic with information from components to drive analysis and improve accuracy.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If black box or white box testing methods are used to analyze applications, then some security issues can be identified, but the analysis is incomplete and produces false positives or negatives

Engineering Contradiction:
Improveaccuracy of vulnerability identificationVSAvoidcompleteness of vulnerability detection
Core Design Contradiction:
Measurement precisionVSReliability

Solution Approach 1:

The patent combines multiple analysis approaches (static analysis, dynamic analysis, machine learning) into a unified system that cross-validates findings. The fusion analyzer integrates results from different components to reduce false positives and negatives while improving both accuracy and completeness of vulnerability detection.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system implements feedback loops where analysis results are continuously refined. The machine learning component learns from identified vulnerabilities and false positives/negatives, adjusting its detection algorithms to improve precision and reliability over time. The system uses feedback to iteratively enhance its analysis capabilities.

Inventive Principle:
Principle #23Feedback

2Device complexity

If traditional analysis methods are used, then the system is simpler to implement, but they fail to provide comprehensive coverage of complex modern applications

Engineering Contradiction:
Improvesimplicity of analysis systemVSAvoidcoverage of complex applications
Core Design Contradiction:
Device complexityVSAdaptability or versatility

Solution Approach 1:

The patent divides the analysis system into distinct modular components: static analysis component, dynamic analysis component, machine learning component, and fusion analyzer. Each component handles specific aspects of analysis, making the complex system manageable while providing comprehensive coverage of modern applications through coordinated operation of these segments.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The analysis system is designed to be universally applicable across different types of applications and vulnerabilities. The fusion analyzer coordinates multiple analysis approaches that can adapt to various application complexities, providing versatile coverage while maintaining a unified system architecture that avoids excessive complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of operation

If penetration testers and black box scanners are used, then external vulnerabilities can be found, but they cannot identify all vulnerabilities including those requiring internal knowledge

Engineering Contradiction:
Improveexternal accessibility of analysisVSAvoidcompleteness of vulnerability identification
Core Design Contradiction:
Ease of operationVSMeasurement precision

Solution Approach 1:

The patent introduces a fusion analyzer as an intermediary that bridges external scanning and internal analysis. It coordinates findings from external black-box scanning with internal static and dynamic analysis, combining perspectives to achieve complete vulnerability identification while maintaining ease of operation through automated integration of multiple analysis types.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentEP2891101B1A system for analyzing applications in order to find security and quality issues
Publication Date: 2016.11.09 IAPPSECURE SOLUTIONS PVT
  • EP2891101B1 patent drawingFigure 1
  • EP2891101B1 patent drawingFigure 2a
  • EP2891101B1 patent drawingFigure 2b

AI summary

The present invention relates to field of application analysis and more specifically to analysis of applications for determining security and quality issues.The present invention describes a novel application analysis system providing a platform for accurately analyzing applications which is useful in finding security and quality issues in an application. In particular, the present invention is composed of an advanced fusion analyzer which gains a detailed understanding of the application behavior by using a novel multi-way coordination and orchestration across components used in the present invention to build and continuously refine a model representing knowledge and behavior of the application as a large network of objects across different dimensions and using reasoning and learning logic on this model along with information and events received from the components to both refine the model further as well as drive the components further by sending information and events to them and again using the information and events received as a result to further trigger the entire process until the system stabilizes.The present invention is useful in analysis of internet/intranet based web applications, desktop applications, mobile applications and also embedded systems as well as for hardware, equipment and machines controlled by software.