Generative AI Security Inspection for Missing Web Parameters

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing security inspection methods struggle with missing web pages and parameters during searches, limited vulnerability detection, and inability to adapt to the latest threats, leading to incomplete and outdated inspections.

Innovation Solution

Utilizing generative artificial intelligence to interactively add missing web pages and parameters, update inspection policies, and perform simulated hacking to enhance security inspections, thereby improving search performance and adapting to the latest threats.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional security inspection methods are used, then the inspection process is simple and fast, but the detection capability is limited and cannot identify missing web pages and parameters

Engineering Contradiction:
Improvevulnerability detection capabilityVSAvoidinspection system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent introduces Generative AI as an intermediary component between the inspection system and the target server. This AI intermediary autonomously explores the target server, discovers missing web pages and parameters, and generates inspection policies, thereby enhancing detection capability without requiring direct complex configuration in the main inspection system.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The Generative AI performs self-service by autonomously conducting reconnaissance on the target server, automatically identifying web pages, extracting parameters, and generating inspection policies without human intervention. This self-service capability resolves the contradiction by automating the complex tasks that would otherwise require sophisticated manual configuration.

Inventive Principle:
Principle #25Self-service

2Measurement precision

If comprehensive security inspection is performed to detect all vulnerabilities, then the detection capability is high, but the inspection time and resources increase significantly

Engineering Contradiction:
Improvevulnerability detection coverageVSAvoidinspection time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies preliminary action by having the Generative AI perform reconnaissance and policy generation before the actual security inspection. The AI pre-identifies web pages, extracts parameters, and creates tailored inspection policies, which significantly reduces the time required during the actual inspection phase while maintaining comprehensive detection coverage.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The inspection system dynamically adapts to each target server by having the Generative AI generate customized inspection policies based on the specific structure and characteristics of the target. This dynamic approach ensures comprehensive vulnerability detection coverage while optimizing inspection time by avoiding unnecessary checks on servers with different configurations.

Inventive Principle:
Principle #15Dynamics

3Adaptability or versatility

If fixed inspection policies are used, then the inspection process is stable and predictable, but the system cannot adapt to the latest threats and attack patterns

Engineering Contradiction:
Improveadaptability to latest threatsVSAvoidpolicy management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent utilizes parameter changes by having the Generative AI dynamically adjust inspection policy parameters based on the target server's characteristics and the latest threat intelligence. The AI modifies inspection depth, parameter types, and attack vectors according to the specific context, enabling adaptability to emerging threats without requiring manual policy updates.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system implements feedback mechanisms where the Generative AI continuously learns from inspection results and threat intelligence, automatically refining and updating inspection policies. This feedback loop enables the system to adapt to the latest threats while the AI autonomously manages the complexity of policy adjustments, reducing the burden on operators.

Inventive Principle:
Principle #23Feedback

4Productivity

If manual configuration of inspection parameters is performed, then the inspection is precise, but the productivity is low and costs are high

Engineering Contradiction:
Improveinspection efficiencyVSAvoidinspection accuracy
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The Generative AI performs self-service by automatically conducting reconnaissance, identifying web pages, extracting parameters, and generating inspection policies without human intervention. This automation maintains high inspection accuracy through intelligent analysis while dramatically improving productivity by eliminating manual configuration tasks.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the mechanical process of manual parameter configuration with an intelligent AI-based system. The Generative AI uses advanced algorithms to automatically discover and configure inspection parameters, substituting human manual work with automated intelligent processes that maintain or improve accuracy while significantly boosting productivity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS20250280029A1Method for security inspection based on generative artificial intelligence and diagnostic device using same
Publication Date: 2025.09.04 SAMSUNG SDS CO LTD
  • US20250280029A1 patent drawing
  • US20250280029A1 patent drawing
  • US20250280029A1 patent drawing

AI summary

A processor-implemented method including collecting diagnostic target data by searching for a target server according to a configuration pattern, receiving, from a generative artificial intelligence server, additional diagnostic target data, the generative artificial intelligence server being configured to search the target server for the additional diagnostic target data to merge the additional diagnostic target data with the diagnostic target data, generating a diagnostic script from the diagnostic target data according to an inspection policy, performing an inspection on the target server with the diagnostic script to collect inspection data, and generating a vulnerability analysis result for the target server by using the inspection data.