Interactive Web Application Vulnerability Scanning and Remediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current web application scanning methods provide a high-level view of vulnerabilities, making it difficult for users to locate and understand the specific issues within their applications, leading to inefficient remediation processes.

Innovation Solution

A method that facilitates interactive remediation by receiving information from remote vulnerability scans, allowing users to navigate directly to and highlight vulnerabilities within their web pages, providing inline feedback on severity, solution, and plugin output.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If web application scanning provides a high-level view of vulnerabilities, then the scanning process is simple and fast, but users cannot locate and understand specific issues within their applications

Engineering Contradiction:
Improvescanning efficiencyVSAvoidvulnerability location information
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent segments vulnerability information into two levels: a high-level summary view for quick overview and detailed page-level views for specific vulnerability locations. The scanner divides the web application into individual pages and identifies vulnerabilities at the page level, allowing users to navigate to specific affected pages while maintaining the efficiency of automated scanning.

Inventive Principle:
Principle #1Segmentation

2Loss of information

If web application scanning provides detailed vulnerability information, then users can locate specific issues, but the scanning process becomes more complex and time-consuming

Engineering Contradiction:
Improvevulnerability detail informationVSAvoidscanning system complexity
Core Design Contradiction:
Loss of informationVSDevice complexity

Solution Approach 1:

The patent adds a spatial dimension to vulnerability reporting by mapping vulnerabilities to specific web pages and locations within the application. Instead of merely listing vulnerabilities, the system provides navigational information that guides users to the exact page and element affected, transforming abstract vulnerability data into location-specific actionable information.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

3Measurement precision

If manual vulnerability assessment is performed, then threat ranking is accurate, but the process is manual and subjective

Engineering Contradiction:
Improvethreat assessment accuracyVSAvoidassessment process ease
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The patent implements automated feedback mechanisms where the scanning system not only identifies vulnerabilities but also provides immediate guidance on remediation. The system delivers structured information including vulnerability descriptions, affected pages, and remediation recommendations, creating a closed-loop feedback system that guides users from detection to resolution without manual intervention.

Inventive Principle:
Principle #23Feedback

4Productivity

If automated exploit prediction algorithms are used, then resource allocation is improved, but the algorithms rely on vulnerability prevalence rather than specific location

Engineering Contradiction:
Improveresource allocation efficiencyVSAvoidspecific vulnerability location
Core Design Contradiction:
ProductivityVSLoss of information

Solution Approach 1:

The patent merges automated scanning capabilities with location-specific identification. The system combines the efficiency of automated vulnerability detection with precise page-level and element-level location information, creating a unified approach that maintains both automation benefits and detailed location awareness for effective remediation.

Inventive Principle:
Principle #5Merging (Combining)

Data Source

PatentUS12088620B2Interactive web application scanning
Publication Date: 2024.09.10 TENABLE INC
  • US12088620B2 patent drawing
  • US12088620B2 patent drawing
  • US12088620B2 patent drawing

AI summary

Techniques, methods and/or apparatuses are disclosed that enable facilitation of remediation of one or more vulnerabilities detected in a web application. Through the disclosed techniques, methods and/or apparatuses, users will be able to navigate to respective web pages of the detected vulnerabilities and snap directly to the vulnerabilities within the webpages. This allows the users to immediately know the location of the vulnerability, and inline feedback can be provided on the issue, including description, severity, solution and plugin outputs.