Platform-Specific Security Vulnerability Assessment via GUI

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems fail to accurately determine platform-specific end-to-end security vulnerabilities for software applications, leading to potential data breaches due to generic security information and the complexity of cybersecurity threats, which are not specific to the platform or software application, and lack real-time assessment capabilities.

Innovation Solution

A system that uses a machine learning model and graphical user interface to identify computing aspects impacted by security vulnerabilities, providing a visual indication of impact levels, enabling users to determine the safety of software applications by mapping platform identifiers to computing aspects and determining threat values based on platform-specific policies.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If generic publicly available security information is used, then information availability is improved, but measurement precision of platform-specific vulnerabilities deteriorates

Engineering Contradiction:
Improvesecurity information availabilityVSAvoidvulnerability assessment accuracy
Core Design Contradiction:
Quantity of substanceVSMeasurement precision

Solution Approach 1:

The system segments security vulnerability information into multiple levels: generic security information from public sources, platform-specific information from identified computing platforms, and application-specific information from software component analysis. This segmentation allows the system to use broad public information while adding layered specificity to achieve both availability and precision.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system applies local quality by tailoring security assessment to specific platforms and applications. Instead of uniform generic assessment, the system identifies specific computing platforms associated with software applications and retrieves platform-specific security information, making the assessment locally adapted to each context for higher precision.

Inventive Principle:
Principle #3Local quality

2Device complexity

If manual security vulnerability determination techniques are used, then device complexity is reduced, but productivity and reliability deteriorate

Engineering Contradiction:
Improvesystem simplicityVSAvoidvulnerability assessment efficiency
Core Design Contradiction:
Device complexityVSProductivity

Solution Approach 1:

The system enables self-service automation where software components automatically identify their associated computing platforms, automatically retrieve relevant security information, and automatically generate vulnerability assessments. This eliminates manual intervention while maintaining system simplicity through automated workflows.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements feedback loops where security vulnerability information is continuously updated and propagated back to software applications and users. This automated feedback mechanism ensures real-time updates without manual intervention, improving productivity while maintaining reliability through systematic information flow.

Inventive Principle:
Principle #23Feedback

3Loss of information

If complex cybersecurity jargon and detailed vulnerability descriptions are provided, then information completeness is improved, but ease of operation for end-users deteriorates

Engineering Contradiction:
Improvesecurity information completenessVSAvoiduser understanding capability
Core Design Contradiction:
Loss of informationVSEase of operation

Solution Approach 1:

The system introduces an intermediary layer that translates complex cybersecurity information into user-friendly presentations. Security vulnerability data with complete technical details is processed through this intermediary that generates simplified visual indicators and explanations, preserving information completeness while improving ease of operation for end-users.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system adds a new dimension of information presentation by providing both detailed technical vulnerability information and simplified user-friendly indicators simultaneously. This multi-dimensional approach allows complete information to be available for experts while providing accessible summaries for general users without compromising either group's needs.

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

4Reliability

If real-time security vulnerability assessment is implemented, then reliability is improved, but use of energy and processing resources increases

Engineering Contradiction:
Improvesecurity assessment accuracyVSAvoidprocessing resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system performs preliminary actions by pre-identifying computing platforms associated with software applications and pre-retrieving relevant security information before actual vulnerability assessment is needed. This advance preparation enables real-time assessment with reduced processing requirements during critical evaluation moments.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements multi-functionality by creating a universal platform identification and information retrieval mechanism that serves multiple software applications and platforms. This universal approach amortizes processing costs across multiple uses, reducing per-assessment resource consumption while maintaining real-time capability and reliability.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11868484B1Determining platform-specific end-to-end security vulnerabilities for a software application via a graphical user interface (GUI) systems and methods
Publication Date: 2024.01.09 CITIBANK N A
  • US11868484B1 patent drawing
  • US11868484B1 patent drawing
  • US11868484B1 patent drawing

AI summary

Systems and methods for determining and displaying platform-specific end-to-end security vulnerabilities via a graphical user interface (GUI) are disclosed. To provide users with visual indications of vulnerable computing aspects associated with a computing platform, the system identifies computing aspects associated with a platform. The system then obtains from a security entity, security-vulnerability descriptions that are associated with the platform. Using the security-vulnerability descriptions, the system then determines threat levels for each security-vulnerability description and then, using the determined threat levels, determines a computing aspect impact level for each computing aspect associated with the platform. The system then generates for display on a GUI, a graphical layout comprising each computing aspect impact level for each computing aspect associated with the platform.