Automated Software Vulnerability Triage via ML Vector Classification

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current methods for scanning and remedying security vulnerabilities in software applications during development are slow and manual, requiring expert interpretation and are hindered by a shortage of cybersecurity experts, necessitating a faster and more efficient process.

Innovation Solution

A system comprising a scan engine, vulnerability report engine, extraction engine, format engine, classification engine, and output engine, utilizing machine learning for automated triage and remediation, reduces false positives and duplicates, and provides actionable recommendations to developers through a user interface.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual scanning and analysis methods are used, then expert interpretation quality is maintained, but the process speed and scalability deteriorate

Engineering Contradiction:
Improvevulnerability analysis qualityVSAvoidscan and remediation speed
Core Design Contradiction:
Measurement precisionVSProductivity

Solution Approach 1:

The patent introduces an intermediary system comprising multiple engines (scan engine, vulnerability report engine, extraction engine, format engine, vector engine, classification engine, output engine) that acts as a mediator between the scanning process and expert analysis. This intermediary automatically processes scan results, extracts features, creates vectors, and classifies vulnerabilities, thereby maintaining analysis quality while significantly improving processing speed and scalability.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent replaces the mechanical manual process of expert interpretation with an automated computational system. The classification engine uses machine learning models to automatically classify vulnerabilities and prioritize them, substituting the manual mechanical process of expert review with an automated electronic system that maintains or improves analysis quality while dramatically increasing productivity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If expert interpretation is used for each vulnerability, then analysis accuracy is improved, but the time consumption and resource requirements increase

Engineering Contradiction:
Improvevulnerability identification accuracyVSAvoidtime for vulnerability assessment
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent segments the vulnerability analysis process into distinct functional components handled by different engines. The extraction engine segments vulnerability features, the vector engine segments data into vectors, and the classification engine segments vulnerabilities into categories. This segmentation allows parallel processing and automated classification, reducing the time each vulnerability requires while maintaining accurate identification through specialized processing for each segment.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent transforms vulnerability data through parameter changes at each processing stage. The extraction engine extracts specific features as parameters, the vector engine converts features into vector parameters, and the classification engine uses these parameters to automatically classify vulnerabilities. These parameter transformations enable automated processing that reduces assessment time while maintaining or improving identification accuracy through systematic parameter analysis.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If comprehensive vulnerability scanning is performed, then security coverage is improved, but false positives and duplicates increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidfalse positives and duplicates
Core Design Contradiction:
ReliabilityVSLoss of information

Solution Approach 1:

The patent implements feedback mechanisms where the classification engine receives input from the vector engine, which receives input from the extraction engine, which receives input from the vulnerability report engine. This feedback loop allows the system to learn from processed vulnerabilities, refine classifications, and reduce false positives and duplicates while maintaining comprehensive security coverage through iterative improvement.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11568057B2Systems and methods for triaging software vulnerabilities
Publication Date: 2023.01.31 ACCENTURE GLOBAL SOLUTIONS LTD
  • US11568057B2 patent drawing
  • US11568057B2 patent drawing
  • US11568057B2 patent drawing

AI summary

Systems and methods are provided for the classification of identified security vulnerabilities in software applications, and their automated triage based on machine learning. The disclosed system may generate a report listing detected potential vulnerability issues, and extract features from the report for each potential vulnerability issue. The system may receive policy data and business rules, and compare the extracted features relative to such data and rules. The system may determine a token based on the source code of a potential vulnerability issue, and a vector based on the extracted features of a potential vulnerability issue and based on the token. The system may select a machine learning modelling method and/or an automated triaging method based on the vector, and determine a vulnerability accuracy score based on the vector using the selected method.