Automated Software Vulnerability Triage via ML Vector Classification
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current methods for scanning and remedying security vulnerabilities in software applications during development are slow and manual, requiring expert interpretation and are hindered by a shortage of cybersecurity experts, necessitating a faster and more efficient process.
Innovation Solution
A system comprising a scan engine, vulnerability report engine, extraction engine, format engine, classification engine, and output engine, utilizing machine learning for automated triage and remediation, reduces false positives and duplicates, and provides actionable recommendations to developers through a user interface.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If manual scanning and analysis methods are used, then expert interpretation quality is maintained, but the process speed and scalability deteriorate
Solution Approach 1:
The patent introduces an intermediary system comprising multiple engines (scan engine, vulnerability report engine, extraction engine, format engine, vector engine, classification engine, output engine) that acts as a mediator between the scanning process and expert analysis. This intermediary automatically processes scan results, extracts features, creates vectors, and classifies vulnerabilities, thereby maintaining analysis quality while significantly improving processing speed and scalability.
Solution Approach 2:
The patent replaces the mechanical manual process of expert interpretation with an automated computational system. The classification engine uses machine learning models to automatically classify vulnerabilities and prioritize them, substituting the manual mechanical process of expert review with an automated electronic system that maintains or improves analysis quality while dramatically increasing productivity.
2Measurement precision
If expert interpretation is used for each vulnerability, then analysis accuracy is improved, but the time consumption and resource requirements increase
Solution Approach 1:
The patent segments the vulnerability analysis process into distinct functional components handled by different engines. The extraction engine segments vulnerability features, the vector engine segments data into vectors, and the classification engine segments vulnerabilities into categories. This segmentation allows parallel processing and automated classification, reducing the time each vulnerability requires while maintaining accurate identification through specialized processing for each segment.
Solution Approach 2:
The patent transforms vulnerability data through parameter changes at each processing stage. The extraction engine extracts specific features as parameters, the vector engine converts features into vector parameters, and the classification engine uses these parameters to automatically classify vulnerabilities. These parameter transformations enable automated processing that reduces assessment time while maintaining or improving identification accuracy through systematic parameter analysis.
3Reliability
If comprehensive vulnerability scanning is performed, then security coverage is improved, but false positives and duplicates increase
Solution Approach 1:
The patent implements feedback mechanisms where the classification engine receives input from the vector engine, which receives input from the extraction engine, which receives input from the vulnerability report engine. This feedback loop allows the system to learn from processed vulnerabilities, refine classifications, and reduce false positives and duplicates while maintaining comprehensive security coverage through iterative improvement.
Data Source
AI summary
Systems and methods are provided for the classification of identified security vulnerabilities in software applications, and their automated triage based on machine learning. The disclosed system may generate a report listing detected potential vulnerability issues, and extract features from the report for each potential vulnerability issue. The system may receive policy data and business rules, and compare the extracted features relative to such data and rules. The system may determine a token based on the source code of a potential vulnerability issue, and a vector based on the extracted features of a potential vulnerability issue and based on the token. The system may select a machine learning modelling method and/or an automated triaging method based on the vector, and determine a vulnerability accuracy score based on the vector using the selected method.


