Vulnerability Analytics Engine for Automated Code Remediation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Large, complex code bases face challenges in efficiently managing security vulnerabilities due to the distributed ownership and the high frequency of vulnerability discoveries, leading to a backlog of unassigned vulnerabilities and security holes.
Innovation Solution
A computerized method for classifying vulnerability data by creating a finding object, populating it with property values, evaluating technical owner rules to assign responsible owners, and distributing the findings to a GRC module for remediation, with the use of machine learning for feedback-based rule adjustments.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If manual identification of responsible technical owners is used, then accuracy of assignment may be maintained, but the process becomes time-consuming and cannot keep up with vulnerability discovery rate
Solution Approach 1:
The patent replaces the manual mechanical process of identifying and assigning technical owners with an automated computerized system. The vulnerability management system automatically receives vulnerability data, identifies responsible technical owners using evaluation rules, and distributes vulnerabilities without human intervention in the assignment process, thereby dramatically increasing assignment rate while reducing time loss.
Solution Approach 2:
The system enables self-service automation where the vulnerability management system autonomously performs the entire assignment process. The system automatically evaluates vulnerability data against technical owner criteria, determines responsible owners, and distributes findings without requiring manual human effort, allowing the system to serve itself in managing the vulnerability workflow.
2Productivity
If automated assignment systems are implemented, then processing speed increases, but accuracy of identifying the correct technical owner may deteriorate
Solution Approach 1:
The patent incorporates feedback mechanisms where the vulnerability management system continuously evaluates assignment outcomes and refines its evaluation rules. By analyzing past assignment data and outcomes, the system learns and improves its accuracy in identifying correct technical owners over time, maintaining precision while operating at high automated speeds.
Solution Approach 2:
The system performs preliminary actions by pre-establishing comprehensive evaluation rules and criteria for technical owner identification before the actual assignment process. These pre-configured rules encompass various vulnerability types, code base structures, and organizational hierarchies, enabling the system to accurately and rapidly assign vulnerabilities without sacrificing precision for speed.
3Reliability
If comprehensive vulnerability analysis is performed, then security coverage is improved, but the complexity of managing and distributing vulnerabilities increases
Solution Approach 1:
The patent segments the complex vulnerability management process into distinct modular components: vulnerability data reception, property value extraction, technical owner evaluation, assignment determination, and distribution. Each module handles a specific aspect of the process independently, making the overall complex system manageable while maintaining comprehensive security coverage through thorough analysis at each segment.
4Reliability
If manual vulnerability distribution is used, then control over assignment quality is maintained, but the backlog of unassigned vulnerabilities grows
Solution Approach 1:
The patent introduces an intermediary automated vulnerability management system that acts as a mediator between vulnerability discovery and technical owner assignment. This intermediary system maintains quality control through structured evaluation rules and automated determination logic while dramatically increasing processing throughput, preventing backlog accumulation by handling assignments at scale without sacrificing quality.
Data Source
AI summary
Vulnerability data is classified as described herein. A finding object is created based on vulnerability data associated with a vulnerability finding and that finding object is populated with property values based on the vulnerability data. Technical owner rules associated with a plurality of technical owners are evaluated based on the property values of the finding object and a technical owner is assigned to the finding object based on the evaluated technical owner rules. Once a technical owner is assigned, the finding object is provided to a governance, risk, and compliance (GRC) module for distribution of the vulnerability finding to the assigned technical owner for remediation. Classification of vulnerability data using the described property values and technical owner rules provides an efficient, accurate, and automated way of distributing vulnerability findings of large, complex code bases to teams for remediation.


