Vulnerability Analytics Engine for Automated Code Remediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large, complex code bases face challenges in efficiently managing security vulnerabilities due to the distributed ownership and the high frequency of vulnerability discoveries, leading to a backlog of unassigned vulnerabilities and security holes.

Innovation Solution

A computerized method for classifying vulnerability data by creating a finding object, populating it with property values, evaluating technical owner rules to assign responsible owners, and distributing the findings to a GRC module for remediation, with the use of machine learning for feedback-based rule adjustments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If manual identification of responsible technical owners is used, then accuracy of assignment may be maintained, but the process becomes time-consuming and cannot keep up with vulnerability discovery rate

Engineering Contradiction:
Improvevulnerability assignment rateVSAvoidtime to assign vulnerabilities
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent replaces the manual mechanical process of identifying and assigning technical owners with an automated computerized system. The vulnerability management system automatically receives vulnerability data, identifies responsible technical owners using evaluation rules, and distributes vulnerabilities without human intervention in the assignment process, thereby dramatically increasing assignment rate while reducing time loss.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables self-service automation where the vulnerability management system autonomously performs the entire assignment process. The system automatically evaluates vulnerability data against technical owner criteria, determines responsible owners, and distributes findings without requiring manual human effort, allowing the system to serve itself in managing the vulnerability workflow.

Inventive Principle:
Principle #25Self-service

2Productivity

If automated assignment systems are implemented, then processing speed increases, but accuracy of identifying the correct technical owner may deteriorate

Engineering Contradiction:
Improvevulnerability assignment rateVSAvoidaccuracy of owner identification
Core Design Contradiction:
ProductivityVSMeasurement precision

Solution Approach 1:

The patent incorporates feedback mechanisms where the vulnerability management system continuously evaluates assignment outcomes and refines its evaluation rules. By analyzing past assignment data and outcomes, the system learns and improves its accuracy in identifying correct technical owners over time, maintaining precision while operating at high automated speeds.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary actions by pre-establishing comprehensive evaluation rules and criteria for technical owner identification before the actual assignment process. These pre-configured rules encompass various vulnerability types, code base structures, and organizational hierarchies, enabling the system to accurately and rapidly assign vulnerabilities without sacrificing precision for speed.

Inventive Principle:
Principle #10Preliminary action

3Reliability

If comprehensive vulnerability analysis is performed, then security coverage is improved, but the complexity of managing and distributing vulnerabilities increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the complex vulnerability management process into distinct modular components: vulnerability data reception, property value extraction, technical owner evaluation, assignment determination, and distribution. Each module handles a specific aspect of the process independently, making the overall complex system manageable while maintaining comprehensive security coverage through thorough analysis at each segment.

Inventive Principle:
Principle #1Segmentation

4Reliability

If manual vulnerability distribution is used, then control over assignment quality is maintained, but the backlog of unassigned vulnerabilities grows

Engineering Contradiction:
Improveassignment quality controlVSAvoidvulnerability processing throughput
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent introduces an intermediary automated vulnerability management system that acts as a mediator between vulnerability discovery and technical owner assignment. This intermediary system maintains quality control through structured evaluation rules and automated determination logic while dramatically increasing processing throughput, preventing backlog accumulation by handling assignments at scale without sacrificing quality.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10733302B2Security vulnerability analytics engine
Publication Date: 2020.08.04 MASTERCARD INT INC
  • US10733302B2 patent drawing
  • US10733302B2 patent drawing
  • US10733302B2 patent drawing

AI summary

Vulnerability data is classified as described herein. A finding object is created based on vulnerability data associated with a vulnerability finding and that finding object is populated with property values based on the vulnerability data. Technical owner rules associated with a plurality of technical owners are evaluated based on the property values of the finding object and a technical owner is assigned to the finding object based on the evaluated technical owner rules. Once a technical owner is assigned, the finding object is provided to a governance, risk, and compliance (GRC) module for distribution of the vulnerability finding to the assigned technical owner for remediation. Classification of vulnerability data using the described property values and technical owner rules provides an efficient, accurate, and automated way of distributing vulnerability findings of large, complex code bases to teams for remediation.