Automated Vulnerability Data Integration for Black-Box Testing

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional black-box security testing systems require manual and time-consuming updates, and there is no guarantee that end users will keep the testing systems up to date, leading to inefficiencies in maintaining and exercising diligence in obtaining and installing updates.

Innovation Solution

A method and system that utilize external data sources to obtain vulnerability data for Web applications, derive test payloads, and determine the type of vulnerability exploited, allowing for automatic incorporation of recently discovered attacks into the testing process without manual intervention, using a processor to select existing validation operations for validating responses from the Web application.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Extent of automation

If conventional hardcoded testing systems are used, then the testing system has a fixed and manageable structure, but the system requires manual updates and user diligence to maintain current vulnerability data

Engineering Contradiction:
Improveautomatic update of vulnerability dataVSAvoidsystem architecture complexity
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary component that acts as a bridge between external vulnerability data sources and the internal testing system. This intermediary automatically retrieves, parses, and integrates vulnerability data from external sources without requiring manual user intervention, thus automating the update process while managing complexity through a dedicated intermediary layer

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The testing system is designed to self-update by automatically obtaining vulnerability data from external sources. The system performs self-service operations including automatic data retrieval, parsing, and integration, eliminating the need for manual updates and user diligence while maintaining current vulnerability information

Inventive Principle:
Principle #25Self-service

2Productivity

If manual updates are required, then the system structure remains simple and manageable, but time and effort are consumed by developers for maintaining and updating tests

Engineering Contradiction:
Improvetesting efficiencyVSAvoidtime for manual updates
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The system automatically retrieves and integrates vulnerability data from external sources without requiring manual developer intervention. This self-service capability eliminates the time developers would spend on manual updates while maintaining current and relevant vulnerability testing data, thus improving productivity without time loss

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system performs preliminary actions by automatically obtaining and preparing vulnerability data before it is needed for testing. This proactive approach ensures that vulnerability data is current and ready for use, eliminating the need for reactive manual updates and improving overall testing efficiency

Inventive Principle:
Principle #10Preliminary action

3Reliability

If external data sources are used to automatically obtain vulnerability data, then the system stays current with recent attacks without manual intervention, but the system complexity increases

Engineering Contradiction:
Improveaccuracy of vulnerability dataVSAvoiddata integration architecture
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

An intermediary component is introduced to manage the integration between external data sources and the internal testing system. This intermediary handles data retrieval, parsing, and validation, ensuring reliable and accurate vulnerability data while containing the complexity within a dedicated layer that can be independently managed and maintained

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS10841327B2Mining attack vectors for black-box security testing
Publication Date: 2020.11.17 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10841327B2 patent drawing
  • US10841327B2 patent drawing

AI summary

Black-box security testing for a Web application includes identifying infrastructure supporting the Web application, obtaining vulnerability data for the Web application from an external data source according to the infrastructure, deriving a test payload from the vulnerability data using a processor, and determining a type of vulnerability exploited by the test payload. An existing validation operation of a testing system is selected for validating a response from the Web application to the test payload according to the type of vulnerability.