Automated Vulnerability Data Integration for Black-Box Testing
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional black-box security testing systems require manual and time-consuming updates, and there is no guarantee that end users will keep the testing systems up to date, leading to inefficiencies in maintaining and exercising diligence in obtaining and installing updates.
Innovation Solution
A method and system that utilize external data sources to obtain vulnerability data for Web applications, derive test payloads, and determine the type of vulnerability exploited, allowing for automatic incorporation of recently discovered attacks into the testing process without manual intervention, using a processor to select existing validation operations for validating responses from the Web application.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Extent of automation
If conventional hardcoded testing systems are used, then the testing system has a fixed and manageable structure, but the system requires manual updates and user diligence to maintain current vulnerability data
Solution Approach 1:
The patent introduces an intermediary component that acts as a bridge between external vulnerability data sources and the internal testing system. This intermediary automatically retrieves, parses, and integrates vulnerability data from external sources without requiring manual user intervention, thus automating the update process while managing complexity through a dedicated intermediary layer
Solution Approach 2:
The testing system is designed to self-update by automatically obtaining vulnerability data from external sources. The system performs self-service operations including automatic data retrieval, parsing, and integration, eliminating the need for manual updates and user diligence while maintaining current vulnerability information
2Productivity
If manual updates are required, then the system structure remains simple and manageable, but time and effort are consumed by developers for maintaining and updating tests
Solution Approach 1:
The system automatically retrieves and integrates vulnerability data from external sources without requiring manual developer intervention. This self-service capability eliminates the time developers would spend on manual updates while maintaining current and relevant vulnerability testing data, thus improving productivity without time loss
Solution Approach 2:
The system performs preliminary actions by automatically obtaining and preparing vulnerability data before it is needed for testing. This proactive approach ensures that vulnerability data is current and ready for use, eliminating the need for reactive manual updates and improving overall testing efficiency
3Reliability
If external data sources are used to automatically obtain vulnerability data, then the system stays current with recent attacks without manual intervention, but the system complexity increases
Solution Approach 1:
An intermediary component is introduced to manage the integration between external data sources and the internal testing system. This intermediary handles data retrieval, parsing, and validation, ensuring reliable and accurate vulnerability data while containing the complexity within a dedicated layer that can be independently managed and maintained
Data Source
AI summary
Black-box security testing for a Web application includes identifying infrastructure supporting the Web application, obtaining vulnerability data for the Web application from an external data source according to the infrastructure, deriving a test payload from the vulnerability data using a processor, and determining a type of vulnerability exploited by the test payload. An existing validation operation of a testing system is selected for validating a response from the Web application to the test payload according to the type of vulnerability.

