Vulnerability Detection Qualification Using Configuration Context

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Commercial vulnerability scanners are over-inclusive and under-inclusive, leading to false positives and undetected security vulnerabilities due to their inability to apply additional context, such as authentication mechanisms at the file system level, when identifying vulnerabilities like anonymous FTP.

Innovation Solution

A computer-implemented method that qualifies vulnerability detections by applying additional context based on the target system's configuration, using a qualification server to process data from vulnerability scanners and determine if detected vulnerabilities require remediation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Quantity of substance

If vulnerability scanners perform comprehensive detection tests to surface all security vulnerabilities, then the quantity of detected vulnerabilities increases, but the precision of detection decreases due to false positives

Engineering Contradiction:
Improvequantity of detected vulnerabilitiesVSAvoidprecision of vulnerability detection
Core Design Contradiction:
Quantity of substanceVSMeasurement precision

Solution Approach 1:

The patent introduces an intermediary system (vulnerability verification system) that acts as a mediator between the vulnerability scanner and the remediation process. This intermediary performs additional verification steps using multiple detection methods and context analysis to confirm whether detected vulnerabilities are genuine, thereby reducing false positives while maintaining comprehensive detection coverage

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent applies preliminary action by performing additional verification and context analysis before finalizing vulnerability detections. The system conducts preliminary checks including authentication mechanism verification, configuration context analysis, and multiple detection method cross-validation before confirming a vulnerability, ensuring high precision while maintaining comprehensive detection

Inventive Principle:
Principle #10Preliminary action

2Ease of operation

If vulnerability scanners use simplified detection tests to improve ease of operation, then the ease of operation increases, but the reliability of detection decreases due to false positives

Engineering Contradiction:
Improveease of vulnerability scanningVSAvoidreliability of vulnerability detection
Core Design Contradiction:
Ease of operationVSReliability

Solution Approach 1:

The patent segments the vulnerability detection process into distinct phases: initial scanning (maintaining ease of operation), verification phase (enhancing reliability), and remediation phase. The verification phase is automatically triggered for detections requiring additional context, separating the simple scanning operation from the complex verification process

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The vulnerability verification system performs self-service by automatically conducting additional verification steps, context analysis, and false positive filtering without requiring manual intervention. The system autonomously evaluates authentication mechanisms, analyzes configuration contexts, and cross-validates detections, maintaining ease of operation while enhancing reliability

Inventive Principle:
Principle #25Self-service

3Device complexity

If vulnerability scanners lack additional system context to qualify detections, then the device complexity decreases, but the measurement precision of vulnerability detection worsens

Engineering Contradiction:
Improvecomplexity of vulnerability scanning systemVSAvoidprecision of vulnerability qualification
Core Design Contradiction:
Device complexityVSMeasurement precision

Solution Approach 1:

The patent adds another dimension to the vulnerability detection process by incorporating configuration context and authentication mechanism analysis. The verification system operates in an additional dimensional space that considers not just the presence of vulnerabilities but also the system context, authentication requirements, and configuration details, thereby enhancing precision without significantly increasing apparent complexity

Inventive Principle:
Principle #17Another dimension (Dimensionality change)

Data Source

PatentUS20250225251A1Vulnerability and remediation validation automation
Publication Date: 2025.07.10 DISNEY ENTERPRISES INC
  • US20250225251A1 patent drawing
  • US20250225251A1 patent drawing
  • US20250225251A1 patent drawing

AI summary

A method of qualifying a vulnerability detection for remediation comprising: obtaining a vulnerability detection from a vulnerability scanner for a target system; determining qualification data qualifying the vulnerability detection, wherein the qualification data is based on a configuration of the target system excluded in the vulnerability detection from the vulnerability scanner; and associating the qualification data with the vulnerability detection.