Vulnerability Detection Qualification Using Configuration Context
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Commercial vulnerability scanners are over-inclusive and under-inclusive, leading to false positives and undetected security vulnerabilities due to their inability to apply additional context, such as authentication mechanisms at the file system level, when identifying vulnerabilities like anonymous FTP.
Innovation Solution
A computer-implemented method that qualifies vulnerability detections by applying additional context based on the target system's configuration, using a qualification server to process data from vulnerability scanners and determine if detected vulnerabilities require remediation.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Quantity of substance
If vulnerability scanners perform comprehensive detection tests to surface all security vulnerabilities, then the quantity of detected vulnerabilities increases, but the precision of detection decreases due to false positives
Solution Approach 1:
The patent introduces an intermediary system (vulnerability verification system) that acts as a mediator between the vulnerability scanner and the remediation process. This intermediary performs additional verification steps using multiple detection methods and context analysis to confirm whether detected vulnerabilities are genuine, thereby reducing false positives while maintaining comprehensive detection coverage
Solution Approach 2:
The patent applies preliminary action by performing additional verification and context analysis before finalizing vulnerability detections. The system conducts preliminary checks including authentication mechanism verification, configuration context analysis, and multiple detection method cross-validation before confirming a vulnerability, ensuring high precision while maintaining comprehensive detection
2Ease of operation
If vulnerability scanners use simplified detection tests to improve ease of operation, then the ease of operation increases, but the reliability of detection decreases due to false positives
Solution Approach 1:
The patent segments the vulnerability detection process into distinct phases: initial scanning (maintaining ease of operation), verification phase (enhancing reliability), and remediation phase. The verification phase is automatically triggered for detections requiring additional context, separating the simple scanning operation from the complex verification process
Solution Approach 2:
The vulnerability verification system performs self-service by automatically conducting additional verification steps, context analysis, and false positive filtering without requiring manual intervention. The system autonomously evaluates authentication mechanisms, analyzes configuration contexts, and cross-validates detections, maintaining ease of operation while enhancing reliability
3Device complexity
If vulnerability scanners lack additional system context to qualify detections, then the device complexity decreases, but the measurement precision of vulnerability detection worsens
Solution Approach 1:
The patent adds another dimension to the vulnerability detection process by incorporating configuration context and authentication mechanism analysis. The verification system operates in an additional dimensional space that considers not just the presence of vulnerabilities but also the system context, authentication requirements, and configuration details, thereby enhancing precision without significantly increasing apparent complexity
Data Source
AI summary
A method of qualifying a vulnerability detection for remediation comprising: obtaining a vulnerability detection from a vulnerability scanner for a target system; determining qualification data qualifying the vulnerability detection, wherein the qualification data is based on a configuration of the target system excluded in the vulnerability detection from the vulnerability scanner; and associating the qualification data with the vulnerability detection.


