Vulnerability Identification Engine for Application Security

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large entities face challenges in monitoring and managing security vulnerabilities across complex information technology infrastructures, particularly in mainframe environments with multiple logical partitions and diverse user requirements, leading to difficulties in identifying and prioritizing security issues before they become critical.

Innovation Solution

A centralized privacy evaluation engine that compiles applications into a database, generates a weighted asset security value based on information security and business criteria, and provides an interactive graphical interface for users to filter and visualize vulnerabilities, allowing for prioritization and detailed analysis of application characteristics.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If a centralized database compiling all applications across the entity is created, then the ability to identify and track vulnerabilities improves, but the complexity of managing and processing the large volume of application data worsens

Engineering Contradiction:
Improvevulnerability identification accuracyVSAvoiddata management complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent segments the large-scale vulnerability management system into modular components: a centralized database for data storage, a processing engine for analyzing application characteristics, and an interactive interface for user interaction. This segmentation allows the system to handle large volumes of application data without overwhelming complexity by dividing the management task into manageable modules that can operate independently yet coordinated.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an interactive graphical interface as an intermediary between the centralized database and users. This intermediary layer processes and presents vulnerability information in a comprehensible format, filtering and organizing the complex data from the database before presentation. The interface acts as a mediator that simplifies the interaction between users and the complex underlying data structure.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If detailed information about all application characteristics is collected and analyzed, then the prioritization of security vulnerabilities improves, but the time and computational resources required worsens

Engineering Contradiction:
Improvesecurity assessment reliabilityVSAvoidanalysis time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements preliminary action by pre-calculating and storing application characteristic data in the centralized database before security assessments are needed. Application information, including vulnerability data and business criteria, is compiled and organized in advance, allowing the system to quickly retrieve and analyze relevant information when security assessments are required, rather than processing all data from scratch each time.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent applies partial action by focusing analysis on specific application characteristics and vulnerability types that are most relevant to security prioritization. Rather than analyzing every possible attribute of each application equally, the system identifies and concentrates computational resources on the most critical security-related characteristics, achieving reliable security assessment with reduced computational overhead.

Inventive Principle:
Principle #16Partial or excessive action

3Adaptability or versatility

If the system provides comprehensive filtering and visualization capabilities for all application characteristics, then user control and prioritization ability improve, but the interface complexity and difficulty of operation worsens

Engineering Contradiction:
Improvefiltering capabilityVSAvoidinterface usability
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The patent implements dynamics by creating an adaptive interface that adjusts its complexity based on user needs and preferences. The interactive graphical interface allows users to dynamically select which application characteristics to filter and visualize, enabling the system to simplify or expand its functionality according to the specific assessment requirements. This dynamic adaptability maintains ease of operation while providing comprehensive filtering capabilities when needed.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The patent applies local quality by allowing users to customize the interface to highlight specific vulnerability types, application characteristics, or business criteria relevant to their particular needs. Rather than presenting all possible filtering options simultaneously, the interface enables users to focus on local areas of interest, displaying detailed information about selected characteristics while keeping the overall interface clean and manageable.

Inventive Principle:
Principle #3Local quality

4Reliability

If the system tracks and monitors security vulnerabilities across the entire entity infrastructure, then security coverage and protection capability improve, but the computational resources and processing power required worsens

Engineering Contradiction:
Improvesecurity coverageVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The patent extracts and isolates only the critical security-related data and characteristics from the entire application portfolio for detailed analysis. Rather than processing all application data uniformly, the system identifies and extracts vulnerability information, security criteria, and relevant business criteria, separating these from other application attributes. This extraction approach enables comprehensive security coverage while reducing computational resource consumption by focusing processing power on essential security data.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS10264008B2Vulnerability exposing application characteristic variation identification engine
Publication Date: 2019.04.16 BANK OF AMERICA CORP
  • US10264008B2 patent drawing
  • US10264008B2 patent drawing
  • US10264008B2 patent drawing

AI summary

Embodiments of the invention are directed to a system, method, or computer program product for an engine for exposing vulnerability within applications based on application characteristic identification. In this way, the engine identifies existing data sets that aid in understanding the possible privacy vulnerabilities associated with technologies such as applications, operated by an entity. The engine comprises dials and levers that allow for prioritization visualization of vulnerabilities critical to a particular portion of the entity. In this way, a user can drive the application engine allowing them to narrow the focus on any number of variations of application characteristics including, but not limited to types of vulnerabilities, status of the vulnerabilities, critical applications, regulated applications, vulnerabilities, business continuity and/or accessibility to the applications.