Graphical Visualization of Web Application Vulnerabilities
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing methods for web application security are cumbersome and inefficient, particularly in legacy systems, as they struggle to effectively visualize and manage vulnerabilities exposed through URLs and APIs, leading to tedious rule creation for Web Application Firewalls.
Innovation Solution
A system and method for graphical visualization of web application vulnerabilities, which extracts data from scanner logs to generate an application vulnerability graph, allowing for filtering, security protection enablement/disabling, and generation of WAF rules as regular expressions, enabling easier comprehension and management of vulnerabilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If vulnerability scanning tools are used to detect web application vulnerabilities, then security issues can be identified, but the process of creating WAF rules based on scanner results becomes tedious and complex
Solution Approach 1:
The patent introduces an intermediary system that sits between the vulnerability scanner and the WAF rule creation process. This intermediary automatically processes scanner results, extracts relevant vulnerability information, and generates corresponding WAF rules, thereby mediating the complex transformation from raw scan data to actionable security rules and eliminating manual rule creation efforts
Solution Approach 2:
The system enables self-service by allowing the vulnerability management process to automatically generate and configure WAF rules without human intervention. The scanner results are automatically parsed, analyzed, and converted into ready-to-deploy security rules, making the system self-sufficient in the rule creation task
2Adaptability or versatility
If multiple developers work on a web application, then functionality can be enhanced, but confusion related to application structure and content increases
Solution Approach 1:
The patent replaces manual tracking and documentation mechanisms with an automated system that dynamically generates visual representations of the application's URL and API structure. Instead of relying on developers to manually maintain structure documentation, the system automatically scans and visualizes the application architecture, making structure information always current and easily accessible
Solution Approach 2:
The system uses color-coding to visually represent different aspects of the application structure and vulnerability status. Different colors indicate various vulnerability severities, URL types, and structural elements, enabling developers to quickly comprehend the application landscape and identify issues without reading detailed documentation
3Duration of action of stationary object
If legacy applications are maintained, then business continuity is preserved, but tracking accessible URLs and APIs becomes cumbersome and leads to untracked vulnerabilities
Solution Approach 1:
The patent creates a universal system that can handle multiple types of web application structures, URL patterns, and API formats simultaneously. The visualization tool adapts to different application architectures and provides unified tracking mechanisms, making it equally effective for legacy applications as for modern applications without requiring application-specific customization
Solution Approach 2:
The system replaces manual URL and API tracking mechanisms with automated discovery and visualization tools. The system automatically scans the legacy application, discovers all accessible endpoints, and generates visual maps of the application structure, eliminating the need for manual tracking and ensuring no vulnerabilities are missed
Data Source
AI summary
A computer system is provided. The computer system includes a memory and at least one processor coupled to the memory and configured to extract, from a website vulnerability scanner log, a uniform resource locator (URL) and a vulnerability score and vulnerability classification associated with the URL. The at least one processor is further configured to generate an application vulnerability graph comprising connected nodes that are associated with a field of the URL. The nodes are labeled to indicate the associated field of the URL and color coded based on the vulnerability score. The nodes are also associated with the vulnerability classification. The at least one processor is further configured to enable or disable security protection against a user-selected vulnerability classification of a user-selected node by generating web application firewall security rules and/or web application firewall relaxation rules.


