Website Vulnerability Scanning Using Application Segmentation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Conventional website vulnerability scanning methods are inefficient and time-consuming when applied to websites built on known web applications, often resulting in false positives and unnecessary bandwidth usage.

Innovation Solution

A website scanning system that employs a policy analysis device to identify known web applications, a crawler device to obtain link content, a web application identification device to determine known web applications, and a full scanning device to perform vulnerability scans only on non-identified applications, thereby reducing unnecessary scanning and increasing efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If conventional vulnerability scanning methods are used to scan all pages on a website, then comprehensive vulnerability detection is achieved, but scanning time and network bandwidth consumption increase significantly

Engineering Contradiction:
Improvevulnerability detection completenessVSAvoidscanning time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent segments the website scanning process into two distinct paths: one for known web applications and another for unknown applications. The policy analysis device divides the scanning task by identifying whether each URL belongs to a known web application, allowing different scanning strategies to be applied to different segments of the website, thereby reducing overall scanning time while maintaining detection completeness.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent performs preliminary identification of known web applications before conducting full vulnerability scans. The web application identification device and policy analysis device execute preliminary checks to recognize established applications, allowing the system to skip comprehensive scanning for these identified applications and proceed directly to targeted vulnerability checks, significantly reducing scanning time.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If conventional vulnerability scanning methods are used to scan all pages on a website, then comprehensive vulnerability detection is achieved, but network bandwidth consumption increases

Engineering Contradiction:
Improvevulnerability detection completenessVSAvoidnetwork bandwidth
Core Design Contradiction:
ReliabilityVSLoss of energy

Solution Approach 1:

The patent segments the website scanning process into two distinct paths: one for known web applications and another for unknown applications. The policy analysis device divides the scanning task by identifying whether each URL belongs to a known web application, allowing different scanning strategies to be applied to different segments of the website, thereby reducing overall scanning time while maintaining detection completeness.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial scanning action by performing only targeted vulnerability checks on known web applications rather than comprehensive scans. For identified known applications, the system performs selective vulnerability detection based on the application type, executing only necessary checks rather than full-page scanning, thus reducing network bandwidth consumption while maintaining effective vulnerability detection.

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If full vulnerability scanning is performed on all pages, then all vulnerabilities are detected, but false positives increase

Engineering Contradiction:
Improvevulnerability detection accuracyVSAvoidfalse positive rate
Core Design Contradiction:
ReliabilityVSMeasurement precision

Solution Approach 1:

The patent segments the website scanning process into two distinct paths: one for known web applications and another for unknown applications. The policy analysis device divides the scanning task by identifying whether each URL belongs to a known web application, allowing different scanning strategies to be applied to different segments of the website, thereby reducing overall scanning time while maintaining detection completeness.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent applies partial scanning action by performing only targeted vulnerability checks on known web applications rather than comprehensive scans. For identified known applications, the system performs selective vulnerability detection based on the application type, executing only necessary checks rather than full-page scanning, thus reducing network bandwidth consumption while maintaining effective vulnerability detection.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS10491618B2Method and apparatus for website scanning
Publication Date: 2019.11.26 NSFOCUS INFORMATION TECHNOLOGY CO LTD
  • US10491618B2 patent drawing
  • US10491618B2 patent drawing
  • US10491618B2 patent drawing

AI summary

A website scanning apparatus having a policy analysis device for determining whether a link in a target website belongs to a known web application used by the target website, if the link belongs to the identified web application, then a vulnerability scanning is not performed on the link; a crawler device for obtaining the link content that the link points to; a web application identification device for determining whether the link belongs to a known web application; a full scan device for performing a full vulnerability scanning on a link determined as not belonging to the known web application; and a known web application vulnerability detection device for performing vulnerability detection on the website for the determined identified web application according to known vulnerabilities of the identified web application to determine whether the known vulnerabilities of the identified web application exist in the website is provided.