Prioritizing vulnerability based on application security context
According to some embodiments, a method includes determining a plurality of business transactions for a plurality of services provided by an application. The method further includes calculating a vulnerability score for each determined business transaction. Each vulnerability score is based on one or more application context factors of a plurality of application context factors. The method further includes displaying a graphical user interface. The graphical user interface includes a list of the determined business transactions and the calculated vulnerability score for each determined business transaction in the list.
1 . An apparatus comprising:
one or more memory units; and
one or more computer processors communicatively coupled to the one or more memory units and configured to:
access a plurality of application context factors stored in the one or more memory units, wherein the plurality of application context factors is associated with a plurality of weights, respectively;
determine a plurality of business transactions for a plurality of services provided by an application;
determine a subset of the plurality of application context factors applicable to each of the plurality of business transactions;
determine a further subset of the plurality of application context factors dependent on a status of the application, wherein the subset of the plurality of application context factors dynamically change according to a state of the application;
determine, based on the further subset of the plurality of application context factors, an associated subset of the plurality of weights for each of the plurality of business transactions;
calculate a vulnerability score for each of the plurality of business transactions using the respective subset of the plurality of weights; and
display a graphical user interface comprising:
an ordered list of the plurality of business transactions, where the plurality of business transactions is listed in descending order based on each business transaction's respective calculated vulnerability score; and
the vulnerability score for each of the plurality of business transactions in the ordered list.
2 . The apparatus of claim 1 , wherein each of the plurality of business transactions is a processing path used to fulfill a request for a particular service of the plurality of services provided by the application.
3 . The apparatus of claim 1 , wherein the plurality of application context factors are input using the graphical user interface.
4 . The apparatus of claim 1 , wherein the plurality of business transactions are determined automatically in real time.
5 . The apparatus of claim 1 , wherein the plurality of application context factors comprises:
whether the application is Internet facing;
a quantity of server ports open to read;
a sensitivity of each of the plurality of business transactions;
a value of data being stored;
a significance of the application to a business;
a number of admin users;
whether a firewall is present;
an encryption method used;
whether disk encryption is used;
how heavily the application is used;
an amount of revenue the application is generating; and
whether an application runtime behavior has changed.
6 . The apparatus of claim 1 , wherein calculating the vulnerability score for each of the plurality of business transactions comprises:
calculating a context score using one or more of the plurality of application context factors;
determining a Common Vulnerability Scoring System (CVSS) score; and
calculating the vulnerability score using the context score and the CVSS score.
7 . The apparatus of claim 1 , wherein determining the plurality of business transactions comprises analyzing a plurality of transaction identifications and a plurality of business transaction identifications associated with a plurality of transactions.
8 . A method by a computing system, the method comprising:
Determining a plurality of business transactions for a plurality of services provided by an application;
determining a plurality of application context factors, wherein the plurality of application context factors is associated with a plurality of weights, respectively;
determining a subset of the plurality of application context factors applicable to each of the plurality of business transactions;
determining a further subset of the plurality of application context factors dependent on a status of the application, wherein the subset of the plurality of application context factors dynamically change according to a state of the application;
determining, based on the further subset of the plurality of application context factors, an associated subset of the plurality of weights for each of the plurality of business transactions;
calculating a vulnerability score for each of the plurality of business transactions using the respective subset of the plurality of weights; and
displaying a graphical user interface comprising:
an ordered list of the plurality of business transactions, where the plurality of business transactions is listed in descending order based on each business transaction's respective calculated vulnerability score; and
the vulnerability score for each of the plurality of business transactions in the ordered list.
9 . The method of claim 8 , wherein each of the plurality of business transactions is a processing path used to fulfill a request for a particular service of the plurality of services provided by the application.
10 . The method of claim 8 , wherein the plurality of application context factors is input using the graphical user interface.
11 . The method of claim 8 , wherein the plurality of business transactions is determined automatically in real time.
12 . The method of claim 8 , wherein the plurality of application context factors comprises:
whether the application is Internet facing;
a quantity of server ports open to read;
a sensitivity of each of the plurality of business transactions;
a value of data being stored;
a significance of the application to a business;
a number of admin users;
whether a firewall is present;
an encryption method used;
whether disk encryption is used;
how heavily the application is used;
an amount of revenue the application is generating; and
whether an application runtime behavior has changed.
13 . The method of claim 8 , wherein calculating the vulnerability score for each of the plurality of business transactions comprises:
calculating a context score using one or more of the plurality of application context factors;
determining a Common Vulnerability Scoring System (CVSS) score; and
calculating the vulnerability score using the context score and the CVSS score.
14 . The method of claim 8 , wherein determining the plurality of business transactions comprises analyzing a plurality of transaction identifications and a plurality of business transaction identifications associated with a plurality of transactions.
15 . One or more computer-readable non-transitory storage media embodying instructions that, when executed by a processor, cause the processor to perform operations comprising:
determining a plurality of business transactions for a plurality of services provided by an application;
determining a plurality of application context factors, wherein the plurality of application context factors is associated with a plurality of weights, respectively;
determining a subset of the plurality of application context factors applicable to each of the plurality of business transactions;
determine a further subset of the plurality of application context factors dependent on a status of the application, wherein the subset of the plurality of application context factors dynamically change according to a state of the application;
determining, based on the further subset of the plurality of application context factors, an associated subset of the plurality of weights for each of the plurality of business transactions;
calculating a vulnerability score for each of the plurality of business transactions using the respective subset of the plurality of weights; and
displaying a graphical user interface comprising:
an ordered list of the plurality of business transactions, where the plurality of business transactions is listed in descending order based on each business transaction's respective calculated vulnerability score; and
the vulnerability score for each of the plurality of business transactions in the ordered list.
16 . The one or more computer-readable non-transitory storage media of claim 15 , wherein each of the plurality of business transactions is a processing path used to fulfill a request for a particular service of the plurality of services provided by the application.
17 . The one or more computer-readable non-transitory storage media of claim 15 , wherein the plurality of application context factors is input using the graphical user interface.
18 . The one or more computer-readable non-transitory storage media of claim 15 , wherein the plurality of business transactions is determined automatically in real time.
19 . The one or more computer-readable non-transitory storage claim 15 , wherein the plurality of application context factors comprises:
whether the application is Internet facing;
a quantity of server ports open to read;
a sensitivity of each of the plurality of business transactions;
a value of data being stored;
a significance of the application to a business;
a number of admin users;
whether a firewall is present;
an encryption method used;
whether disk encryption is used;
how heavily the application is used;
an amount of revenue the application is generating; and
whether an application runtime behavior has changed.
20 . The one or more computer-readable non-transitory storage media of claim 15 , wherein calculating the vulnerability score for each of the plurality of business transactions comprises:
calculating a context score using one or more of the plurality of application context factors;
determining a Common Vulnerability Scoring System (CVSS) score; and
calculating the vulnerability score using the context score and the CVSS score.