IP Library Granted Patent US 9,667,643
Granted Patent B2
US 9,667,643 · App. 14/243,842 · Granted May 30, 2017

Apparatus, system, and method for correlating security vulnerabilities from multiple independent vulnerability assessment methods

Inventors: Mike Cotton (San Antonio, TX); Michael Cosby (San Antonio, TX); Gordon Mackay (San Antonio, TX); Brandon Shilling (San Antonio, TX)
Assignee: Digital Defense Incorporated
H04L63/1433G06F21/577
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 9,667,643
App. No.
14/243,842
Granted
May 30, 2017
Kind
B2
Abstract

The present disclosure relates to methods for correlating security vulnerability assessment data from a network vulnerability assessment, a static application security test (SAST) assessment and/or a zero day vulnerability metadata source.

Claims (20)

1. A method comprising:

receiving in computer memory a SAST assessment for a software application;

receiving in computer memory the software application;

instrumenting the software application based on the SAST assessment, wherein instrumenting the software application comprises inserting at least one instruction in the software application;

loading the instrumented software application on a network host;

executing the instrumented software application on the network host, wherein an output from an instrumented portion of the software application is outputted when the instrumented portion of the software application is executed on the network host, wherein the output is entered in a log file on the network host, and wherein the entry in the log file identifies a location of the instrumented portion within the software application;

performing a network vulnerability scan on the network host and creating a network vulnerability assessment based on the results of the network vulnerability scan;

receiving in computer memory at least one output from an instrumented and executed portion of the software application; and

correlating at least one item in the SAST assessment with at least one item in the network vulnerability assessment based on the at least one output by associating a location of the instrumented and executed portion of the software application within the software application, as determined by the at least one output, and a test program performed during the network vulnerability scan.

2. The method of claim 1 , where the location is identified by line number.

3. A non-transitory computer-readable medium comprising instructions, that when executed by a processor, cause the processor to perform the steps comprising:

receiving in computer memory a SAST assessment for a software application;

receiving in computer memory the software application;

instrumenting the software application based on the SAST assessment, wherein instrumenting the software application comprises inserting at least one instruction in the software application;

loading the instrumented software application on a network host;

executing the instrumented software application on the network host, wherein an output from an instrumented portion of the software application is outputted when the instrumented portion of the software application is executed on the network host, wherein the output is entered in a log file on the network host, and wherein the entry in the log file identifies a location of the instrumented portion within the software application;

performing a network vulnerability scan on the network host and creating a network vulnerability assessment based on the results of the network vulnerability scan;

receiving in computer memory at least one output from an instrumented portion of the software application; and

correlating at least one item in the SAST assessment with at least one item in the network vulnerability assessment based on the at least one output by associating a location of the instrumented and executed portion of the software application within the software application, as determined by the at least one output, and a test program performed during the network vulnerability scan.

4. The non-transitory computer-readable medium of claim 3 , where the location is identified by line number.

Assignments (7)
TERMINATION AND RELEASE OF FIRST LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 56229/0029 Recorded Nov 24, 2025
From: JEFFERIES FINANCE LLC
To: DIGITAL DEFENSE, INC.
Reel/Frame 073781/0173 →
TERMINATION AND RELEASE OF SECOND LIEN INTELLECTUAL PROPERTY SECURITY INTEREST RECORDED AT REEL/FRAME 56229/0076 Recorded Nov 21, 2025
From: ACQUIOM AGENCY SERVICES LLC
To: DIGITAL DEFENSE, INC.
Reel/Frame 073658/0891 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Aug 14, 2025
From: GOLUB CAPITAL MARKETS LLC (AS EXISTING AGENT)
To: ACQUIOM AGENCY SERVICES LLC (AS SUCCESSOR COLLATERAL AGENT)
Reel/Frame 072471/0665 →
ASSIGNMENT OF INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 20, 2021
From: JEFFERIES FINANCE LLC, AS EXISTING AGENT
To: GOLUB CAPITAL MARKETS LLC, AS SUCCESSOR AGENT
Reel/Frame 056322/0628 →
SECOND LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 13, 2021
From: DIGITAL DEFENSE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 056229/0076 →
FIRST LIEN INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded May 13, 2021
From: DIGITAL DEFENSE, INC.
To: JEFFERIES FINANCE LLC, AS COLLATERAL AGENT
Reel/Frame 056229/0029 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jun 25, 2014
From: COTTON, MIKE; MACKAY, GORDON; SHILLING, BRANDON; COSBY, MICHAEL
To: DIGITAL DEFENSE INCORPORATED
Reel/Frame 033174/0911 →
Continuity (2)
Provisional Application 61942182 · Feb 20, 2014
Related Publication 20150237063A1 · Aug 20, 2015