IP Library Granted Patent US 10,291,643
Granted Patent B2
US 10,291,643 · App. 15/381,045 · Granted May 14, 2019

Method and system for validating a vulnerability submitted by a tester in a crowdsourcing environment

Inventors: Antonio Rene Marquez (Austin, TX); Sergio Romulo Salazar (South Pasadena, CA); Nathan Sportsman (Austin, TX)
Assignee: Praetorian Group, Inc.
H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 10,291,643
App. No.
15/381,045
Granted
May 14, 2019
Kind
B2
Abstract

A method for validating a vulnerability submitted by a tester in a crowdsourcing environment. The method comprises identifying at least one vulnerability within at least one computer resource and receiving vulnerability data corresponding to the at least one vulnerability. The method further comprises pre-processing the vulnerability data to generate structured data and generating a replica of the vulnerability using the structured data and at least one validator. Further, the method comprises calculating a confidence score of the vulnerability using the replica of the vulnerability and a result of the at least one validator. The method executes at least one validating instruction based on the confidence score of the vulnerability.

Claims (41)

1. A method for validating a vulnerability submitted by a tester in a crowdsourcing environment, the method comprising:

identifying at least one vulnerability within at least one computer resource;

receiving vulnerability data corresponding to the at least one vulnerability;

pre-processing the vulnerability data to generate structured data;

generating a replica of the vulnerability using the structured data and at least one validator, the at least one validator being configured to verify an existence of a specific type of application vulnerability;

calculating a confidence score of the vulnerability using the replica of the vulnerability and a result of the at least one validator; and

executing at least one validating instruction based on the confidence score of the vulnerability, and a threshold confidence score.

2. A method according to claim 1 , wherein the at least one validating instruction comprises an instruction to approve the vulnerability when the confidence score of the vulnerability is above the threshold confidence score.

3. A method according to claim 1 , further comprising recommending a reward for the tester when the confidence score of the vulnerability is above the threshold confidence score.

4. A method according to claim 1 , further comprising sending the vulnerability to a manual triage queue when the confidence score of the vulnerability is below the threshold confidence score.

5. A method according to claim 1 , further comprising sending the vulnerability to a manual triage queue when the server fails to generate the replica of the vulnerability.

6. A method according to claim 1 , further comprising identifying at least one executable plan for generating the replica of the vulnerability.

7. A method according to claim 6 , further comprising sending the vulnerability to the manual triage queue when the server fails to identify the at least one executable plan for generating the replica of the vulnerability.

8. A method according to claim 1 , further comprising:

generating a signature for the vulnerability using the structured data;

comparing the signature for the vulnerability with a signature of at least one pre-stored vulnerability submission; and

notifying the tester when the signature for the vulnerability is matched with the signature of the at least one pre-stored vulnerability submission.

9. A method according to claim 8 , further comprising providing a reference of the at least one pre-stored vulnerability submission to the tester when the signature for the vulnerability is matched with the signature of the at least one pre-stored vulnerability submission.

10. A method according to claim 1 , further comprising:

extracting information from the structured data;

determining a scope of the vulnerability using the extracted information; and

notifying the tester when the scope of the vulnerability is outside a scope of a bug bounty project.

11. A method according to claim 10 , wherein the notifying the tester comprising rejecting the vulnerability when the scope of the vulnerability is outside the scope of a bug bounty project.

12. A method according to claim 1 , wherein the structured data include at least parameterization of an internet protocol, a hostname, an IP address, a port, a service, a uniform resource locator (URL), a parameter, a http method, a vulnerability type, and a section of code.

13. A system for validating a vulnerability submitted by a tester in a crowdsourcing environment, the system comprising:

a testing computer configured to identify at least one vulnerability within the at least one computer resource and submit vulnerability data corresponding to the at least one vulnerability to a server; and

the server configured to:

pre-process the vulnerability data to generate structured data;

generate a replica of the vulnerability using the structured data and at least one validator, the at least one validator being configured to verify an existence of a specific type of application vulnerability;

calculate a confidence score of the vulnerability using the replica of the vulnerability and a result of the at least one validator; and

execute at least one validating instruction based on the confidence score of the vulnerability, and a threshold confidence score.

14. A system according to claim 13 , wherein the server is configured to automatically generate the replica of the vulnerability in accordance with at least one executable plan.

15. A system according to claim 13 , wherein the server is configured to:

generate a signature for the vulnerability using the structured data;

compare the signature for the vulnerability with a signature of at least one pre-stored vulnerability submission; and

notify the tester when the signature for the vulnerability is matched with the signature of the at least one pre-stored vulnerability submission.

16. A system according to claim 13 , wherein the server is configured to:

extract information from the structured data;

determine a scope of the vulnerability using the extracting information; and

notify the tester when the scope of the vulnerability is outside a scope of a bug bounty project.

17. A system according to claim 13 , wherein the structured data includes at least parameterization of an internet protocol, a hostname, an IP address, a port, a service, a uniform resource locator (URL), a parameter, a http method, a vulnerability type, and a section of code.

Assignments (3)
SECURITY INTEREST Recorded Aug 28, 2026
From: PRAETORIAN SECURITY, INC.
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 075827/0535 →
CHANGE OF NAME Recorded Feb 13, 2020
From: PRAETORIAN GROUP, INC
To: PRAETORIAN SECURITY, INC.
Reel/Frame 051929/0855 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 16, 2018
From: MARQUEZ, ANTONIO RENE; SALAZAR, SERGIO ROMULO; SPORTSMAN, NATHAN
To: PRAETORIAN GROUP, INC.
Reel/Frame 045553/0044 →
Continuity (2)
Provisional Application 62368767 · Jul 29, 2016
Related Publication 20180034846A1 · Feb 1, 2018