IP Library Patent Application 15675969
Patent Application
App. No. 15/675,969

GENERATING RULES TO DETECT SECURITY VULNERABILITIES BASED ON VULNERABILITY PRIMITIVES WITH ENTRY POINT FINDER

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
15/675,969
Abstract

A computer-based method is disclosed for generating rules to detect security vulnerabilities in a target business-critical application computer system based on vulnerability primitives. The method includes running a computer-based entry point finder at the target business-critical application computer system so that the entry point finder can access and extract information about source code that is actually installed at the target business-critical application computer system. The computer-based entry point finder creates a graphical-style database that represents software objects extracted from the target business-critical application computer system and relationships between the extracted software objects. The process includes identifying a vulnerability primitive for a security vulnerability at the target business-critical application computer system, and correlate the vulnerability primitive against information in the graphical-style database to help identify any relationships between a software object that is identified by the vulnerability primitive as being vulnerable and one or more other software objects in the target business-critical application computer system.

Claims (34)

1 . A computer-based method for generating rules to detect security vulnerabilities in a target business-critical application computer system based on vulnerability primitives, the method comprising:

running a computer-based entry point finder at the target business-critical application computer system so that the entry point finder can access and extract information about source code that is actually installed at the target business-critical application computer system;

creating, with the computer-based entry point finder, a graphical-style database that represents software objects extracted from the target business-critical application computer system and relationships between the extracted software objects;

identify a vulnerability primitive for a security vulnerability at the target business-critical application computer system; and

correlate the vulnerability primitive against information in the graphical-style database to help identify any relationships between a software n object that is identified by the vulnerability primitive as being vulnerable and one or more other software objects in the target business-critical application computer system.

2 . The computer-based method of claim 1 , wherein the software object that is identified by the vulnerability primitive is vulnerable, but undetectable or difficult to detect, and wherein the one or more other entry point software objects in the target business-critical application computer system are easier to detect software objects in the target business-critical application computer system.

3 . The computer-based method of claim 1 , wherein the security vulnerabilities are bugs or features of the target business-critical application computer system that expose the target business-critical application computer system to possible attack, or flaws in the target business-critical application computer system's security, and wherein the vulnerability primitive is a simple statement or indication that a particular software object is vulnerable.

4 . The computer-based method of claim 1 , wherein the graphical-style database represents each extracted software object as a node and each relationship between the extracted software objects as a connector between nodes.

5 . The computer-based method of claim 1 , further comprising:

extracting, with one or more worker modules of the entry point finder, a plurality of software objects from the target business-critical application computer system;

storing the extracted software objects in a computer-based search platform;

finding relationships, with one or more of the worker modules of the entry point finder, between the extracted software objects that are stored in the computer-based search platform; and

creating the graphical database based on the relationships found.

6 . The computer-based method of claim 1 , further comprising:

generating one or more detection rules for the security vulnerability represented by the vulnerability primitive based on the correlation based on the entry point software objects resulted from the entry point finder.

7 . The computer-based method of claim 6 , wherein one or more of the detection rules reference the one or more other software objects in the target business-critical application computer system identified through the correlation.

8 . The computer-based method of claim 7 , further comprising:

taking corrective measures to address the corresponding security vulnerability in response to one or more of the detection rules being satisfied.

9 . A computer-based system for generating rules to detect security vulnerabilities in a target business-critical application computer system based on vulnerability primitives, the computer-based system comprising:

a computer-based entry point finder running at the target business-critical application computer system and configured to create a graphical-style database that represents software objects from the target business-critical application computer system and relationships between the extracted software objects based on source code actually installed on the target business-critical application computer system;

a knowledge base of vulnerability primitives defining one or more vulnerability primitives for security vulnerabilities at the target business-critical application computer system; and

an affected entry point finder configured to correlate each respective one of the vulnerability primitives against information in the graphical-style database to help identify any relationships between a software object that is identified by the vulnerability primitive and one or more other software objects in the target business-critical application computer system.

10 . The computer-based system of claim 9 , wherein the software object that is identified by the vulnerability primitive is vulnerable, but undetectable or difficult to detect, and wherein the one or more other entry point software objects in the target business-critical application computer system are software objects in the target business-critical application computer system that are easier to detect than the software object that is identified in the vulnerability primitive.

11 . The computer-based system of claim 9 , wherein the security vulnerabilities are bugs or features of the target business-critical application computer system that expose the target business-critical application computer system to possible attack, or flaws in the target business-critical application computer system's security, and wherein the vulnerability primitive is a simple statement or indication that a particular software object is vulnerable.

12 . The computer-based system of claim 9 , wherein the graphical-style database represents each extracted software object as a node and each relationship between the extracted software objects as a connector between nodes.

13 . The computer-based system of claim 9 , wherein the computer-based entry point finder is configured to:

extract, with one or more worker modules, a plurality of software objects from the target business-critical application computer system;

store the extracted software objects in a computer-based search platform;

find relationships, with one or more of the worker modules, between the extracted software objects that are stored in the computer-based search platform; and

create the graphical-style database based on the relationships found.

14 . The computer-based system of claim 9 , further configured to:

generate one or more detection rules for the security vulnerability represented by each respective one of the vulnerability primitives based on the correlation with the entry point software objects resulted from the entry point finder.

15 . The computer-based system of claim 14 , wherein one or more of the detection rules reference the one or more other software objects in the target business-critical application computer system identified through the correlation.

16 . The computer-based system of claim 14 , wherein a corrective measure is taken to address the corresponding security vulnerability or vulnerabilities in response to one or more of the detection rules being satisfied.

Assignments (5)
RELEASE OF SECURITY INTEREST Recorded Aug 14, 2024
From: FIRST-CITIZENS BANK & TRUST COMPANY
To: ONAPSIS, INC.
Reel/Frame 068289/0125 →
RELEASE OF SECURITY INTEREST Recorded Nov 16, 2021
From: GOLUB CAPITAL LLC, AS AGENT
To: ONAPSIS, INC.
Reel/Frame 058129/0338 →
SECURITY INTEREST Recorded Sep 8, 2021
From: ONAPSIS INC.
To: SILICON VALLEY BANK
Reel/Frame 057407/0920 →
SECURITY INTEREST Recorded Oct 15, 2019
From: ONAPSIS INC.
To: GOLUB CAPITAL LLC, AS AGENT
Reel/Frame 050723/0914 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 31, 2017
From: ABRAHAM, SERGIO JAVIER; ARTUSO, PABLO AGUSTÍN
To: ONAPSIS, INC.
Reel/Frame 044341/0734 →