IP Library Granted Patent US 11,438,358
Granted Patent B2
US 11,438,358 · App. 16/011,606 · Granted Sep 6, 2022

Aggregating asset vulnerabilities

Inventor: Michael Floering (Jamaica Plain, MA)
Assignee: Veracode, Inc.
H04L63/1433H04L61/1511H04L67/02
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,438,358
App. No.
16/011,606
Granted
Sep 6, 2022
Kind
B2
Abstract

In a system for determining vulnerabilities associated with a web property, requests are communicated to network accessible servers associated with a set of one or more domains. Software components indicated in responses from the network accessible servers are identified. Vulnerability information is obtained for the software components. An aggregate vulnerability is determined for each network accessible server based on at least one of a ratio of software components of the network accessible server indicated as vulnerable by the vulnerability information to total software components used by the network accessible server and a frequency of use of those of the plurality of software components of the network accessible server indicated as vulnerable by the vulnerability information. Vulnerability of the network accessible servers is indicated based on the aggregate vulnerabilities.

Claims (46)

1. A method comprising:

communicating first requests to network accessible servers associated with a set of one or

more domains;

identifying a plurality of software components indicated in responses from the network

accessible servers;

obtaining vulnerability information for the plurality of software components;

determining an aggregate vulnerability for each network accessible server based on at

least one of a ratio of software components of the network accessible server indicated as vulnerable by the vulnerability information to total software components used by the network accessible server and a frequency of use of those of the plurality of software components of the network accessible server indicated as vulnerable by the vulnerability information; and

indicating vulnerability of the network accessible servers based on the aggregate vulnerabilities.

2. The method of claim 1 , further comprising identifying the network accessible servers associated with the set of domains.

3. The method of claim 2 , wherein identifying the network accessible servers comprises communicating second requests to network addresses associated with the set of one or more domains to identify the network accessible servers.

4. The method of claim 1 , wherein communicating the first requests comprises communicating to each of the network accessible servers multiple requests, each of which corresponds to a different user agent.

5. The method of claim 1 , wherein the network accessible servers comprise web servers.

6. The method of claim 1 , wherein identifying the plurality of software components comprises determining identifiers and versions of the plurality of software components.

7. The method of claim 6 , wherein obtaining the vulnerability information for the plurality of software components comprises querying a set of one or more databases with the identifiers and versions of the plurality of software components.

8. The method of claim 1 , wherein determining frequency of use of those of the software components of the network accessible server indicated as vulnerable comprises determining frequency of use across the network accessible servers.

9. The method of claim 1 , wherein the first requests comprise hypertext transfer protocol requests.

10. The method of claim 1 , wherein identifying the plurality of software components comprises determining names of the plurality of software components.

11. The method of claim 10 , wherein obtaining the vulnerability information for the plurality of software components comprises querying a set of one or more databases with the names of the plurality of software components.

12. A non-transitory, computer-readable medium having instructions stored thereon that are executable by a computing device to perform operations comprising:

communicating first requests to network accessible servers associated with a set of one or

more domains;

identifying a plurality of software components indicated in responses from the network

accessible servers;

obtaining vulnerability information for the plurality of software components;

determining an aggregate vulnerability for each network accessible server based on at

least one of a ratio of software components of the network accessible server indicated as vulnerable by the vulnerability information to total software components of the network accessible server and frequency of use of those of the plurality of software components of the network accessible server indicated as vulnerable by the vulnerability information; and

indicating vulnerability of the network accessible servers based on the aggregate vulnerabilities.

13. The non-transitory, computer-readable medium of claim 12 , further having instructions executable by a computing device to perform operations comprising identifying the network accessible servers associated with the set of domains.

14. The non-transitory, computer-readable medium of claim 12 , wherein communicating the first requests comprises communicating to each of the network accessible servers multiple requests, each of which corresponds to a different user agent.

15. The non-transitory, computer-readable medium of claim 12 , wherein identifying the plurality of software components comprises determining identifiers and versions of the plurality of software components.

16. The non-transitory, computer-readable medium of claim 15 , wherein obtaining the vulnerability information for the plurality of software components comprises querying a set of one or more databases with the identifiers and versions of the plurality of software components.

17. The non-transitory, computer-readable medium of claim 12 , wherein obtaining the vulnerability information for the plurality of software components comprises querying a set of one or more databases with names of the plurality of software components.

18. An apparatus comprising:

a hardware processor; and

a physical storage medium having instructions stored therein, the instructions executable by the hardware processor to cause the apparatus to,

communicate via a set of one or more network interfaces first requests to network

accessible servers associated with a set of one or more domains;

identify a plurality of software components indicated in responses from the network

accessible servers;

obtain vulnerability information for the plurality of software components;

determine an aggregate vulnerability for each network accessible server based on at least

one of a ratio of software components of the network accessible server indicated as vulnerable by the vulnerability information to total software components of the network accessible server and frequency of use of those of the plurality of software components of the network accessible server indicated as vulnerable by the vulnerability information; and

indicate vulnerability of the network accessible servers based on the aggregate vulnerabilities.

19. The apparatus of claim 18 , wherein the instructions to identify the plurality of software components comprise instructions executable by the hardware processor to cause the apparatus to determine names of the plurality of software components.

20. The apparatus of claim 19 , wherein the instructions to identify the plurality of software components comprise instructions executable by the hardware processor to cause the apparatus to query a set of one or more databases with the names of the plurality of software components.

Assignments (4)
SECURITY INTEREST Recorded May 25, 2022
From: VERACODE, INC
To: DEUTSCHE BANK AG NEW YORK BRANCH, AS COLLATERAL AGENT
Reel/Frame 060011/0351 →
RELEASE OF SECURITY INTEREST IN PATENTS Recorded May 2, 2022
From: BARCLAYS BANK PLC, AS AGENT
To: VERACODE, INC.
Reel/Frame 059846/0650 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Nov 5, 2020
From: VERACODE, INC.
To: BARCLAYS BANK PLC, AS COLLATERAL AGENT
Reel/Frame 054330/0624 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Nov 8, 2018
From: FLOERING, MICHAEL
To: VERACODE, INC.
Reel/Frame 047457/0038 →