IP Library Granted Patent US 11,544,385
Granted Patent B2
US 11,544,385 · App. 16/525,207 · Granted Jan 3, 2023

Method and system for dynamic testing with diagnostic assessment of software security vulnerability

Inventors: Matthew Canada (Rosedale, MD); Jerry Allen Craig, II (Knoxville, TN); Kathrine Dass (Severna Park, MD); Raja Krishnamurthy (Lewis Center, OH); Dipanjan Nag (Columbus, OH); Eugene Noble (Bethesda, MD); David Anthony Rigsby (Heath, OH); Richard Nathan Toney (Windsor Mill, MD); Stephen J. Veneruso (Columbus, OH)
Assignee: Ventech Solutions, Inc.
G06F21/577G06F21/52G06F21/552G06Q40/08G06F2221/033
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,544,385
App. No.
16/525,207
Granted
Jan 3, 2023
Kind
B2
Abstract

A method and system for dynamic testing and diagnostic assessment of security vulnerability of cloud-based enterprise software applications. The method comprises directing, to a software program under execution, a series of attack vectors; diagnosing a set of results associated with the software execution as comprising one of a security vulnerability and not a security vulnerability, the set of results produced based at least in part on the attack vectors; and assessing a dynamic security vulnerability score for the software program based at least in part on the diagnosing.

Claims (30)

1. A method of performing a security vulnerability diagnostic assessment of a software program, the method comprising:

directing, from a security assessing server, to a software program under execution, a series of attack vectors;

diagnosing a set of results associated with the software program under execution as comprising a security vulnerability in accordance with a cross-site forgery command, the set of results produced based at least in part on the series of attack vectors;

assessing a dynamic security vulnerability score for the software program based at least in part on the diagnosing;

awarding a certification status to the software program under execution based at least in part on the dynamic security vulnerability score in accordance with a pre-established certification standard;

correlating the certification status with a level of software security risk of an enterprise; and

based on the correlating, assessing a monetary premium of a risk insurance policy as merited by the enterprise based at least in part on a level of control ceded to an attacker in accordance with the set of results associated with the software program under execution.

2. The method of claim 1 wherein the software program comprises a cloud based software program that is communicatively accessible to the security assessing server during the execution based at least partly on having acquired no prior knowledge of execution attributes of the software program.

3. The method of claim 1 wherein the pre-established certification standard includes at least one of an industry mandated, a proprietary and a government mandated certification standards.

4. The method of claim 1 wherein the dynamic security vulnerability score comprises an aggregation of the set of results constituting the security vulnerability that is attributable to the series of attack vectors.

5. The method of claim 4 wherein the dynamic security vulnerability score comprises a weighted aggregation of the set of results constituting the security vulnerability that is attributable to the respective ones of the series of attack vectors.

6. The method of claim 1 wherein at least one attack vector of the series comprises a data set that encodes an attempt to exploit a security vulnerability aspect of the software program under execution.

7. The method of claim 6 wherein the data set includes at least one of an identifier of a class and a type of attack, a data value, a group of data values, a reference to a predetermined attack data set, and a copy of an attack data set.

8. The method of claim 1 wherein the diagnosing of the security vulnerability comprises the software program providing an error response indicating that at least one attack vector in the series of attack vectors successfully exploited a security vulnerability of the application.

9. A server computing system comprising:

a processor;

a memory storing a set of instructions, the instructions executable in the processor to:

direct, to a software program under execution, a series of attack vectors;

diagnose a set of results associated with the software program under execution as comprising a security vulnerability in accordance with a cross-site forgery command, the set of results produced based at least in part on the series of attack vectors;

assess a dynamic security vulnerability score for the software program based at least in part on the diagnosing;

award a certification status to the software program under execution based at least in part on the dynamic security vulnerability score in accordance with a pre-established certification standard;

correlate the certification status with a level of software security risk of an enterprise; and

based on the correlating, assessing a monetary premium of a risk insurance policy as merited by the enterprise based at least in part on a level of control ceded to an attacker in accordance with the set of results associated with the software program under execution.

10. The system of claim 9 wherein the software program comprises a cloud based software program that is communicatively accessible to the security assessing server during the execution based at least partly on having acquired no prior knowledge of execution attributes of the software program.

11. The system of claim 9 wherein the pre-established certification standard includes at least one of an industry mandated, a proprietary and a government mandated certification standards.

12. The system of claim 9 wherein the dynamic security vulnerability score comprises an aggregation of the set of results constituting the security vulnerability that is attributable to the series of attack vectors.

13. The system of claim 12 wherein the dynamic security vulnerability score comprises a weighted aggregation of the set of results constituting the security vulnerability that is attributable to the respective ones of the series of attack vectors.

14. The system of claim 9 wherein at least one attack vector of the series comprises a data set that encodes an attempt to exploit a security vulnerability aspect of the software program under execution.

15. The system of claim 14 wherein the data set includes at least one of an identifier of a class and a type of attack, a data value, a group of data values, a reference to a predetermined attack data set, and a copy of an attack data set.

16. The system of claim 9 wherein the diagnosing of the security vulnerability comprises the software program providing an error response indicating that at least one attack vector in the series of attack vectors successfully exploited a security vulnerability of the program.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 29, 2019
From: TONEY, RICHARD NATHAN; KRISHNAMURTHY, RAJA; NAG, DIPANJAN; CANADA, MATTHEW; CRAIG, JERRY ALLEN, II; DASS, KATHRINE; RIGSBY, DAVID ANTHONY; NOBLE, EUGENE; VENERUSO, STEPHEN J.
To: VENTECH SOLUTIONS, INC.
Reel/Frame 049893/0097 →
Continuity (1)
Related Publication 20210034752A1 · Feb 4, 2021