IP Library Granted Patent US 11,570,196
Granted Patent B2
US 11,570,196 · App. 16/801,459 · Granted Jan 31, 2023

Method for determining duplication of security vulnerability and analysis apparatus using same

Inventors: Bong Goo Kang (Seongnam-si, KR); Min Seob Lee (Seongnam-si, KR); Won Tae Jang (Seongnam-si, KR); June Ahn (Seongnam-si, KR); Jihwan Yoon (Seongnam-si, KR)
Assignee: NAVER CLOUD CORPORATION
H04L63/1433G06F16/2255G06F16/9566G06F16/986H04L9/0643
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,570,196
App. No.
16/801,459
Granted
Jan 31, 2023
Kind
B2
Abstract

A method for determining duplication of a vulnerability may include a vulnerability extraction step of extracting vulnerability uniform resource locator (URL) addresses including the vulnerability from an analysis target server; a hash generation step of generating the URL hash value corresponding to the extracted vulnerability from the vulnerability URL address; and a duplication determination step of determining, when the URL hash value is present in the first comparison table, that the vulnerability is duplicated and excluding the corresponding vulnerability from vulnerability information.

Claims (32)

1. A method for determining duplication of a vulnerability of an analysis target server, by an analysis apparatus, the method comprising:

a vulnerability extraction step of extracting a vulnerability uniform resource locator (URL) address of the vulnerability from the analysis target server;

a hash generation step of generating a URL hash value corresponding to the extracted vulnerability by rearranging a URL character string of the vulnerability URL address; and

a duplication determination step of determining, when the URL hash value is present in a first comparison table, that the vulnerability is duplicated, and excluding the corresponding vulnerability from vulnerability information.

2. The method of claim 1 , further comprising:

an updating step of including when the URL hash value is not present in the first comparison table, the vulnerability in the vulnerability information, and adding the URL hash value to the first comparison table to update the URL hash value.

3. The method of claim 2 , wherein the hash generation step includes

generating the URL character string by removing a parameter name and a parameter value of a vulnerability parameter determined as the vulnerability in the vulnerability URL address,

removing parameter values of remaining parameters included in the URL character string and rearranging the parameter names of the parameters according to an ordering order to generate the rearranged character string, and

generating the URL hash value by applying a hash function to the rearranged character string.

4. A non-transitory computer readable recording medium storing a program which, when executed by a processor, performs the method for determining duplication of a vulnerability as defined in claim 1 .

5. A method for determining duplication of a vulnerability of an analysis target server, by an analysis apparatus, the method comprising:

a vulnerability extraction step of extracting a vulnerability uniform resource locator (URL) address of the vulnerability from the analysis target server;

a hash generation step of generating a tag hash value corresponding to a response page connected to the vulnerability URL address by applying a hash function to a tag character string connecting tag names extracted from the response papge; and

a duplication determination step of determining, when the tag hash value is present in a second comparison table, that the vulnerability is duplicated and excluding the corresponding vulnerability from vulnerability information.

6. The method of claim 5 , further comprising:

an updating step of including, when the tag hash value is not present in the second comparison table, the vulnerability in the vulnerability information, and adding the tag hash value to the second comparison table to update the tag hash value.

7. The method of claim 5 , wherein the hash generation step includes

extracting the tag names of tags included in a hypertext markup language (HTML) of the response page,

removing tag names corresponding to tags for contents among the tag names, and

connecting the tag names according to an order disclosed in the HTML code to generate the tag character string.

8. A method for managing vulnerability information of an analysis target server, by an analysis apparatus, the method comprising:

extracting a vulnerability URL address including a vulnerability from the analysis target server;

generating a URL hash value corresponding to the vulnerability by rearranging a URL character string of the vulnerability URL address;

searching the URL hash value in a first comparison table;

generating, when the URL hash value is present in the first comparison table, a tag hash value corresponding to a response page connected to the vulnerability URL address;

searching the tag hash value in a second comparison table; and

determining, when the tag hash value is present in the second comparison table, that the vulnerability is duplicated and excluding the corresponding vulnerability from vulnerability information.

9. An analysis apparatus for determining duplication of a vulnerability of an analysis target server, comprising:

a vulnerability extraction unit extracting a vulnerability URL address including a vulnerability from the analysis target server;

a hash generation unit generating a URL hash value corresponding to the vulnerability by rearranging a URL character string of the vulnerability URL address or generating a tag hash value corresponding to a response page connected to the vulnerability URL address; and

a duplication determination unit determining whether the vulnerability is duplicated by using the URL hash value or tag hash value.

Assignments (2)
CHANGE OF NAME Recorded May 28, 2021
From: NAVER BUSINESS PLATFORM CORPORATION
To: NAVER CLOUD CORPORATION
Reel/Frame 056424/0336 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Feb 26, 2020
From: KANG, BONG GOO; LEE, MIN SEOB; JANG, WON TAE; AHN, JUNE; YOON, JIHWAN
To: NAVER BUSINESS PLATFORM CORPORATION
Reel/Frame 051934/0858 →
Priority Claims (1)
KR 10-2019-0036357 · Mar 28, 2019 · national
Continuity (1)
Related Publication 20200314135A1 · Oct 1, 2020