IP Library Granted Patent US 12,118,095
Granted Patent B1
US 12,118,095 · App. 17/389,692 · Granted Oct 15, 2024

Machine learning model for calculating confidence scores associated with potential security vulnerabilities

Inventors: Stuart Millar (Belfast, GB); Denis Podgurskii (Belfast, GB)
Assignee: Rapid7, Inc.
G06F21/577G06N20/00G06F2221/034
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,118,095
App. No.
17/389,692
Granted
Oct 15, 2024
Kind
B1
Abstract

Various embodiments include systems and methods of implementing a machine learning model for calculating confidence scores associated with potential security vulnerabilities. The machine learning model is trained using vulnerability data associated with a set of previously identified vulnerabilities, where the vulnerability data indicates whether a previously identified vulnerability is a true positive or a false positive. In some embodiments, scan traffic data may be obtained. The scan traffic data may be associated with potential security vulnerabilities detected via scan engine(s) that implement application security testing. The machine learning model may be used to determine respective confidence scores for each potential security vulnerability. According to some embodiments, responsive to a request for scan findings associated with a particular application, the respective confidence scores may be displayed via a vulnerability analysis graphical user interface.

Claims (45)

1. A system, comprising:

one or more hardware processors with associated memory that implement a machine learning (ML) model for calculating confidence scores associated with potential security vulnerabilities detected via application security testing, wherein the one or more hardware processors are configured to:

obtain scan traffic data associated with one or more potential security vulnerabilities detected via one or more scan engines that implement application security testing, wherein the one or more scan engines send scan requests to different applications and detect potential security vulnerabilities using scan responses obtained in response to the scan requests;

determine, using the ML model, respective confidence scores for each of the one or more potential security vulnerabilities, wherein the ML model is trained using vulnerability data associated with a set of previously identified vulnerabilities, and wherein the vulnerability data indicates, for each respective previously identified vulnerability of the set of previously identified vulnerabilities, whether the previously identified vulnerability is a true positive or a false positive;

responsive to a request for scan findings associated with a particular application, display the respective confidence scores via a vulnerability analysis graphical user interface; and

responsive to a selection of a particular potential security vulnerability via the vulnerability analysis graphical user interface, display a vulnerability details graphical user interface that indicates (a) a scan request that caused detection of the particular potential security vulnerability, (b) a scan response received in response to the scan request, (c) a module type of the particular potential security vulnerability detected, and (d) a confidence score determined by the ML model for the particular potential security vulnerability.

2. The system of claim 1 , wherein each of the respective confidence scores corresponds to a percentage value within a range of zero percent to one-hundred percent.

3. The system of claim 2 , wherein an individual confidence score having a percentage value of zero percent is indicative of the ML model having determined that a particular potential security vulnerability is most likely to be a false positive.

4. The system of claim 2 , wherein an individual confidence score having a percentage value of one-hundred percent is indicative of the ML model having determined that a particular potential security vulnerability is most likely to be a true positive.

5. The system of claim 1 , wherein the one or more hardware processors are configured to display respective vulnerability severities for each of the individual potential security vulnerabilities via the vulnerability analysis graphical user interface.

6. The system of claim 5 , wherein each of the respective vulnerability severities corresponds to one of: a high vulnerability severity; a medium vulnerability severity; and a low vulnerability severity.

7. The system of claim 1 , wherein the individual potential security vulnerabilities are sorted in a ranked order in the vulnerability analysis graphical user interface based on the respective confidence scores.

8. The system of claim 1 , wherein the one or more hardware processors are configured to identify, via the vulnerability details graphical user interface, a portion of the scan response that the ML model deems to have contributed to the confidence score.

9. The system of claim 1 , wherein the vulnerability details graphical user interface includes a selectable option to change a status of the particular potential security vulnerability from an unverified status to a verified status to identify the particular potential security vulnerability as a true positive security vulnerability.

10. The system of claim 1 , wherein the one or more hardware processors are configured to generate an alert to notify an analyst that the confidence score generated by the ML model is indicative of the particular potential security vulnerability being a false positive security vulnerability.

11. A method comprising:

implementing, using one or more hardware processors, a machine learning (ML) model for calculating confidence scores associated with potential security vulnerabilities detected via application security testing, wherein the implementing comprises:

obtaining scan traffic data associated with one or more potential security vulnerabilities detected via one or more scan engines that implement application security testing, wherein the one or more scan engines send scan requests to different applications and detect potential security vulnerabilities using scan responses obtained in response to the scan requests;

determining, using the ML model, respective confidence scores for each of the one or more potential security vulnerabilities, wherein the ML model is trained using vulnerability data associated with a set of previously identified vulnerabilities, and wherein the vulnerability data indicates, for each respective previously identified vulnerability of the set of previously identified vulnerabilities, whether the previously identified vulnerability is a true positive or a false positive;

responsive to a request for scan findings associated with a particular application, displaying the respective confidence scores via a vulnerability analysis graphical user interface; and

responsive to a selection of a particular potential security vulnerability via the vulnerability analysis graphical user interface, displaying a vulnerability details graphical user interface that indicates (a) a scan request that caused detection of the particular potential security vulnerability, (b) a scan response received in response to the scan request, (c) a module type of the particular potential security vulnerability detected, and (d) a confidence score determined by the ML model for the particular potential security vulnerability.

12. The method of claim 11 , wherein:

each of the respective confidence scores corresponds to a percentage value within a range of zero percent to one-hundred percent;

an individual confidence score having a percentage value of zero percent is indicative of the ML model having determined that a particular potential security vulnerability is most likely to be a false positive; and

an individual confidence score having a percentage value of one-hundred percent is indicative of the ML model having determined that a particular potential security vulnerability is most likely to be a true positive.

13. The method of claim 11 , further comprising:

displaying respective vulnerability severities for each of the individual potential security vulnerabilities via the vulnerability analysis graphical user interface; and

wherein each of the respective vulnerability severities corresponds to one of: a high vulnerability severity; a medium vulnerability severity; and a low vulnerability severity.

14. The method of claim 13 , wherein the individual potential security vulnerabilities are sorted in a ranked order in the vulnerability analysis graphical user interface based on a combination of the respective confidence scores and the respective vulnerability severities.

15. One or more non-transitory computer-accessible storage media storing program instructions that, when executed on or across one or more processors, implement at least a portion of a system that implements a machine learning (ML) model for calculating confidence scores associated with potential security vulnerabilities detected via application security testing and cause the system to:

obtain scan traffic data associated with one or more potential security vulnerabilities detected via one or more scan engines that implement application security testing, wherein the one or more scan engines send scan requests to different applications and detect potential security vulnerabilities using scan responses obtained in response to the scan requests;

determine, using the ML model, respective confidence scores for each of the one or more potential security vulnerabilities, wherein the ML model is trained using vulnerability data associated with a set of previously identified vulnerabilities, and wherein the vulnerability data indicates, for each respective previously identified vulnerability of the set of previously identified vulnerabilities, whether the previously identified vulnerability is a true positive or a false positive;

responsive to a request for scan findings associated with a particular application, display the respective confidence scores via a vulnerability analysis graphical user interface; and

responsive to a selection of a particular potential security vulnerability via the vulnerability analysis graphical user interface, display a vulnerability details graphical user interface that indicates (a) a scan request that caused detection of the particular potential security vulnerability, (b) a scan response received in response to the scan request, (c) a module type of the particular potential security vulnerability detected, and (d) a confidence score determined by the ML model for the particular potential security vulnerability.

16. The one or more non-transitory computer-accessible storage media of claim 15 , wherein:

each of the respective confidence scores corresponds to a percentage value within a range of zero percent to one-hundred percent;

an individual confidence score having a percentage value of zero percent is indicative of the ML model having determined that a particular potential security vulnerability is most likely to be a false positive; and

an individual confidence score having a percentage value of one-hundred percent is indicative of the ML model having determined that a particular potential security vulnerability is most likely to be a true positive.

17. The one or more non-transitory computer-accessible storage media of claim 15 , wherein the program instructions when executed on or across the one or more processors cause the system to:

display respective vulnerability severities for each of the individual potential security vulnerabilities via the vulnerability analysis graphical user interface;

wherein each of the respective vulnerability severities corresponds to one of: a high vulnerability severity; a medium vulnerability severity; and a low vulnerability severity; and

wherein the individual potential security vulnerabilities are sorted in a ranked order in the vulnerability analysis graphical user interface based on a combination of the respective confidence scores and the respective vulnerability severities.

18. The one or more non-transitory computer-accessible storage media of claim 15 , wherein the program instructions when executed on or across the one or more processors cause the system to identify, via the vulnerability details graphical user interface, a portion of the scan response that the ML model deems to have contributed to the confidence score.

19. The one or more non-transitory computer-accessible storage media of 15 , wherein the vulnerability details graphical user interface includes a selectable option to change a status of the particular potential security vulnerability from an unverified status to a verified status to identify the particular potential security vulnerability as a true positive security vulnerability.

20. The one or more non-transitory computer-accessible storage media of 15 , wherein the program instructions when executed on or across the one or more processors cause the system to generate an alert to notify an analyst that the confidence score generated by the ML model is indicative of the particular potential security vulnerability being a false positive security vulnerability.

Assignments (2)
SECURITY INTEREST Recorded Jun 26, 2025
From: RAPID7, INC.; RAPID7 LLC
To: JPMORGAN CHASE BANK, N.A.
Reel/Frame 071743/0537 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Dec 15, 2021
From: MILLAR, STUART; PODGURSKII, DENIS
To: RAPID7, INC.
Reel/Frame 058397/0186 →
Cited By (3)
US 12,511,477 US 12,619,734 US 12,719,887