IP Library Granted Patent US 12,346,487
Granted Patent B2
US 12,346,487 · App. 17/659,572 · Granted Jul 1, 2025

System and method for detecting cybersecurity vulnerabilities via device attribute resolution

Inventors: Evgeny Luk-Zilberman (Herzliya, IL); Tom Hanetz (Tel Aviv, IL); Ron Shoham (Tel Aviv, IL); Yuval Friedlander (Petah-Tiqwa, IL); Gil Ben Zvi (Hod Hasharon, IL)
Assignee: Armis Security Ltd.
G06F21/73G06F16/152G06F16/2425G06F16/90344G06F21/577H04L9/3213H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 12,346,487
App. No.
17/659,572
Granted
Jul 1, 2025
Kind
B2
Abstract

A system and method for vulnerability detection. A method includes: tokenizing device attribute data for a device into at least one set of first tokens, wherein each of the first tokens is formatted according to a token schema; creating at least one device attribute string, each device attribute string including one of the first tokens; matching each of the at least one device attribute string to combinations of device attributes stored in a vulnerabilities database in order to identify at least one matching combination of device attributes for the device, wherein the vulnerabilities database stores mappings between combinations of device attributes and vulnerabilities, wherein each combination of device attributes in the vulnerabilities database includes second tokens formatted according to the token schema; detecting at least one vulnerability of the device based on the at least one matching combination of device attributes and the mappings in the vulnerabilities database.

Claims (35)

1. A method for vulnerability detection, comprising:

obtaining, from one or more data sources, device attribute data, the device attribute data comprising one or more attributes, each attribute related to a hardware type, operating system, or application of a device;

cleaning the device attribute data by removing non-character symbols, punctuation, and/or duplicate portions of data from the device attribute data;

tokenizing, using a tokenizer function, the cleaned device attribute data for the device into one or more first tokens, the one or more first tokens formatted according to a token schema, and each first token representing an attribute of the one or more attributes, wherein a null token is created for an attribute that is not included in the obtained device attribute data;

creating at least one device attribute string based on the one or more first tokens, wherein each of the at least one device attribute string corresponds to a respective entity of the device, wherein each entity of the device has a type selected from: hardware, operating system, or application, and wherein each at least one device attribute string comprises a token indicating the entity type to which the at least one device attribute string corresponds;

matching, by applying one or more matching rules based on the token indicating the entity type, each of the at least one device attribute string to a combination of device attributes of a plurality of combinations of device attributes stored in a vulnerabilities database, wherein the vulnerabilities database stores mappings between each combination of device attributes of the plurality of combinations of device attributes and one or more vulnerabilities, wherein each combination of device attributes in the vulnerabilities database is defined by a second token formatted according to the token schema; and

detecting at least one vulnerability of the device based on the matching of the device attribute strong to the combination of device attributes and the corresponding mapping in the vulnerabilities database.

2. The method of claim 1 , further comprising:

performing at least one mitigation action with respect to the device based on the detected at least one vulnerability.

3. The method of claim 1 , wherein the at least one device attribute string is at least one first device attribute string, wherein each combination of device attributes in the vulnerabilities database is a second device attribute string.

4. The method of claim 1 , wherein the vulnerabilities in the vulnerabilities database are identified by respective common vulnerabilities and exposures identifiers.

5. The method of claim 1 , wherein matching each of the at least one device attribute string to the plurality of combinations of device attributes stored in the vulnerabilities database further comprises:

comparing the set of first tokens included in the device attribute string to each of the plurality of combinations of device attributes.

6. A non-transitory computer readable medium having stored thereon instructions for causing a processing circuitry to execute a process, the process comprising:

obtaining, from one or more data sources, device attribute data, the device attribute data comprising one or more attributes, each attribute related to a hardware type, operating system, or application of a device;

cleaning the device attribute data by removing non-character symbols, punctuation, and/or duplicate portions of data from the device attribute data;

tokenizing, using a tokenizer function, the cleaned device attribute data for the device into one or more first tokens, the one or more first tokens formatted according to a token schema, and each first token representing an attribute of the one or more attributes, wherein a null token is created for an attribute that is not included in the obtained device attribute data;

creating at least one device attribute string based on the one or more first tokens, wherein each of the at least one device attribute string corresponds to a respective entity of the device, wherein each entity of the device has a type selected from: hardware, operating system, or application, and wherein each at least one device attribute string comprises a token indicating the entity type to which the at least one device attribute string corresponds;

matching, by applying one or more matching rules based on the token indicating the entity type, each of the at least one device attribute string to a combination of device attributes of a plurality of combinations of device attributes stored in a vulnerabilities database, wherein the vulnerabilities database stores mappings between each combination of device attributes of the plurality of combinations of device attributes and one or more vulnerabilities, wherein each combination of device attributes in the vulnerabilities database is defined by a second token formatted according to the token schema; and

detecting at least one vulnerability of the device based on the matching of the device attribute strong to the combination of device attributes and the corresponding mapping in the vulnerabilities database.

7. A system for vulnerability detection, comprising:

a processing circuitry; and

a memory, the memory containing instructions that, when executed by the processing circuitry, configure the system to:

obtain, from one or more data sources, device attribute data, the device attribute data comprising one or more attributes, each attribute related to a hardware type, operating system, or application of a device;

clean the device attribute data by removing non-character symbols, punctuation, and/or duplicate portions of data from the device attribute data;

tokenize, using a tokenizer function, the cleaned device attribute data for the device into one or more first tokens, the one or more first tokens formatted according to a token schema, and each first token representing an attribute of the one or more attributes, wherein a null token is created for an attribute that is not included in the obtained device attribute data;

create at least one device attribute string based on the one or more first tokens, wherein each of the at least one device attribute string corresponds to a respective entity of the device, wherein each entity of the device has a type selected from: hardware, operating system, or application, and wherein each at least one device attribute string comprises a token indicating the entity type to which the at least one device attribute string corresponds;

match, by applying one or more matching rules based on the token indicating the entity type, each of the at least one device attribute string to a combination of device attributes of a plurality of combinations of device attributes stored in a vulnerabilities database, wherein the vulnerabilities database stores mappings between each combination of device attributes of the plurality of combinations of device attributes and one or more vulnerabilities, wherein each combination of device attributes in the vulnerabilities database is defined by a second token formatted according to the token schema; and

detect at least one vulnerability of the device based on the matching of the device attribute strong to the combination of device attributes and the corresponding mapping in the vulnerabilities database.

8. The system of claim 7 , wherein the system is further configured to:

perform at least one mitigation action with respect to the device based on the detected at least one vulnerability.

9. The system of claim 7 , wherein the at least one device attribute string is at least one first device attribute string, wherein each combination of device attributes in the vulnerabilities database is a second device attribute string.

10. The system of claim 7 , wherein the vulnerabilities in the vulnerabilities database are identified by respective common vulnerabilities and exposures identifiers.

11. The system of claim 7 , wherein the system is further configured to:

compare the set of first tokens included in the device attribute string to each of the plurality of combinations of device attributes.

Assignments (3)
RELEASE OF SECURITY INTEREST Recorded Apr 21, 2026
From: HERCULES CAPITAL, INC.
To: ARMIS SECURITY LTD; ARMIS INC.
Reel/Frame 075477/0965 →
INTELLECTUAL PROPERTY SECURITY AGREEMENT Recorded Mar 5, 2024
From: ARMIS SECURITY LTD.
To: HERCULES CAPITAL, INC., AS ADMINISTRATIVE AND COLLATERAL AGENT
Reel/Frame 066740/0499 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Apr 18, 2022
From: LUK-ZILBERMAN, EVGENY; HANETZ, TOM; SHOHAM, RON; FRIEDLANDER, YUVAL; BEN ZVI, GIL
To: ARMIS SECURITY LTD.
Reel/Frame 059625/0693 →
Continuity (1)
Related Publication 20230336580A1 · Oct 19, 2023
References Cited (20)
US 9031087B2 · Petrovykh · 2015 [cited by applicant]
US 10187369B2 · Caldera et al. · 2019 [cited by applicant]
US 10291635B2 · Muddu et al. · 2019 [cited by applicant]
US 10313383B2 · Sommer · 2019 [cited by applicant]
US 10419418B2 · Grajek et al. · 2019 [cited by applicant]
US 20140173738A1 · Condry · 2014 [cited by examiner]
US 20150128274A1 · Giokas · 2015 [cited by applicant]
US 20180309747A1 · Sweet et al. · 2018 [cited by applicant]
US 20190097907A1 · Nickolov et al. · 2019 [cited by applicant]
US 20190156042A1 · Kim et al. · 2019 [cited by applicant]
US 20190288852A1 · Shetye · 2019 [cited by examiner]
US 20190379699A1 · Katragadda et al. · 2019 [cited by applicant]
US 20210112087A1 · Tassoumt et al. · 2021 [cited by applicant]
US 20230014556A1 · Schuler · 2023 [cited by examiner]
US 20230090050A1 · Kellner · 2023 [cited by examiner]
CN 104520871A · 2015 [cited by examiner]
CN 110661759A · 2020 [cited by applicant]
CN 112560045A · 2021 [cited by examiner]
Johnson, Daniel. “NLTK Tokenize: Words and Sentences Tokenizer with Example”. Updated Mar. 8, 2022. https://www.guru99.com/tokenize-words-sentences-nltk.html. [cited by applicant]
International Search Report and Written Opinion of corresponding PCT Application No. PCT/IB2023/053857, mailed Jul. 12, 2023, ISA: Israel Patent Office, 9 pages. [cited by applicant]
Cited By (3)
US 12,572,846 US 12,574,399 US 12,695,752