IP Library Patent Application 17975651
Patent Application
App. No. 17/975,651

VULNERABILITY MANAGEMENT FOR DISTRIBUTED SOFTWARE SYSTEMS

Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US None
App. No.
17/975,651
Abstract

In an example, a computer-implemented method may include receiving vulnerability data indicative of a vulnerability associated with a computing environment from a security scanning platform. Further, the method may include determining a type of the vulnerability and determining an operating system component, an application component, or both being vulnerable to a security threat based on the type of vulnerability. Furthermore, the method may include determining a compute node, of the computing environment, hosting the operating system component, the application component, or both that are vulnerable. Further, the method may include generating an alert notification indicating that the operating system component, the application component, or both along with the determined compute node are vulnerable to the security threat.

Claims (73)

1 . A method comprising:

receiving vulnerability data indicative of a vulnerability associated with a computing environment from a security scanning platform;

determining a type of the vulnerability;

determining, based on the type of vulnerability, an operating system component, an application component, or both being vulnerable to a security threat;

determining a compute node, of the computing environment, hosting the operating system component, the application component, or both that are vulnerable; and

generating an alert notification indicating that the operating system component, the application component, or both along with the determined compute node are vulnerable to the security threat.

2 . The method of claim 1 , further comprising:

determining a distributed software system that is impacted by the vulnerability in the operating system component, application component, or both, wherein the distributed software system is a multi-tier application including multiple application components distributed across multiple compute nodes in the computing environment for execution; and

generating an alert notification indicating that the distributed software system is vulnerable.

3 . The method of claim 1 , wherein determining the operating system component, the application component, or both are vulnerable to the security threat comprises:

fetching process details, port details, or both corresponding to the type of vulnerability;

mapping the process details, port details, or both to the operating system component, the application component, or both; and

determining that the operating system component, the application component, or both being vulnerable to the security threat based on the mapping.

4 . The method of claim 3 , wherein fetching process details, port details, or both comprises:

collecting metrics corresponding to operating system components, application components, or both via monitoring tool that monitors the computing environment; and

fetching the process details, port details, or both corresponding to the type of vulnerability from the collected metrics.

5 . The method of claim 1 , wherein determining the type of the vulnerability comprises:

determining the type of the vulnerability by comparing the vulnerability with predefined vulnerabilities.

6 . The method of claim 1 , wherein the type of vulnerability comprises an open port vulnerability, a cross-site scripting (XSS) vulnerability, a cipher suite vulnerability, a code/library vulnerability, or any combination thereof.

7 . The method of claim 1 , wherein generating the alert notification comprises:

determining a recommended action to mitigate a security vulnerability related to the security threat; and

generating the alert notification including the recommended action to mitigate the security vulnerability related to the security threat.

8 . The method of claim 1 , further comprising:

retrieving vulnerability information associated with the vulnerability from a public database;

generating the alert notification including the vulnerability information; and

presenting the alert notification including the vulnerability information on a graphical user interface, invoking a corresponding application programming interface to send the alert notification including the vulnerability information to a management application, or both.

9 . The method of claim 8 , further comprising:

generating an insight based on the vulnerability information; and

presenting the insight to a user via the graphical user interface, application programming interface (API), or both.

10 . The method of claim 9 , wherein generating the insight comprises at least one of:

categorizing security vulnerabilities related to the security threat based on a type, a severity level, or both associated with the security threat;

providing an application-level visibility, a host-level visibility, or both associated with the security threat;

recommending an action to be performed to mitigate a security vulnerability related to the security threat;

classifying a severity of the security threat based on a vulnerability score; and

exploring an access exploitation and an impact of the security threat.

11 . The method of claim 8 , wherein retrieving the vulnerability information comprises:

transmitting a hypertext transfer protocol (HTTP) get command to a web server that includes the public database; and

receiving a response to the HTTP get command from the web server, the response including the vulnerability information associated with the vulnerability.

12 . A management node comprising:

a processor; and

memory coupled to the processor, wherein the memory comprises:

a vulnerability insight module to:

receive vulnerability data indicative of a vulnerability associated with a cloud computing environment from a security scanning platform;

determine a type of the vulnerability;

determine, based on the type of vulnerability, an operating system component, an application component, or both being vulnerable to a security threat;

determine a distributed software system, deployed in the cloud computing environment, that is impacted by the vulnerability in the operating system component, application component, or both, wherein the distributed software system is a multi-tier application including multiple application components distributed across multiple compute nodes in the computing environment for execution; and

generate an alert notification indicating that the distributed software system is vulnerable.

13 . The management node of claim 12 , wherein the vulnerability insight module is to:

determine a compute node, of the computing environment, hosting the operating system component, the application component, or both that are vulnerable; and

generate an alert notification indicating that the operating system component, the application component, or both along with the determined compute node are vulnerable.

14 . The management node of claim 12 , wherein the vulnerability insight module is to:

fetch process details, port details, or both corresponding to the type of vulnerability;

map the process details, port details, or both to the operating system component, the application component, or both; and

determine that the operating system component, the application component, or both being vulnerable to the security threat based on the mapping.

15 . The management node of claim 14 , wherein the vulnerability insight module is to:

collect metrics corresponding to operating system components, application components, or both via monitoring tool that monitors the computing environment; and

fetch the process details, port details, or both corresponding to the type of vulnerability from the collected metrics.

16 . The management node of claim 12 , wherein the vulnerability insight module is to determine the type of the vulnerability by comparing the vulnerability with predefined vulnerabilities.

17 . The management node of claim 12 , wherein the vulnerability insight module is to:

determine a recommended action to mitigate a security vulnerability related to the security threat; and

generate the alert notification including the recommended action to mitigate the security vulnerability related to the security threat.

18 . A non-transitory computer-readable storage medium encoded with instructions that, when executed by a processor of a management node, cause the processor to:

receive vulnerability data indicative of a vulnerability associated with a computing environment from a security scanning platform;

determine a type of the vulnerability;

determine, based on the type of vulnerability, an operating system component, an application component, or both being vulnerable to a security threat;

determine a compute node, of the computing environment, hosting the operating system component, the application component, or both that are vulnerable; and

generate an alert notification indicating that the operating system component, the application component, or both along with the determined compute node are vulnerable to the security threat.

19 . The non-transitory computer-readable storage medium of claim 18 , further comprising instructions to:

determine a distributed software system that is impacted by the vulnerability in the operating system component, application component, or both, wherein the distributed software system is a multi-tier application including multiple application components distributed across multiple compute nodes in the computing environment for execution; and

generate an alert notification indicating that the distributed software system is vulnerable.

20 . The non-transitory computer-readable storage medium of claim 18 , wherein the instructions to generate the alert notification comprise instructions to:

determine a recommended action to mitigate a security vulnerability related to the security threat; and

generate the alert notification including the recommended action to mitigate the security vulnerability related to the security threat.

Assignments (2)
CHANGE OF NAME Recorded Feb 27, 2024
From: VMWARE, INC.
To: VMWARE LLC
Reel/Frame 066692/0103 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 28, 2022
From: THIRUMALACHAR, PADMINI SAMPIGE; SANKAR, MADHAN; S, PUNITH; VIRPARIYA, SMEETH
To: VMWARE, INC.
Reel/Frame 061573/0787 →