IP Library › Granted Patent US 11,113,406
Granted Patent B2
US 11,113,406 · App. 16/504,367 · Granted Sep 7, 2021

Methods and systems for de-duplication of findings

Inventors: Adam Youngberg (Allen, TX); Stephen Kent (Fairfax, VA)
Assignee: CAPITAL ONE SERVICES, LLC
G06F21/577G06F16/1748G06F21/552G06F21/562G06F21/566
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,113,406
App. No.
16/504,367
Granted
Sep 7, 2021
Kind
B2
Abstract

A system for performing de-duplication of findings includes a non-transitory computer readable medium and a processor. The non-transitory computer readable medium stores normalized findings of application code performed by at least one software security analysis tool. Each normalized finding is identifiable by a fingerprint. The processor receives a first finding in a first vendor-provided format from a first software security analysis tool that performs a scan of application code. The processor receives a second finding in a second vendor-provided format from a second software security analysis tool. The processor normalizes the findings to a standardized taxonomy. The processor determines a first fingerprint and a second fingerprint that respectively identify the normalized first and second findings. The processor determines any need to update the normalized first finding by comparing the normalized second finding with the normalized first finding after determining that the second fingerprint at least partially matches the first fingerprint.

Claims (79)

1. A system for performing de-duplication of findings, comprising:

one or more processors;

a graphical user interface configured for display and operably connected to the one or more processors; and

a memory in communication with the one or more processors and storing instructions that, when executed by the one or more processors, are configured to:

receive, from a first software security analysis tool, a first finding comprising one or more software issues, the first software security analysis tool being a Static Application Security Testing (SAST) tool or a Dynamic Application Security Testing (DAST) tool;

determine a first identifier that identifies the first finding;

store the first finding and the first identifier;

receive, from a second software security analysis tool, a second finding comprising one or more software issues, the second software security analysis tool being a Static Application Security Testing (SAST) tool or a Dynamic Application Security Testing (DAST) tool;

determine a second identifier that identifies the second finding;

determine that the second identifier at least partially matches the first identifier;

appending the first finding to the second finding;

comparing the one or more software issues of the first finding to the one or more software issues of the second finding to determine at least a partial match; and

removing the at least partial match from the first finding.

2. The system of claim 1 , wherein the one or more processors are further configured to normalize the first finding and the second finding to a standardized taxonomy.

3. The system of claim 2 , wherein

the normalized first finding is associated with a first timestamp, and

the normalized second finding is associated with a second timestamp.

4. The system of claim 3 , wherein the one or more processors are further configured to:

store an update to the normalized first finding after determining that the normalized second finding differs from the normalized first finding, the update to the normalized first finding being associated with the second timestamp;

cause the graphical user interface to display the normalized first finding and the first timestamp; and

cause the graphical user interface to display the update to the normalized first finding and the second timestamp.

5. The system of claim 3 , wherein the one or more processors are further configured to:

store the normalized first finding and the normalized second finding as historical updates; and

cause the graphical user interface to display the historical updates upon request.

6. The system of claim 1 , wherein each of the first and second identifier includes at least one of: name, category, or a severity of a finding.

7. The system of claim 1 , wherein the first finding and the second finding are in a vendor-provided format.

8. A system for performing de-duplication of findings, comprising:

one or more processors;

a graphical user interface configured for display and operably connected to the one or more processors; and

a memory in communication with the one or more processors and storing instructions that, when executed by the one or more processors, are configured to:

receive, from a first software security analysis tool, a first finding comprising one or more software issues, the first software security analysis tool comprising a Static Application Security Testing (SAST) tool or a Dynamic Application Security Testing (DAST) tool;

determine a first identifier that identifies the first finding;

store the first finding and the first identifier;

receive, from a second software security analysis tool, a second finding comprising one or more software issues, the second software security analysis tool comprising a Static Application Security Testing (SAST) tool or a Dynamic Application Security Testing (DAST) tool;

determine a second identifier that identifies the second finding;

determine that the second identifier at least partially matches the first identifier;

append the first finding to the second finding;

compare the one or more software issues of the first finding to the one or more software issues of the second finding to determine at least a partial match; and

remove the at least partial match from the first finding to create an update first finding;

store the updated first finding;

cause the graphical user interface to display the updated first finding; and

cause the graphical user interface to display the first finding prior to the update.

9. The system of claim 8 , wherein the one or more processors are further configured to normalize the first finding and the second finding to a standardized taxonomy, and wherein

the normalized first finding is associated with a first timestamp, and

the normalized second finding is associated with a second timestamp.

10. The system of claim 9 , wherein the one or more processors are further configured to:

store the normalized first finding and the normalized second finding as historical updates; and

cause the graphical user interface to display the historical updates upon request.

11. The system of claim 8 , wherein

the first software security analysis tool is a standalone solution, a network-based client-server solution, a web-based solution, or a cloud-based solution, and

the second software security analysis tool is a standalone solution, a network-based client-server solution, a web-based solution, or a cloud-based solution.

12. The system of claim 8 , wherein each of the first and second identifier includes at least one of: name, category, or a severity of a finding.

13. A system for performing de-duplication of findings, comprising:

one or more processors;

a graphical user interface configured for display and operably connected to the one or more processors; and

a memory in communication with the one or more processors and storing instructions that, when executed by the one or more processors, are configured to:

receive, from a first software security analysis tool comprising a Static Application Security Testing (SAST) tool or a Dynamic Application Security Testing (DAST) tool, a first finding, wherein the first finding includes one or more respective software issues and a first identifier;

store the first finding and the first identifier;

receive, from a second software security analysis tool comprising a Static Application Security Testing (SAST) tool or a Dynamic Application Security Testing (DAST) tool, a second finding, wherein the second finding includes one or more respective software issues and a second identifier;

determine that the second identifier at least partially matches the first identifier;

generate a third finding by combining the first finding with the second finding;

compare the one or more software issues of the first finding to the one or more software issues of the second finding to determine at least a partial match;

remove the at least partial match from the third finding;

store the third finding;

cause the graphical user interface to display the third finding; and

cause the graphical user interface to display the first finding.

14. The system of claim 13 , wherein the one or more processors is further configured to normalize the first finding and the second finding to a standardized taxonomy, and wherein

the normalized first finding is associated with a first timestamp, and

the normalized second finding is associated with a second timestamp.

15. The system of claim 14 , wherein the one or more processors are further configured to:

store the normalized first finding and the normalized second finding as historical updates; and

cause the graphical user interface to display the historical updates upon request.

16. The system of claim 13 , wherein

the first software security analysis tool is a standalone solution, a network-based client-server solution, a web-based solution, or a cloud-based solution, and

the second software security analysis tool is a standalone solution, a network-based client-server solution, a web-based solution, or a cloud-based solution.

17. The system of claim 13 , wherein each of the first and second identifier includes at least one of: name, category, or a severity of a finding.

18. The system of claim 13 , wherein

the first software security analysis tool is a standalone solution, a network-based client-server solution, a web-based solution, or a cloud-based solution, and

the second software security analysis tool is a standalone solution, a network-based client-server solution, a web-based solution, or a cloud-based solution.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Jul 8, 2019
From: YOUNGBERG, ADAM; KENT, STEPHEN
To: CAPITAL ONE SERVICES, LLC
Reel/Frame 049682/0936 →
Continuity (2)
Continuation 16177299 · Oct 31, 2018
Related Publication 20200134193A1 · Apr 30, 2020
Cited By (1)
US 12,659,337