IP Library › Granted Patent US 11,411,982
Granted Patent B2
US 11,411,982 · App. 17/034,636 · Granted Aug 9, 2022

Systems and methods for graphical visualization of web application vulnerabilities

Inventors: Kasirao Velugu (Bangalore, IN); Priya Bagaria (Kolkata, IN); Thirumoorthi Thangamani (Bangalore, IN); Ganesh Kathiresan (Bangalore, IN)
Assignee: Citrix Systems, Inc.
H04L63/1433H04L41/22H04L63/0236H04L63/1416H04L63/20
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,411,982
App. No.
17/034,636
Filed
Sep 28, 2020
Granted
Aug 9, 2022
Kind
B2
Art Unit
2434
USPC
726/22
Abstract

A computer system is provided. The computer system includes a memory and at least one processor coupled to the memory and configured to extract, from a website vulnerability scanner log, a uniform resource locator (URL) and a vulnerability score and vulnerability classification associated with the URL. The at least one processor is further configured to generate an application vulnerability graph comprising connected nodes that are associated with a field of the URL. The nodes are labeled to indicate the associated field of the URL and color coded based on the vulnerability score. The nodes are also associated with the vulnerability classification. The at least one processor is further configured to enable or disable security protection against a user-selected vulnerability classification of a user-selected node by generating web application firewall security rules and/or web application firewall relaxation rules.

Claims (38)

1. A computer system comprising:

a memory; and

at least one processor coupled to the memory and configured to:

extract, from a website vulnerability scanner log file, a uniform resource locator (URL), a vulnerability score associated with the URL, and a vulnerability classification associated with the URL;

generate an application vulnerability graph comprising nodes connected by edges, wherein one or more of the nodes are associated with an application programming interface (API), the API associated with a field of the URL, the nodes are labeled to indicate the associated field of the URL, the nodes are color coded based on the vulnerability score, and the nodes are associated with the vulnerability classification;

filter nodes of the application vulnerability graph based on a match between a user-selected vulnerability classification and the vulnerability classification associated with the nodes; and

enable or disable security protection against the user-selected vulnerability classification of the nodes.

2. The computer system of claim 1 , wherein the vulnerability classification comprises one or more of a Structured Query Language injection vulnerability, a Cross-site Scripting injection vulnerability, a credit card leak vulnerability, and a path traversal vulnerability.

3. The computer system of claim 1 , wherein the at least one processor is further configured to generate web application firewall security rules and/or web application firewall relaxation rules for application to one or more user-selected nodes.

4. The computer system of claim 3 , wherein the web application firewall security rules and the web application firewall relaxation rules are generated as regular expressions based on the URL.

5. The computer system of claim 1 , wherein the at least one processor is further configured to:

generate a first application vulnerability graph based on a first website vulnerability scanner log file provided at a first time;

generate a second application vulnerability graph based on a second website vulnerability scanner log file provided at a second time; and

render a visualization of differences between the first application vulnerability graph and the second application vulnerability graph.

6. A method for graphical visualization of web application vulnerabilities comprising:

extracting, by a computer system, from a website vulnerability scanner log file, a uniform resource locator (URL), a vulnerability score associated with the URL, and a vulnerability classification associated with the URL;

generating, by the computer system, an application vulnerability graph comprising nodes connected by edges, wherein one or more of the nodes are associated with an application programming interface (API), the API associated with a field of the URL, the nodes are labeled to indicate the associated field of the URL, the nodes are color coded based on the vulnerability score, and the nodes are associated with the vulnerability classification;

filtering, by the computer system, nodes of the application vulnerability graph based on a match between a user-selected vulnerability classification and the vulnerability classification associated with the nodes; and

enabling or disabling, by the computer system, security protection against the user-selected vulnerability classification of a user-selected node.

7. The method of claim 6 , wherein the vulnerability classification comprises one or more of a Structured Query Language injection vulnerability, a Cross-site Scripting injection vulnerability, a credit card leak vulnerability, and a path traversal vulnerability.

8. The method of claim 6 , further comprising generating web application firewall security rules and/or web application firewall relaxation rules for application to one or more user-selected nodes.

9. The method of claim 8 , wherein the web application firewall security rules and the web application firewall relaxation rules are generated as regular expressions based on the URL.

10. The method of claim 6 , further comprising:

generating a first application vulnerability graph based on a first website vulnerability scanner log file provided at a first time;

generating a second application vulnerability graph based on a second website vulnerability scanner log file provided at a second time; and

rendering a visualization of differences between the first application vulnerability graph and the second application vulnerability graph.

11. A non-transitory computer readable medium storing executable sequences of instructions to provide graphical visualization of web application vulnerabilities, the sequences of instructions comprising instructions to:

extract, from a website vulnerability scanner log file, a uniform resource locator (URL), a vulnerability score associated with the URL, and a vulnerability classification associated with the URL;

generate an application vulnerability graph comprising nodes connected by edges, wherein one or more of the nodes are associated with an application programming interface (API), the API associated with a field of the URL, the nodes are labeled to indicate the associated field of the URL, the nodes are color coded based on the vulnerability score, and the nodes are associated with the vulnerability classification;

filter nodes of the application vulnerability graph based on a match between a user-selected vulnerability classification and the vulnerability classification associated with the nodes; and

enable or disable security protection against the user-selected vulnerability classification of a user-selected node.

12. The computer readable medium of claim 11 , wherein the vulnerability classification comprises one or more of a Structured Query Language injection vulnerability, a Cross-site Scripting injection vulnerability, a credit card leak vulnerability, and a path traversal vulnerability.

13. The computer readable medium of claim 11 , wherein the sequences of instructions further include instructions to generate web application firewall security rules and/or web application firewall relaxation rules for application to one or more user-selected nodes.

14. The computer readable medium of claim 13 , wherein the web application firewall security rules and the web application firewall relaxation rules are generated as regular expressions based on the URL.

15. The computer readable medium of claim 11 , wherein the sequences of instructions further include instructions to:

generate a first application vulnerability graph based on a first website vulnerability scanner log file provided at a first time;

generate a second application vulnerability graph based on a second website vulnerability scanner log file provided at a second time; and

render a visualization of differences between the first application vulnerability graph and the second application vulnerability graph.

Assignments (9)
PATENT SECURITY AGREEMENT Recorded Aug 15, 2025
From: CLOUD SOFTWARE GROUP, INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 072488/0172 →
SECURITY INTEREST Recorded May 24, 2024
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 067662/0568 →
PATENT SECURITY AGREEMENT Recorded Apr 14, 2023
From: CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.); CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 063340/0164 →
RELEASE AND REASSIGNMENT OF SECURITY INTEREST IN PATENT (REEL/FRAME 062113/0001) Recorded Apr 14, 2023
From: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
To: CITRIX SYSTEMS, INC.; CLOUD SOFTWARE GROUP, INC. (F/K/A TIBCO SOFTWARE INC.)
Reel/Frame 063339/0525 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: BANK OF AMERICA, N.A., AS COLLATERAL AGENT
Reel/Frame 062112/0262 →
PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION, AS NOTES COLLATERAL AGENT
Reel/Frame 062113/0470 →
SECOND LIEN PATENT SECURITY AGREEMENT Recorded Oct 7, 2022
From: TIBCO SOFTWARE INC.; CITRIX SYSTEMS, INC.
To: GOLDMAN SACHS BANK USA, AS COLLATERAL AGENT
Reel/Frame 062113/0001 →
SECURITY INTEREST Recorded Sep 30, 2022
From: CITRIX SYSTEMS, INC.
To: WILMINGTON TRUST, NATIONAL ASSOCIATION
Reel/Frame 062079/0001 →
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded Oct 7, 2020
From: VELUGU, KASIRAO; BAGARIA, PRIYA; THANGAMANI, THIRUMOORTHI; KATHIRESAN, GANESH
To: CITRIX SYSTEMS, INC.
Reel/Frame 054000/0129 →
Continuity (1)
Related Publication 20220103587A1 · Mar 31, 2022