IP Library › Granted Patent US 11,509,677
Granted Patent B2
US 11,509,677 · App. 16/867,153 · Granted Nov 22, 2022

Automatically detecting vulnerability remediations and regressions

Inventors: Aastha Yadav (Seattle, WA); Martin Hristov Georgiev (Seattle, WA)
Assignee: Uber Technologies, Inc.
H04L63/1433
View Patent ↗
Loading inventors, assignments & file history…
Monitor This Case
Get email alerts when status or documents change.
Order Certified Copies
Most orders are placed with the USPTO same day — all within 24 business hours.
Order via The Patent Place →
Pre-filled with this patent's details
Quick Facts
Patent No.
US 11,509,677
App. No.
16/867,153
Granted
Nov 22, 2022
Kind
B2
Abstract

A mechanism is described herein for automatically detecting vulnerability remediations and regressions. A system may receive data indicating that a security alert exists for a specific vulnerability. The system retrieves parameters from the alert and generates (or retrieves) a script or a set of scripts for detecting the vulnerability based on those parameters. The script is executed to determine whether the vulnerability has been remediated or has regressed post remediation. If the system determined that the vulnerability has been remediated, it transmits a request to resolve the security alert. The script is then continually or periodically executed. If the system, through executing the script, determines that the vulnerability has been reintroduced into the environment (e.g., via a code upgrade or a parameter update), it reopens the existing alert indicating that the vulnerability has been reintroduced into the environment.

Claims (55)

1. A computer-implemented method for automatically detecting vulnerability remediations and reintroductions, the method comprising:

detecting a vulnerability remediation by:

receiving, by at least one processor, a security alert for one or more electronic systems, wherein the security alert includes one or more vulnerability detection parameters, wherein the security alert includes an identifier of a vulnerability in the one or more vulnerability detection parameters;

determining, using the vulnerability detection parameters, a script for detecting the vulnerability associated with the security alert;

executing the script for detecting the vulnerability; and

determining, based on output from the script, that the vulnerability has been remediated;

responsive to determining that the vulnerability has been remediated, transmitting, to a vulnerability tracking system, a first request to resolve the security alert, wherein the first request includes an identifier of the security alert;

detecting a reintroduction of the remediated vulnerability by:

periodically executing the script for detecting the vulnerability;

determining, based on an output of the periodically executed script, that the vulnerability has been reintroduced; and

responsive to determining that the vulnerability has been reintroduced, transmitting, to the vulnerability tracking system, a second request to reactivate the security alert, wherein the second request includes the identifier of the vulnerability.

2. The computer-implemented method of claim 1 , wherein the security alert includes the identifier of the security alert, and wherein the second request includes the identifier of the security alert.

3. The computer-implemented method of claim 1 , wherein receiving the security alert comprises receiving a data structure that includes a plurality of fields for a plurality of vulnerability detection parameters, and wherein the plurality of vulnerability detection parameters includes a vulnerability-specific query and a vulnerability type.

4. The computer-implemented method of claim 3 , wherein determining the script for detecting the vulnerability associated with the security alert comprises selecting a script template based on the vulnerability type and adding the vulnerability-specific query into the script.

5. The computer-implemented method of claim 1 , further comprising:

determining a severity level associated with the vulnerability; and

generating a schedule for execution of the script for detecting the vulnerability based on the severity level.

6. The computer-implemented method of claim 1 , wherein receiving the security alert for one or more electronic systems comprises receiving the security alert from the vulnerability tracking system.

7. A non-transitory computer-readable medium comprising memory with instructions encoded thereon for automatically detecting vulnerability remediations and reintroductions, the instructions causing one or more processors to perform operations when executed, the instructions comprising instructions to:

detect a vulnerability remediation by:

receiving, by at least one processor, a security alert for one or more electronic systems, wherein the security alert includes one or more vulnerability detection parameters, wherein the security alert includes an identifier of a vulnerability in the one or more vulnerability detection parameters;

determining, using the vulnerability detection parameters, a script for detecting the vulnerability associated with the security alert;

executing the script for detecting the vulnerability; and

determining, based on output from the script, that the vulnerability has been remediated;

responsive to determining that the vulnerability has been remediated, transmit, to a vulnerability tracking system, a first request to resolve the security alert, wherein the first request includes an identifier of the security alert;

detect a reintroduction of the remediated vulnerability by:

periodically executing the script for detecting the vulnerability;

determining, based on an output of the periodically executed script, that the vulnerability has been reintroduced; and

responsive to determining that the vulnerability has been reintroduced, transmit, to the vulnerability tracking system, a second request to reactivate the security alert, wherein the second request includes the identifier of the vulnerability.

8. The non-transitory computer readable medium of claim 7 , wherein the security alert includes the identifier of the security alert, and wherein the second request includes the identifier of the security alert.

9. The non-transitory computer readable medium of claim 7 , wherein the instructions to receive the security alert comprise instructions to receive a data structure that includes a plurality of fields for a plurality of vulnerability detection parameters, and wherein the plurality of vulnerability detection parameters includes a vulnerability-specific query and a vulnerability type.

10. The non-transitory computer readable medium of claim 9 , wherein the instructions to determine the script for detecting the vulnerability associated with the security alert comprise instructions to select a script template based on the vulnerability type and adding the vulnerability-specific query into the script.

11. The non-transitory computer readable medium of claim 7 , wherein the instructions further comprise instructions to:

determine a severity level associated with the vulnerability; and

generate a schedule for execution of the script for detecting the vulnerability based on the severity level.

12. The non-transitory computer readable medium of claim 7 , wherein the instructions to receive the security alert for one or more electronic systems comprise instructions to receive the security alert from the vulnerability tracking system.

13. A system for automatically detecting vulnerability remediations and reintroductions, the system comprising:

memory with instructions encoded thereon; and

one or more processors that, when executing the instructions, are caused to perform operations comprising:

detecting a vulnerability remediation by:

receiving, by at least one processor, a security alert for one or more electronic systems, wherein the security alert includes one or more vulnerability detection parameters, wherein the security alert includes an identifier of a vulnerability in the one or more vulnerability detection parameters;

determining, using the vulnerability detection parameters, a script for detecting the vulnerability associated with the security alert;

executing the script for detecting the vulnerability; and

determining, based on output from the script, that the vulnerability has been remediated;

responsive to determining that the vulnerability has been remediated, transmitting, to a vulnerability tracking system, a first request to resolve the security alert, wherein the first request includes an identifier of the security alert;

detecting a reintroduction of the remediated vulnerability by:

periodically executing the script for detecting the vulnerability;

determining, based on an output of the periodically executed script, that the vulnerability has been reintroduced; and

responsive to determining that the vulnerability has been reintroduced, transmitting, to the vulnerability tracking system, a second request to reopen the security alert, wherein the second request includes the identifier of the vulnerability.

14. The system of claim 13 , wherein the security alert includes the identifier of the security alert, and wherein the second request includes the identifier of the security alert.

15. The system of claim 13 , wherein the operations to receive the security alert comprise operations to receive a data structure that includes a plurality of fields for a plurality of vulnerability detection parameters, and wherein the plurality of vulnerability detection parameters includes a vulnerability-specific query and a vulnerability type.

16. The system of claim 15 , wherein the operations to determine the script for detecting the vulnerability associated with the security alert comprise operations to select a script template based on the vulnerability type and adding the vulnerability-specific query into the script.

17. The system of claim 13 , where operations further comprise operations to:

determine a severity level associated with the vulnerability; and

generate a schedule for execution of the script for detecting the vulnerability based on the severity level.

Assignments (1)
ASSIGNMENT OF ASSIGNOR'S INTEREST Recorded May 6, 2020
From: YADAV, ASATHA; GEORGIEV, MARTIN HRISTOV
To: UBER TECHNOLOGIES, INC.
Reel/Frame 052591/0995 →
Continuity (1)
Related Publication 20210352096A1 · Nov 11, 2021
Cited By (1)
US 12,483,587