US2021326451A1PendingUtilityA1

Automated security assessment of business-critical systems and applications

Assignee: ONAPSIS S R LPriority: Jul 1, 2010Filed: Jun 30, 2021Published: Oct 21, 2021
Est. expiryJul 1, 2030(~3.9 yrs left)· nominal 20-yr term from priority
G06F 21/577H04L 63/1433G06F 2221/033G06F 16/951
61
PatentIndex Score
0
Cited by
0
References
0
Claims

Abstract

Systems and methods which provide a new application security assessment framework that allows auditing and testing systems to automatically perform security and compliance audits, detect technical security vulnerabilities, and illustrate the associated security risks affecting the business-critical applications.

Claims

exact text as granted — not AI-modified
We claim: 
     
         1 . A method for risk assessment comprising:
 measuring a plurality of parameters on a target system on a cloud server;   storing the measured parameters in a database, receiving data regarding the target system from the cloud server;   comparing the measured parameters with the received data; and   identifying, based on the comparing, a defect as part of the risk assessment.   
     
     
         2 . The method of  claim 1 , wherein the risk assessment is performed on at least one central server different from the cloud server storing the target system. 
     
     
         3 . The method of  claim 1 , wherein the measuring is performed by a measurement input interface including a test input interface for receiving the data. 
     
     
         4 . The method of  claim 3 , wherein the data comprises test data from the test input interface. 
     
     
         5 . The method of  claim 1 , further comprising:
 generating correction instructions for correcting the parameters when the defect is identified.   
     
     
         6 . The method of  claim 1 , wherein the defect comprises a software risk in software of the target system. 
     
     
         7 . The method of  claim 6 , wherein the software of the target system comprises at least one of Customer Relationship Management (CRM), Supplier Relationship Management (SRM), Supply Chain Management (SCM), Product Life-cycle Management (PLM), Human Capital Management (HCM), Integration Platforms, Business Warehouse (BW), Business Intelligence (BI), or enterprise resource planning (ERP). 
     
     
         8 . The method of  claim 7 , wherein the software comprises at least one of SAP software, Oracle software, Microsoft software, Siebel software, JD Edwards software, Salesforce, Workday, or PeopleSoft software. 
     
     
         9 . The method of  claim 6 , wherein the parameters comprise settings or snapshots of a state of the software. 
     
     
         10 . The method of  claim 1 , wherein the comparing and the identifying is performed on a second cloud server different from the cloud server. 
     
     
         11 . The method of  claim 1 , wherein the comparing and the identifying is performed on-premises. 
     
     
         12 . A method for risk assessment comprising:
 identifying at least one target system storing a software system;   determining parameters for the software system of the identified at least one target system;   selecting at least one testing or probing module for the identified at least one target system based on the determined parameters;   receiving, at a cloud server, data from an execution of the selected at least one testing or probing module;   analyzing, at the cloud server, the received data for the risk assessment of the software system for the at least one target system; and   correlating, at the cloud server, the risk assessment of the software system for the at least one target system with a second target system from the at least one target system.   
     
     
         13 . The method of  claim 12 , wherein the correlating at the cloud server comprises comparing parameters from different ones of the target systems. 
     
     
         14 . The method of  claim 12 , wherein the parameters comprise at least one of settings, resources, characteristics, or snapshots of a state of the software system. 
     
     
         15 . The method of  claim 12 , further comprising:
 determining risk for a plurality of target systems.   
     
     
         16 . The method of  claim 12 , further comprising:
 identifying a second target system storing a second software system;   determining second parameters for the second software system of the identified second target system;   selecting at least one testing or probing module for the identified second target system based on the determined second parameters;   receiving, at the cloud server, second data from an execution of the selected at least one testing or probing module for the identified second target system; and   analyzing, at the cloud server, the received second data for the risk assessment of the second software system.   
     
     
         17 . The method of  claim 12 , wherein the software systems comprises at least one of a Customer Relationship Management (CRM), Supplier Relationship Management (SRM), Supply Chain Management (SCM), Product Life-cycle Management (PLM), Human Capital Management (HCM), Integration Platforms, Business Warehouse (BW), Business Intelligence (BI), or enterprise resource planning (ERP). 
     
     
         18 . The method of  claim 12 , wherein the risk assessment further comprises:
 identifying a defect in the software system in the one or more cloud servers, wherein the defect comprises a software risk in the software system of the at least one target system; and   generating correction instructions for correcting the parameters when the defect is identified.   
     
     
         19 . The method of  claim 12 , wherein each of the at least one target system are stored locally and configured to communication over a network with the cloud server. 
     
     
         20 . The method of  claim 12 , wherein each of the at least one target system are stored in at least one additional cloud servers that are each configured to communicate over one or more networks with the cloud server. 
     
     
         21 . A system for automatically determining security vulnerabilities comprising:
 a core engine subsystem for storing data related to the security vulnerabilities and configurations for at least one target computer system running one or more software applications in a network;   a scan engine subsystem in communication with the core engine subsystem, wherein the core engine subsystem and the scan engine subsystem are stored on one or more cloud servers, the scan engine subsystem comprising:
 a system identifier module for discovering and identifying the at least one target computer system and relevant resources of the at least one target computer system; 
 an intelligent dispatch module for launching at least one testing or probing module based on a characteristic of at least one relevant resource discovered and identified by the system identifier module; and 
 at least one testing and probing module for automatically testing the at least one relevant resource and for determining a vulnerability of the at least one relevant resource; 
   wherein the at least one testing and probing module is controlled by the intelligent dispatch module and wherein security configurations for the at least one target computer system are stored in one of the one or more cloud servers and the modules are executed on the data in the one of the cloud servers.   
     
     
         22 . The system of  claim 21 , wherein the system identifier module is further configured for detecting risks for a plurality of the at least one target computer systems over each of the one or more cloud servers. 
     
     
         23 . The system of  claim 21  wherein the system identifier module is further configured for detecting risks for the software applications.

Join the waitlist — get patent alerts

Track US2021326451A1 — get alerts on status changes and closely related new filings.

We store only your email — no account needed. See our privacy policy.