Application (pre-grant publication)
VULNERABILITY AND REMEDIATION VALIDATION AUTOMATION
- Number
- 20250225251
- Published
- 2025-07-10
- Filed
- 2024-01-05
- Assignee
- DISNEY ENTERPRISES, INC.
- Inventors
- AGHAMOHAMMAD; Sherwin et al.
- CPC
- G06F21/577
- Verdict
- Set aside cybersecurity vulnerability tooling, unrelated
- Source
- Google Patents · FreePatentsOnline
Abstract
A method of qualifying a vulnerability detection for remediation comprising: obtaining a vulnerability detection from a vulnerability scanner for a target system; determining qualification data qualifying the vulnerability detection, wherein the qualification data is based on a configuration of the target system excluded in the vulnerability detection from the vulnerability scanner; and associating the qualification data with the vulnerability detection.
Background
BACKGROUND Field of the Various Embodiments
Embodiments of the present disclosure relate generally to qualifying vulnerabilities detected by vulnerability scanners for remediation. Description of the Related Art
Over the past decades, the ongoing trend to computerize corporate records and operations has revolutionized business processes. These trends involve digitizing records, implementing integrated software systems, embracing cloud computing, and leveraging data analytics. This shift enhances efficiency, data accessibility, and decision-making, fostering adaptability in the ever-evolving digital landscape. However, this trend to digitize corporate records and operations has given rise to malicious actors who seek to exploit security vulnerabilities in these computer systems to disrupt operations and/or extort organizations for financial gain.
Security vulnerabilities are weaknesses or flaws in computer systems, software, hardware, or procedures that can be exploited by malicious actors to compromise the confidentiality, integrity, or availability of data, systems, or networks. These vulnerabilities can vary in nature and severity, and they pose a significant risk to the security and privacy of information technology assets. While providing an exact number of new software vulnerabilities identified each year is challenging, the number is typically in the thousands. Because of the evolving nature of security vulnerabilities, best practices in security in