Invention Grant
- Patent Title: Open source vulnerability remediation tool
-
Application No.: US16228538Application Date: 2018-12-20
-
Publication No.: US11308218B2Publication Date: 2022-04-19
- Inventor: Vinjith Nagaraja , Raymond Brammer , James Myers , Christopher Gutierrez , Ireneusz Pazdzierniak , Shanshan Jiang , Karim Mawani , Pankaj Rathore , Jerry Wald , David Worth , Dhruv Vig , Archana Taparia , Robert Chifamba , Vamshi Ramarapu
- Applicant: Visa International Service Association
- Applicant Address: US CA San Francisco
- Assignee: Visa International Service Association
- Current Assignee: Visa International Service Association
- Current Assignee Address: US CA San Francisco
- Agency: Kilpatrick Townsend & Stockton LLP
- Main IPC: G06F21/57
- IPC: G06F21/57 ; G06F11/36 ; G06F8/71

Abstract:
A method and system for remediating vulnerable code libraries, including open source libraries, in a software application. An application that uses code libraries and information regarding known library vulnerabilities are received, then it identifies one or more libraries in the application that are vulnerable based upon the information. For each of the one or more vulnerable libraries, a library version that minimizes risk is determined. The determined library version is incorporated into the application to form a test application, and an application test is performed on the test application. If an application test score on the test application is below a predetermined threshold, the determined library version is incorporated into a final application precursor. A final application can be determined from the final application precursor for each of the one or more vulnerable libraries.
Information query