Invention Grant
US08099787B2 Knowledge-based and collaborative system for security assessment of web applications
有权
基于知识的协作系统,用于Web应用程序的安全评估
- Patent Title: Knowledge-based and collaborative system for security assessment of web applications
- Patent Title (中): 基于知识的协作系统,用于Web应用程序的安全评估
-
Application No.: US11839080Application Date: 2007-08-15
-
Publication No.: US08099787B2Publication Date: 2012-01-17
- Inventor: Weimin Vasudeva
- Applicant: Weimin Vasudeva
- Applicant Address: US NC Charlotte
- Assignee: Bank of America Corporation
- Current Assignee: Bank of America Corporation
- Current Assignee Address: US NC Charlotte
- Agency: Banner & Witcoff, Ltd.
- Agent Michael A. Springs
- Main IPC: G06F15/18
- IPC: G06F15/18

Abstract:
A standardized system for assessing the security of web based applications which has a component for collecting information regarding threat and vulnerabilities to web applications is described. The system includes a component for organizing the information regarding threat and vulnerabilities to web applications into a uniform language so that the information is integrated throughout the entirety of the system. Further, the system has a component for expressing the information in a structured and uniform format of a hierarchical relationship between threat and vulnerabilities which includes threat vulnerability trees. The system includes a component for rating the threats and vulnerabilities under a uniform rating system. The system includes a component for integrating the information into both a storage component and also a presentation component for presenting the information. The presentation component presents the information in a graphical format which visually demonstrates the relationships between the threats and the vulnerabilities.
Public/Granted literature
- US20090049553A1 Knowledge-Based and Collaborative System for Security Assessment of Web Applications Public/Granted day:2009-02-19
Information query