Invention Grant
- Patent Title: Security assessment incentive method for promoting discovery of computer software vulnerabilities
-
Application No.: US15231588Application Date: 2016-08-08
-
Publication No.: US09697362B2Publication Date: 2017-07-04
- Inventor: Jay Kaplan , Mark Kuhr
- Applicant: SYNACK, INC.
- Applicant Address: US CA Redwood City
- Assignee: Synack, Inc.
- Current Assignee: Synack, Inc.
- Current Assignee Address: US CA Redwood City
- Agency: Hickman Palermo Becker Bingham LLP
- Main IPC: G06F11/00
- IPC: G06F11/00 ; G06F12/14 ; G06F12/16 ; G08B23/00 ; G06F21/57 ; H04L29/06 ; G06Q30/02 ; G06F11/07 ; G06F11/273

Abstract:
In one aspect, the disclosure provides: A method comprising: assessing a plurality of researchers as a precondition for receiving an invitation to be a researcher of a distributed plurality of researchers, resulting in the distributed plurality of researchers wherein each researcher is associated with one or more tags in records that identify the researcher for one or more attributes; inviting a subset of the distributed plurality of researchers to participate in one or more computer vulnerability research projects directed to identifying computer vulnerabilities of one or more computers that are owned or operated by a third party, the subset of the distributed plurality of researchers selected based on the one or more tags in records that identify the researcher and a description of the computer vulnerabilities of the one or more computers; using a computer that is communicatively coupled to a particular researcher among the subset of the distributed plurality of researchers and a network under test among the one or more computers, monitoring communications between the particular researcher and the particular third party computer, wherein the communications relate to attempting to identify a candidate security vulnerability of the particular third party computer; in response to a report of the candidate security vulnerability of the particular third party computer that is received from the particular researcher, evaluating the report of the candidate security vulnerability.
Public/Granted literature
- US20160342796A1 SECURITY ASSESSMENT INCENTIVE METHOD FOR PROMOTING DISCOVERY OF COMPUTER SOFTWARE VULNERABILITIES Public/Granted day:2016-11-24
Information query