- 专利标题: Managing application security vulnerabilities
-
申请号: US17305057申请日: 2021-06-30
-
公开(公告)号: US11874932B2公开(公告)日: 2024-01-16
- 发明人: Matthew Paul Chapman , Chengxuan Xing , Ashley Donald Harrison , Vlad Balanescu
- 申请人: International Business Machines Corporation
- 申请人地址: US NY Armonk
- 专利权人: International Business Machines Corporation
- 当前专利权人: International Business Machines Corporation
- 当前专利权人地址: US NY Armonk
- 代理商 Stephen R. Yoder; Jared Montanaro
- 主分类号: G06F21/57
- IPC分类号: G06F21/57 ; G06F21/54
摘要:
Approaches presented herein enable a security risk manager embedded in an application to manage security vulnerabilities of the application. More specifically, the application comprises code entities such as components, packages, libraries, or microservices. The entities are modified as part of the application development process to have an enabled state, in which these entities are permitted to run normally when called, and a disabled state, in which these entities do not run when called but instead perform a back-out behavior such as generating an error message. At runtime, the application periodically accesses a security vulnerabilities database to check for security alerts. When a relevant security alert is found, the application changes any code entities that are affected by the security alert to the disabled state pending investigation by an operations team. The application notifies the operations team by sending a notification of the security alert to an external security monitoring tool.
公开/授权文献
- US20230004650A1 MANAGING APPLICATION SECURITY VULNERABILITIES 公开/授权日:2023-01-05
信息查询