- 专利标题: SYSTEM AND METHOD FOR EXTRACTING CONFIGURATION-RELATED INFORMATION FOR REASONING ABOUT THE SECURITY AND FUNCTIONALITY OF A COMPOSED INTERNET OF THINGS SYSTEM
-
申请号: US16918966申请日: 2020-07-01
-
公开(公告)号: US20210014263A1公开(公告)日: 2021-01-14
- 发明人: Hamed Soroush , Milad Asgari Mehrabadi , Shantanu Rane , Marc E. Mosko
- 申请人: Palo Alto Research Center Incorporated
- 申请人地址: US CA Palo Alto
- 专利权人: Palo Alto Research Center Incorporated
- 当前专利权人: Palo Alto Research Center Incorporated
- 当前专利权人地址: US CA Palo Alto
- 主分类号: H04L29/06
- IPC分类号: H04L29/06 ; G06N5/04 ; G06F16/25
摘要:
Embodiments provide a system and method for extracting configuration-related information for reasoning about the security and functionality of a composed system. During operation, the system determines, by a computing device, information sources associated with hardware and software components of a system, wherein the information sources include at least specification sheets, standard operating procedures, user manuals, and vulnerability databases. The system selects a set of categories of vulnerabilities in a vulnerability database, and ingests the information sources to obtain data in a normalized format. The system extracts, from the ingested information sources, configuration information, vulnerability information, dependency information, and functionality requirements to create a model for the system. The system displays, on a screen of a user device, one or more interactive elements which allow the user to view or select the information sources and the categories of vulnerabilities, initiate ingesting the information sources, and view the extracted configuration information.
公开/授权文献
信息查询