METHOD AND SYSTEM FOR IDENTIFYING AN OPTIMIZED SET OF CODE COMMITS TO PERFORM VULNERABILITY REMEDIATION

    公开(公告)号:US20240169069A1

    公开(公告)日:2024-05-23

    申请号:US18157849

    申请日:2023-01-23

    申请人: Wipro Limited

    IPC分类号: G06F21/57

    CPC分类号: G06F21/577 G06F2221/033

    摘要: Embodiments of present disclosure relates to method and remediation system of performing remediation for managing vulnerabilities in application. The remediation system receives data related to source code associated with plurality of vulnerabilities and target code of application from one or more data sources. The remediation system identifies commit-log comprising plurality of code commits by extracting features, code commits and test cases from one or more data sources. The remediation system determines lower bound limit and upper bound limit to identify optimal code commits log from commit-log. Thereafter, the remediation system performs remediation by generating security patches for optimal code commits log. Thus, the present disclosure automatically identifies optimal code commits log for which security patches needs to be generated without any manual intervention.

    ZERO TRUST BASED ACCESS MANAGEMENT OF INFRASTRUCTURE WITHIN ENTERPRISE USING MICRO-SEGMENTATION AND DECENTRALIZED IDENTIFIER NETWORK

    公开(公告)号:US20230198764A1

    公开(公告)日:2023-06-22

    申请号:US17650333

    申请日:2022-02-08

    申请人: Wipro Limited

    IPC分类号: H04L9/32 H04L41/12

    摘要: A system and method for onboarding and managing assets in a decentralized identity network is disclosed. The method may include receiving an authorization proof from a member of a team of an enterprise to access an asset in the decentralized identity network. The method may further include validating the member of the team through a set of validator nodes. The method may further include provisioning the asset on the decentralized identity network. The method may further include onboarding the provisioned asset on the decentralized identity network. The method may further include generating a set of derived credentials of the onboarded asset. The method may further include validating a user access request corresponding to at least one of owners of an application and user to access the asset. The method may further include dynamically validating an employee access request from an employee and the unique asset DID to access the asset.

    SYSTEM AND METHOD FOR MANAGING SECURITY RISK OF INFORMATION TECHNOLOGY SYSTEMS IN AN ENTERPRISE

    公开(公告)号:US20220138327A1

    公开(公告)日:2022-05-05

    申请号:US17142413

    申请日:2021-01-06

    申请人: Wipro Limited

    IPC分类号: G06F21/57 G06F16/245

    摘要: The disclosure relates to system and method for managing security risk of information technology (IT) systems in an enterprise. The method includes determining valid trustware components that need to be evaluated for security risk of an IT system within the enterprise; correlating information associated with each of the valid trustware components in a set of data repositories; generating a mapping list comprising the valid trustware components, test cases corresponding to each of the valid trustware components, and test environments corresponding to each of the valid trustware components based on the correlation; triggering trustware security units for testing the valid trustware components based on the mapping list; and identifying security issues associated with the valid trustware components based on the testing. The trustware security units are arranged in a sequential manner or a parallel manner to align with execution of the test cases corresponding to each of the valid trustware components.