Machine learned model for generating opinionated threat assessments of security vulnerabilities
US-2024411898-A1 · Dec 12, 2024 · US
US9998450B2 · US · B2
| Field | Value |
|---|---|
| Publication number | US-9998450-B2 |
| Application number | US-201514820465-A |
| Country | US |
| Kind code | B2 |
| Filing date | Aug 6, 2015 |
| Priority date | Sep 3, 2013 |
| Publication date | Jun 12, 2018 |
| Grant date | Jun 12, 2018 |
A practical reading order for non-experts. Skip the full description unless you need deep technical detail.
What the patent document calls the invention.
A short plain-language summary of the technical disclosure.
Who owns or filed the patent and who is credited as inventor.
Filing, priority, publication, and grant dates set the timeline.
The legal scope of protection — read this for what is actually claimed.
Technology tags used to group this patent with similar filings.
Prior art links and similar publications in this corpus.
Official abstract text for this publication.
A certification application automatically generates a certification document associated with a service. A transformation module retrieves a component information associated with a status of a service from a data store maintaining the component information. The component security data and component metadata is included within the component information. The component information is transformed for insertion into a certification information. Risk analysis, phraseology, and localization data is used to transform the component information. The certification document is generated based on the certification template by inserting the component information into the certification template.
Opening claim text (preview).
What is claimed is: 1. A system to automatically generate certification documents, the system comprising: a first server configured to execute a service for consumption by a consumer; and a second server coupled to the first server through a communication network, the second server configured to execute a certification application to automatically generate a certification document associated with the service, wherein the certification application is configured to: detect a request from the consumer to receive the certification document; retrieve component information associated with a status of the service from the first server; query at least one of the service at the first server and a risk analysis provider to retrieve risk analysis data; retrieve phraseology data and localization data from at least one of a local resource and a trusted external resource; process the component information with the risk analysis data, the phraseology data, and the localization data to transform the component information for insertion into a certification template; generate a certification document based on the certification template by inserting the transformed component information into the certification template; and the first server further configured to establish a secure communication channel using the certification document. 2. The system of claim 1 , further comprising: a data store configured to store component information associated with the service. 3. The system of claim 2 , wherein the certification application is further configured to: retrieve the component information associated with the status of the service from the data store. 4. The system of claim 2 , wherein the component information is updated at the data store in response to at least one change associated with the component information at the service. 5. The system of claim 4 , wherein the certification application is further configured to: query the service at the first server to retrieve the at least one change associated with the component information based on at least one from a set of: a predetermined schedule, an automatically adjusted schedule, and an event based action; update the component information with the at least one change; and transmit the updated component information to the data store for storage. 6. The system of claim 2 , wherein the certification application is further configured to: compare the component information to the risk analysis data; update the component information with the risk analysis data in response to determining a discrepancy between the risk analysis data and the component information; and transmit the updated component information to the data store. 7. The system of claim 1 , wherein the component information comprises component security data that includes implementation information associated with security rules executed by the service. 8. The system of claim 1 , wherein the component information comprises component metadata that includes at least one from a set of: a name, a description, an input parameter, and an output parameter associated with the service. 9. The system of claim 1 , wherein the certification application is further configured to: select the certification template based on at least one matching attribute between the component information and the certification template. 10. The system of claim 1 , Wherein the certification application is further configured to: transmit the certification document to one of a risk analysis entity and the consumer of the service. 11. The system of claim 1 , wherein the secure communication channel comprises a trusted subscription or an encrypted communication. 12. A server implemented on a computing device to automatically generate certification documents, the server comprising: a memory device configured to store instructions; and one or more hardware processors coupled to the memory device and configured to execute a certification application in conjunction with instructions stored in the memory device, wherein the certification application comprises a transformation module, the transformation module configured to: detect a request from a consumer to receive a certification document associated with a service, wherein the service is executed by another server for consumption by the consumer; retrieve component information associated with a status of the service from at least one of the other server and a data store configured to store the component information; query at least one of the service at the other server and a risk analysis provider to retrieve risk analysis data; retrieve phraseology data and localization data from at least one of a local resource and a trusted external resource; process the component information with the risk analysis data, the phraseology data, and the localization data to transform the component information for insertion into a certification template; generate a certification document based on the certification template by inserting the transformed component information into the certification template; and enable the other server to establish a secure communication channel using the certification document. 13. The server of claim 12 , wherein the transformation module is further configured to: translate the component information to a coherent sentence structure of a language parameter associated with the consumer based on the phraseology data. 14. The server of claim 12 , wherein the transformation module is further configured to: process the component information to a technical detail to match a technical detail setting of the certification template based on the phraseology data. 15. The server of claim 12 , wherein the transformation module is further configured to: translate the component information based on the localization data to match a localization setting of the consumer, wherein the localization setting is determined from at least one of: a location of the consumer and a consumer provided setting. 16. The server of claim 12 , wherein the secure communication channel comprises a trusted subscription or an encrypted communication. 17. A method to automatically generate certification documents, the method comprising: a first server detecting a request from a consumer to receive a certification document associated with a service, wherein the service is executed by a second server for consumption by the consumer; the first server retrieving component information associated with a status of the service from at least one of the second server and a data store configured to store the component information; the first server querying at least one of the service at the second server and a risk analysis provider to retrieve risk analysis data; the first server retrieving phraseology data and localization data from at least one of a local resource and a trusted external resource; the first server processing the component information with the risk analysis data, the phraseology data, and the localization data to transform the component information for insertion into a certification template; the first server generating a certification document based on the certification template by inserting the transformed component information into the certification template; and the first server establishing a secure communication channel using the certification document. 18. The method of claim 17 , further comprising: the first server determining a placement of a content of the component information in the certification document base
Assessing vulnerabilities and evaluating computer system security · CPC title
Templates · CPC title
using certificates (cryptographic mechanisms or cryptographic arrangements for entity authentication involving certificates H04L9/3263) · CPC title
Formatting, i.e. changing of presentation of documents (automatic justification G06F40/189; automatic line break hyphenation G06F40/191) · CPC title
for managing network security; network security policies in general (filtering policies H04L63/0227) · CPC title
Related publications grouped by family.
Answers are generated from the same data shown on this page.