Systems and methods for dynamic vulnerability scoring

The Contextual Vulnerability Prioritization engine addresses the limitations of manual CVSS by dynamically scoring vulnerabilities using machine learning, continuously scanning for updates, and adapting scores to network conditions, enhancing automation and accuracy in vulnerability prioritization.

JP7870358B2Active Publication Date: 2026-06-04SECUREWORKS CORP

Patent Information

Authority / Receiving Office
JP · JP
Patent Type
Patents
Current Assignee / Owner
SECUREWORKS CORP
Filing Date
2022-05-11
Publication Date
2026-06-04

AI Technical Summary

Technical Problem

Existing vulnerability scoring systems, such as the Common Vulnerability Scoring System (CVSS), rely heavily on manual input and expert judgment, requiring significant human intervention and are not fully automated, limiting their ability to dynamically adapt to real-time contextual changes and network conditions.

Method used

A system and method utilizing a Contextual Vulnerability Prioritization (CVP) engine that continuously scans for new or updated vulnerabilities, aggregates contextual and non-contextual features using machine learning models, and dynamically updates a Contextual Prioritization Score (CPS) to prioritize vulnerabilities based on real-time data.

Benefits of technology

Enables automated, dynamic, and context-aware vulnerability scoring that adapts to network conditions, reducing the need for manual intervention and providing real-time, mathematically sound, scalable, and granular prioritization of vulnerabilities.

✦ Generated by Eureka AI based on patent content.

Smart Images

  • Figure 0007870358000001
    Figure 0007870358000001
  • Figure 0007870358000002
    Figure 0007870358000002
  • Figure 0007870358000003
    Figure 0007870358000003
Patent Text Reader

Abstract

The present disclosure provides a system and method for substantially continuous and dynamic vulnerability scoring. According to the present disclosure, the method includes detecting one or more vulnerabilities. The method includes determining a context-prioritized score (CPS) for each of the one or more vulnerabilities based on historical data, where the historical data includes a series of context features corresponding to each of the one or more vulnerabilities. The method may include determining a partial CPS score by an agent in response to the detection of an event. The method may include generating an updated CPS based on the CPS and the new partial CPS when a new partial CPS score is determined, and transmitting the updated CPS to each of one or more computing devices.
Need to check novelty before this filing date? Find Prior Art

Description

Technical Field

[0001] The present disclosure generally relates to scoring security vulnerabilities, and more specifically, to dynamic vulnerability scoring of security system vulnerabilities and the use of dynamic vulnerability scoring for prioritizing vulnerabilities, based on substantially continuous input of context data via one or more agents.

Background Art

[0002] Typically, computer network or system vulnerabilities are compiled or classified based on existing Common Vulnerability Scoring System (CVSS). Using CVSS, vulnerabilities are scored and ranked either by using a "base score" (e.g., by a Common Vulnerability Identifier (CVE) site, e.g., a published score), or by using CVSS modifiers or scoring vectors to supplement the "base score". Supplementing the "base score" may attempt to capture local context through the environmental and temporal aspects of the vulnerability. This approach is a manual operation, mostly performed manually by security experts who are responsible for understanding the local context that drives these vectors. Some automation is utilized in the form of existing severity databases, but still may require manual input and scrutiny by security experts. In addition, some systems and methods may attempt to rank vulnerabilities using a level of exploitability, however, such systems use a database similar to the severity database and still require manual input and / or past records.

[0003] Thus, it can be appreciated that there is a need for systems and methods directed to enabling enhanced dynamic scoring of vulnerabilities. The present disclosure addresses the foregoing and other related and unrelated problems / issues in the art. [Overview of the project] [Means for solving the problem]

[0004] In short, in various aspects, this disclosure relates to a system and method for dynamically scoring vulnerabilities in a computer system or network having multiple information handling devices connected thereto. Such a system and method may utilize a contextual vulnerability prioritization engine (CVP engine). The CVP engine may detect new and / or updated vulnerabilities present on the monitored computer network or security system. The CVP engine may scan various internal and / or external databases for vulnerabilities (e.g., Common Vulnerabilities and Exposures (CVE) sites or internal vulnerability databases), wait for a user or computing device to transmit a vulnerability to the CVP engine, and / or scan other data sources to determine whether new or updated vulnerabilities are found. The CVP engine may scan for such vulnerabilities continuously, substantially continuously, or at predetermined time intervals. Alternatively, or in addition to scanning for new vulnerabilities or changes / updates to existing vulnerabilities, the CVP engine may be configured to wait for new or updated vulnerabilities to be received from various sources (e.g., computing devices, user computing devices, security specialists or experts, and / or agents).

[0005] In response to discovering or detecting a new vulnerability, the CVP engine may utilize historical data (e.g., historical context data and / or any other objective historical data), multiple contextual features related to the vulnerability, and / or multiple non-contextual features related to the vulnerability, in addition to the CVSS score, to generate a Contextual Prioritization Score (CPS). In such embodiments, the historical data may include the CVSS score, other data related to the CVSS score, and / or contextual and / or non-contextual data from one or more sources (e.g., computing devices such as switches, routers, servers, and user devices). The CVP engine may include one or more different agents, each agent which may correspond to a type or set of data related to or identified as related to the vulnerability. For example, each agent may include, or consist of, one or more of a machine learning model or classifier, a statistical model, a probabilistic model, and / or various other models or classifiers. The data received by the CVP engine may be used to generate partial CPS or risk scores, which will be aggregated by each associated corresponding agent to generate / determine CPS that are dynamically updated to generate CPS for any new or updated vulnerabilities.

[0006] Furthermore, the CVP engine may scan for or detect events occurring from one or more computing devices. Such scanning or detection may occur continuously, substantially continuously, or at periodic time intervals. In response to the detection of events or events related to or corresponding to vulnerabilities, the CVP engine may directly or analyze the received data types of a subset or portion of the received data related to the event through one or more agents corresponding to each data type of received data related to the event. Each agent may produce a partial risk score or CPS. The partial CPS may be used to adjust and / or update the previous CPS. The updated CPS may be transmitted to each of the one or more computing devices and used to prioritize known vulnerabilities.

[0007] In one aspect, this disclosure provides a system for dynamically assessing and ranking security vulnerabilities in a network having multiple computing devices linked thereto. The system may include a context vulnerability prioritization engine configured to detect one or more vulnerabilities present on the network. The context vulnerability prioritization engine may be configured to determine a context priority score (CPS) for each detected vulnerability based on the aggregation of multiple partial CPSs generated for each of multiple contextual features and multiple non-contextual features associated with each detected vulnerability. The partial CPS for each of the multiple contextual features may be dynamically calculated by a corresponding or associated agent of multiple agents based on multiple contextual features and multiple non-contextual features associated with the vulnerability. The context vulnerability prioritization engine may scan for occurrences of events associated with each identified / detected vulnerability present on the network or any computing device connected thereto, and may be configured to directly direct data corresponding to detected events associated with the vulnerability to the corresponding agent of multiple agents in response to the detection of occurrences of events associated with an identified / detected vulnerability present on one or more of the multiple computing devices. The context vulnerability prioritization engine may also be configured to determine a new partial CPS for each context feature applicable to the data arising from each detected event, via each corresponding agent that receives data corresponding to the detected event. Based on each new partial CPS, the context vulnerability prioritization engine would be configured to determine an updated CPS representing the current state of the identified / detected vulnerability. The context vulnerability prioritization engine may be configured to transmit the updated CPS to each of multiple computing devices.

[0008] In embodiments, the agent may comprise one or more of a trained classifier, statistical model, or probabilistic model. The trained classifier may be generated through a plurality of other contextual features related to the vulnerability, a plurality of other non-contextual features related to the vulnerability, and one or more of a supervised machine learning algorithm or an unsupervised machine learning algorithm. The plurality of computing devices may include one or more of a switch, access point, server, storage device, or user device.

[0009] In another embodiment, multiple non-contextual features may include historical data of features such as CVSS scores associated with the vulnerability. Multiple contextual features may include one or more of the following: payload analysis, exploitability, detection reliability, threat intelligence, or vulnerability trend. Furthermore, multiple contextual features may include one or more of the following: exposure data, software and services affected by the vulnerability, vulnerability-related behavioral analysis, website content, scan frequency, network attack surface, critical potential, asset detection, or remediation time prediction.

[0010] In some embodiments, the context vulnerability prioritization engine may be further configured to dynamically prioritize multiple vulnerabilities based on one or more dynamically updated CPS for one or more vulnerabilities of a plurality. The partial CPS may be determined for each context feature and may be weighted based on the data type of the data corresponding to the occurrence of the event.

[0011] In another aspect, the disclosure provides a method for dynamically scoring known identified or detected vulnerabilities present on a network having multiple computing devices coupled thereto. The method may include detecting vulnerabilities on one or more computing devices in the network or more via a contextual vulnerability prioritization engine. The method includes determining a contextual priority score (CPS) for each of the one or more known identified or detected vulnerabilities based on historical data via an agent of one or more of the contextual vulnerability prioritization engines, the historical data may include a set of contextual features corresponding to each of the one or more known identified or detected vulnerabilities. The method may also include determining a partial CPS for each of the one or more received contextual features associated with an event in response to the detection of an event related to one or more known identified or detected vulnerabilities on one or more of the computing devices in the network, each partial CPS being dynamically determined by an agent of one or more of the contextual vulnerability prioritization engines based on data related to the known identified or detected vulnerability and associated contextual entities related to the vulnerability. The method may also include generating an updated CPS regarding the vulnerability based on the CPS and the new partial CPS, if the new partial CPS is determined with respect to at least one received contextual feature (e.g., a change in the partial CPS score due to a change in such a contextual feature), and transmitting the updated CPS to each of one or more computing devices.

[0012] In some embodiments, the detection of each event may include vulnerability detection based on one or more of the following: network mapping, vulnerability scanning, web application scanning, external sources, or threat intelligence. The detection of one or more occurrences of one or more events related to one or more known identified or detected vulnerabilities on one or more computing devices may occur sequentially, substantially sequentially, or at periodic time intervals. Multiple partial scores may be determined in parallel based on the detection of one or more occurrences of one or more events related to one or more known identified or detected vulnerabilities. Each of the multiple partial scores may be weighted based on a data type or event type corresponding to an additional one or more occurrences of one or more events related to one or more known identified or detected vulnerabilities. The updated CPS may replace the current CPS.

[0013] In another aspect, this disclosure provides a non-transient, machine-readable storage medium for storing processor-executable instructions. The instructions, when executed by at least one processor, may cause at least one processor to detect one or more vulnerabilities in a plurality of computing devices. The instructions, when executed by at least one processor, may cause at least one processor to determine a context prioritization score (CPS) for each of the one or more vulnerabilities based on historical data corresponding to each of the one or more vulnerabilities, via one or more algorithms. The historical data may include one or more contextual features, CVSS scores, and / or other historical data. The instructions, when executed by at least one processor, may cause at least one processor to detect the occurrence of one or more events associated with one of the one or more vulnerabilities on a plurality of computing devices. The instructions, when executed by at least one processor, may cause at least one processor to receive one or more contextual features corresponding to the detection of the occurrence of one or more events associated with one of the one or more vulnerabilities on a plurality of computing devices. When the instruction is executed by at least one processor, it may cause at least one processor to determine a corresponding partial CPS via at least one of one or more agents corresponding to one data type of one or more contextual features related to the detection of the occurrence of one or more events associated with one or more vulnerabilities on one or more computing devices. When the instruction is executed by at least one processor, it may cause at least one processor to generate an updated CPS based on the CPS and the corresponding partial CPS. When the instruction is executed by at least one processor, it may further cause at least one processor to transmit the updated CPS to the computing devices.

[0014] In one embodiment, multiple partial CPSs may be determined in parallel or substantially in parallel. Each of one or more vulnerabilities may be prioritized based on one of the CPSs corresponding to each of one or more vulnerabilities, or one of the updated CPSs if determined.

[0015] When the various objects, features, and advantages of the present disclosure are considered in conjunction with the accompanying drawings, they will become apparent to those skilled in the art upon examination of the following detailed description. This specification also provides, for example, the following: (Item 1) A system for dynamically assessing and ranking the security vulnerabilities of a network in which multiple computing devices are linked, wherein the system comprises: Contextual vulnerability prioritization engine The context vulnerability prioritization engine is equipped with, Detecting vulnerabilities and <舍 Determining a context prioritization score (CPS) for the vulnerability based on the aggregation of multiple partial CPSs generated for each of multiple contextual features related to the vulnerability and one or more non-contextual features related to the vulnerability, Scanning for the occurrence of events related to the aforementioned vulnerability, In response to the detection of events related to the vulnerability by the plurality of computing devices, data corresponding to the detected events related to the vulnerability is directly sent to the corresponding agents of the plurality of agents, Each of the multiple partial CPSs of each of the multiple context features is dynamically calculated by the corresponding agent of the multiple agents based on the data associated with the corresponding agent collected from the multiple context features related to the vulnerability and the detected event, Through each corresponding agent that receives the data corresponding to the detected event, a new partial CPS is determined for each contextual feature applicable to the data corresponding to the occurrence of the event. Based on the aforementioned new partial CPS, determine an updated CPS that represents the current state of the vulnerability, [[ID=3)] The updated CPS is transmitted to each of the plurality of computing devices. A system configured to perform the following actions. U (Item 2) The system described in item 1 comprises, among other things, a trained classifier, a statistical model, or a probabilistic model. (Item 3) The trained classifier is generated through a plurality of additional contextual features related to the vulnerability, a plurality of additional non-contextual features related to the vulnerability, and one or more supervised or unsupervised machine learning algorithms, as described in Item 2. (Item 4) The system described in item 1 includes, among other things, switches, access points, servers, storage devices, or user devices, or more than one of them. (Item 5) The aforementioned one or more non-contextual features include the CVSS score associated with the vulnerability, as described in Item 1 of the system. (Item 6) The system described in Item 1 includes, or surpasses, one of the following contextual features: payload analysis, exploitability, detection reliability, threat intelligence, or vulnerability tendencies. (Item 7) The aforementioned multiple contextual features include, but are not limited to, one or more of the following: exposure data, software and services affected by the vulnerability, vulnerability-related behavioral analysis, website content, scanning frequency, network attack surface, critical potential, prominent asset detection, or remediation time, as described in Item 6. (Item 8) The system described in Item 1 comprises, for example, data corresponding to the detected event, including one or more of the following: exposure data, software and services affected by the vulnerability, vulnerability-related behavioral analysis, website content, scanning frequency, network attack surface, critical potential, prominent asset detection, or remediation time. (Item 9) The context vulnerability prioritization engine is further configured to dynamically prioritize the multiple vulnerabilities based on one or more dynamically updated CPSs relating to one or more vulnerabilities of the multiple vulnerabilities, as described in Item 1. (Item 10) The partial CPS determined for each contextual feature is weighted based on the data type of the data corresponding to the occurrence of the event, as described in item 1. (Item 11) A method for dynamically scoring network vulnerabilities, wherein the method is Detecting vulnerabilities in one or more computing devices of the network via a contextual vulnerability prioritization engine, Determining a context priority score (CPS) for each of the one or more vulnerabilities based on historical data via one or more agents of the context vulnerability prioritization engine, wherein the historical data includes a set of contextual features corresponding to each of the one or more vulnerabilities, In response to the detection of an event related to one of the vulnerabilities in one or more computing devices of the aforementioned network, Determining a partial CPS for each of the one or more received contextual features associated with the event, wherein each partial CPS is dynamically determined by an agent of one or more agents of the contextual vulnerability prioritization engine based on the data associated with the vulnerability and the associated contextual entities associated with the vulnerability, and each agent of the one or more agents is associated with one of the data types of the one or more received contextual features, If a new partial CPS is determined with respect to at least one received contextual feature, Based on the aforementioned CPS and the new partial CPS, an updated CPS relating to the vulnerability is generated, Transmitting the updated CPS to each of the one or more computing devices via the context vulnerability prioritization engine. Methods that include... (Item 12) The aforementioned event is a method of item 11, including vulnerability detection based on one or more of the following: network mapping, vulnerability scanning, web application scanning, external sources, or threat intelligence. (Item 13) The method of item 11, wherein the occurrence of one or more additional events related to one or more of the vulnerabilities on one or more of the aforementioned computing devices occurs continuously, substantially continuously, or in periodic time intervals. (Item 14) The method according to item 11, wherein multiple partial CPSs are determined in parallel based on the detection of the additional occurrence of one or more events associated with one of the one or more vulnerabilities. (Item 15) The method according to item 14, wherein each of the multiple partial CPSs is weighted based on a data type or event type corresponding to the additional occurrence of one or more events associated with one of the one or more vulnerabilities. (Item 16) The aforementioned historical data includes the CVSS score, as described in item 11. (Item 17) A non-transient machine-readable storage medium, the non-transient machine-readable storage medium storing processor-executable instructions, and when the processor-executable instructions are executed by at least one processor, the at least one processor is provided with Detecting vulnerabilities in one or more computing devices, Determining a context prioritization score (CPS) for each of the one or more vulnerabilities based on historical data corresponding to each of the one or more vulnerabilities via one or more agents, wherein the historical data includes one or more contextual features, Detecting the occurrence of one or more events related to one or more of the vulnerabilities on the plurality of computing devices, Receiving one or more contextual features corresponding to the detection of the occurrence of one or more events related to one of the one or more vulnerabilities on the plurality of computing devices, Determining a corresponding partial CPS via at least one of the one or more agents corresponding to one data type of the one or more contextual features corresponding to the detection of the occurrence of one or more events related to one of the one or more vulnerabilities on the plurality of computing devices, Based on the aforementioned CPS and the corresponding partial CPS, an updated CPS is generated. The updated CPS is transmitted to the plurality of computing devices. A non-transient machine-readable memory medium that enables the following. (Item 18) A non-transient machine-readable storage medium as described in item 17, wherein multiple partial CPSs are determined in parallel or substantially in parallel. (Item 19) Each of the aforementioned one or more vulnerabilities is prioritized based on one of the CPS corresponding to each of the aforementioned one or more vulnerabilities, or an updated CPS if determined, in the non-transient machine-readable storage medium described in item 17. (Item 20) A non-transient machine-readable storage medium according to item 17, wherein, in response to a determination of the CPS for each of the one or more vulnerabilities based on historical data corresponding to each of the one or more vulnerabilities, the instruction, when executed by the at least one processor, causes the at least one processor to transmit the CPS corresponding to each of the one or more vulnerabilities to the plurality of computing devices. [Brief explanation of the drawing]

[0016] For the sake of simplification and clarity of the illustrations, please understand that the elements shown in the figures are not necessarily drawn to scale. For example, the dimensions of some elements may be exaggerated relative to others. Embodiments incorporating the teachings of this disclosure are shown and described with reference to the drawings of this specification.

[0017] [Figure 1] Figure 1 is a schematic diagram of a data center, including a networked information handling system, representing one aspect of this disclosure.

[0018] [Figure 2A] Figures 2A and 2B are schematic diagrams of a system for dynamically scoring vulnerabilities, representing one aspect of this disclosure. [Figure 2B] Figures 2A and 2B are schematic diagrams of a system for dynamically scoring vulnerabilities, representing one aspect of this disclosure.

[0019] [Figure 3] Figure 3 is a schematic diagram of a system for dynamically scoring vulnerabilities, representing one aspect of this disclosure.

[0020] [Figure 4] Figure 4 shows an example of a method / process for dynamic vulnerability scoring according to one aspect of this disclosure.

[0021] [Figure 5] Figures 5 and 6 illustrate a method / process for dynamic vulnerability scoring, according to the aspects of this disclosure. [Figure 6] Figures 5 and 6 illustrate a method / process for dynamic vulnerability scoring, according to the aspects of this disclosure.

[0022] [Figure 7]Figure 7 is a schematic diagram of an information handling system capable of performing each of the specific embodiments according to one aspect of this disclosure.

[0023] The use of the same reference symbol in different drawings indicates similar or identical items. [Modes for carrying out the invention]

[0024] Detailed explanation The following description, combined with the figures, is provided to assist in understanding the teachings disclosed herein. The description focuses on specific implementations and embodiments of these teachings and is provided to assist in describing them. This focus should not be construed as a limitation on the scope or applicability of these teachings.

[0025] As shown in Figure 1-7, this disclosure includes a system and method for dynamically scoring security vulnerabilities that are known, identified, or detected to be present on a computer system or network having multiple computing devices or information management devices connected thereto. Examples include a variety of known vulnerabilities related to various software or hardware configurations and / or applications, such as Common Vulnerabilities and Exposures (CVEs), which may be available in various databases and have known CVSS examples. The system may include a Contextual Vulnerability Prioritization (CVP) engine capable of detecting or scanning for new or updated vulnerabilities that may pose a threat to a particular computing device and / or various aspects of a computing device. The CVP engine may detect or scan for one or more different computing devices, networks, cloud computing networks or systems, containers or organized sets of containers, and / or virtual computing devices. Alternatively, or in addition to detecting or scanning for new events, the CVP engine may also be informed of new or updated vulnerabilities from, for example, an external source, and / or wait until a new event is received, for example, through a computing device or user (e.g., through a user interface). Different vulnerabilities pose different levels of risk depending on the exposed asset and / or the affected computing device. Therefore, the CVP engine may determine a Context Prioritization Score (CPS) after detecting new or updated vulnerabilities, including various types of data (e.g., historical data, contextual features, or data).

[0026] To determine the CPS, the CVP engine may utilize data received from external sources (e.g., external databases, the National Vulnerability Database (NVD), Bugtraq, etc., outside the system) or internal sources (e.g., security specialists, internal databases, or repositories, etc., inside the system). The CVP engine may utilize contextual features or data contained within the received data to generate or determine the CPS. Furthermore, each type of received data may be used to generate part or partial CPS through a corresponding agent. The agent may include, or may be, other algorithms and / or models configured to determine or generate part or partial CPS based on a trained machine learning algorithm or classifier, a probabilistic model, a statistical model, or the type of received data. Furthermore, each partial CPS may be weighted based on the data type. In other words, different data types may be determined to be more or less relevant to the overall CPS than other data types.

[0027] After a CPS occurs or is determined, the CVP engine may transmit the CPS and other relevant data indicating the vulnerability to connected computing devices. The computing devices may then execute various instructions at various times to generate the event. The CVP engine may scan each of the computing devices for new events related to known identifications or discovered vulnerabilities. If an event is detected, the CVP engine may retrieve data related to the event, utilize the data, and generate a part or partial CPS of the new CPS through one or more corresponding agents (e.g., a data type of data indicating one or more of the one or more agents to utilize).

[0028] Once a partial CPS occurs or is determined, the CVP engine may incorporate the partial CPS into previous CPS for the corresponding vulnerability. Events and additional partial CPS occurrences may occur multiple times over a selected or continuous period. For example, when a new event is detected, such event may be utilized in the System and Methods for a duration over which the corresponding vulnerability affects computing devices. In other words, once a solution is determined to resolve, correct, neutralize, or otherwise prevent or minimize the effects of a vulnerability present on the System, events arising in connection with such event may be stopped. The number of times such partial CPS may be determined, updated, and / or occur is not necessarily limited and can occur each time an event is detected. Thus, the CPS for each known vulnerability is dynamically updated or calculated substantially continuously or periodically over a given period. Furthermore, since contextual data is used to update the CPS, each vulnerability may be sorted based on its actual impact on an organization or other entity. In other words, each vulnerability may be prioritized based on its impact.

[0029] A new CPS for each vulnerability present in a computer system or network or one or more connected computing devices may be updated or generated in real time. Furthermore, new CPSs may be generated automatically, without human or user interaction. Moreover, the generation of new CPSs is repeatable, mathematically sound, scalable (e.g., multiple new CPSs may be determined for multiple different vulnerabilities based on multiple received context data), fault-tolerant, explainable, and granular. Finally, each new CPS takes into account the different potential risks and impacts brought about by each different context data.

[0030] Figure 1 shows a block diagram of an exemplary data center 10 in which vulnerability scoring for new and updated vulnerabilities, in particular a contextual prioritization score (CPS), is generated and updated based on continuously, substantially continuously, or periodically received event data, which includes at least one contextual feature or data related to the corresponding vulnerability. As shown in Figure 1, the data center 10 may include a computer system or network 12 that can provide communication between multiple information handling systems 14 or computing devices, which may include workstations, personal computers, smart cellular phones, personal digital assistants, laptop computers, servers, computing devices, virtual computing devices, containers or containerized devices, cloud computing-based systems or devices, other suitable devices, and / or combinations thereof. The information handling systems 14 may further be connected to the network 12 through wired connections 16, wireless connections 18, or any other suitable communication or connection lines.

[0031] As further shown in Figure 1, one or more of the data center 10 and / or its information handling systems 14 can be communicably coupled to a network, including a cloud-based or other network, as shown in Figure 12 or 20, by, for example, a wired connection 16 or any other suitable connection such as a wireless connection 18 (e.g., Wi-Fi, cellular, etc.). The network 12 can further be accessible by / by one or more user or client management information handling systems or devices 22 and can facilitate communication between the client management information handling systems 22 and the data center 10, where system logs may be parsed and / or parsing scripts and / or rules may be generated by the event management center. The network 12 may include an API interface for the event management center, but the network can include any suitable network, such as the Internet or other wide area networks, local area networks, or a combination of networks, and can provide communication between the event management center and the client management information handling systems 22, e.g., data communication.

[0032] The client management information handling system 22 is connected to the network 20 via a wired connection, such as an Ethernet® cable or other suitable wired or wireless connection 18, such as WiFi, Bluetooth®, cellular connection (e.g., 3G, 4G, LTE, 5G, etc.), other suitable wireless connection, or a combination thereof (Figure 1), enabling clients or operators of the information handling system 22 to communicate with the event management center and access, for example, one or more services provided thereby. For example, the event management center may be or include a web service.

[0033] For the purposes of this disclosure, the information handling system 14 / 22 may include any computing device means or set of means capable of operating to compute, calculate, determine, classify, process, transmit, receive, read, transmit, switch, store, display, communicate, reveal, detect, record, copy, handle, or utilize any form of information, confidential information, or data for business, scientific, control, or other purposes. In one embodiment, the information handling system may include one or more processing resources such as random access memory (RAM) or (ROM), a central processing unit (CPU) or hardware or software control logic, storage devices such as ROM and / or other types of non-volatile memory. Additional components of the information handling system may include one or more disk drives, one or more network ports for communicating with external devices, and various input and output (I / O) devices such as a keyboard, mouse, touchscreen, and / or video display. The information handling system may also include one or more buses capable of transmitting communications between various hardware components.

[0034] Figures 2A and 2B are schematic diagrams of a system for dynamically scoring vulnerabilities, representing one aspect of the present disclosure. Turning to Figure 2A first, a system 200 for generating scores and dynamically updating scores in relation to new and updated vulnerabilities is illustrated. Such a system 200 may include a Vulnerability and Detect / Response (CVP) system 202. The CVP system 202 may be connected via a communication network 206 to one or more computing devices (e.g., computing device 208A, computing device 208B, and computing device 208N). The CVP system 202 may also be connected to a storage device 204.

[0035] The CVP system 202 may include a CVP engine 210. The CVP engine 210 may consist of software, firmware, hardware (e.g., a network, integrated circuits, etc.), or a combination thereof. The CVP engine 210 may further consist of, or include, instructions or programming that, when executed, cause the CVP engine 210 to perform different functions. For example, instructions, when executed, may cause the CVP engine 210 or processor to scan for vulnerabilities present on the network and for the occurrence of events associated with such vulnerabilities. The scan may include transmitting messages to each computing device 208A, 208B, 208N via the communication network 206 to cause each computing device 208A, 208B, 208N to determine whether a vulnerability has been found or added. For example, the scan may include scanning or reading specific storage devices or ports of each computing device 208A, 208B, 208N to determine whether vulnerabilities have been found and / or added to specified locations (e.g., storage devices or ports associated with computing devices 208A, 208B, 208N). For example, the CVP engine 210 may scan computing devices or other devices to determine whether a computing device or other device contains or has installed outdated software and / or applications, has misconfigured software and / or applications, and / or whether a computing device or other device could become vulnerable based on certain data points or features / factors. In some embodiments, such a scan may include an internal scan by programming configured to explore individual connected devices. In another embodiment, instructions, when executed, may cause the CVP engine 210 to detect vulnerabilities in a similar manner.

[0036] In other embodiments, the CVP system 202 may include a user interface, or the CVP system 202 may be connected to a user interface. The user interface may be configured to allow a user to input data to be transmitted to the CVP system 202 or the storage device 204. Such user access and exploration can also be used, in embodiments, to generate triggers that help prioritize vulnerabilities, for example, regarding which assets / events may be more important in terms of resource allocation. For example, a user such as a security agent or expert may input vulnerabilities and related data into the CVP system 202 via the user interface. Such related data input into the CVP system 202 (e.g., how assets are tagged or categorized) may be used to determine the CPS and / or partial CPS. In the embodiment, the CVP system 202 may detect or discover new or updated vulnerabilities (and related data such as CVSS scores and definition information) from external sources (e.g., external databases, the National Vulnerability Database (NVD), Bugtraq, etc., outside of system 200 or CVP system 202) or internal sources (e.g., security specialists, internal databases, or repositories, etc., inside system 200).

[0037] The CVP engine 210 may further include instructions that, when executed, cause the CVP engine 210 to score any new or updated vulnerabilities that have been discovered, detected, received, or entered. In one embodiment, when a vulnerability is discovered, detected, received, or entered, the vulnerability may include data corresponding to the vulnerability. Such data may include contextual features or data corresponding to one or more computing devices 208A, 208B, 208N, and / or other data (e.g., CVSS and other relevant data from NVD and / or other security data repositories, or contextual features or data from internal sources). The CVP engine 210 may include one or more agents. Each of the one or more agents may correspond to one or more data types of the data corresponding to the vulnerability. Each of the one or more agents may utilize such corresponding data to generate a partial CPS.

[0038] A partial CPS may be weighted by one or more agents or other instructions or algorithms based on the data type corresponding to the partial CPS. The partial CPS may then be combined or incorporated in other ways to generate a whole CPS for the corresponding or associated vulnerability. For example, a partial CPS may be generated as risk, number, and / or other indicators. The risk, number, and / or other indicators may be applied to the previous CPS (e.g., by multiplication or through other formulas, decisions, or calculations) to produce a new CPS. The new CPS may then replace the previous CPS for a particular vulnerability.

[0039] For example, the CPS may be calculated or determined recursively. In such embodiments, the CVP engine 210 may use the CVSS as the basis for initially generating or determining the CPS, and each generated or determined partial CPS may be successively applied to the current CPS.

[0040] In one embodiment, each partial CPS (e.g., a component or part of the final CPS) may be considered a factor in a formula for determining the CPS. Such a formula may be defined in a particular way. For example, the CVP engine 210 may multiply the current CPS (e.g., first, the base score or CVSS) by each partial CPS to determine or generate a new CPS. In other embodiments, a weighted sum of partial CPS may also be utilized, and the weight values ​​may be determined by their respective “importance” or emphasis placed on each agent. These weights may also be learned using, for example, machine learning techniques.

[0041] In another embodiment, the final CPS may be determined or calculated by sequentially multiplying the factors with renormalization to maintain a fixed scoring interval, regardless of the number of factors. The factor multiplication may allow for constructivity, while the renormalization is performed across all vulnerabilities at each assessment step (e.g., determining and incorporating partial CPS). Such nonlinearity may allow for consistency at each step (e.g., a fixed scale) and may allow all vulnerabilities to influence each other. In practice, such a process may lower the scores of lower-risk or less "important" vulnerabilities and raise the scores of higher-risk or more "important" vulnerabilities.

[0042] The initial steps in forming the base CVSS score can be considered uninformative prior distributions and / or context-free risk measures. The uncertainty around the base score as a priority risk score can be high. In other words, the true risk can be higher or lower depending on the context relating to the various aspects of the vulnerability. The successive aggregation of each assessment can reduce the "ambiguity" or uncertainty around the true risk. Such a process can converge, or cause, the final CPS towards a much narrower band of uncertainty.

[0043] The term “Common Vulnerability Scoring System” (CVSS) is used to refer to a freely available industry standard that identifies vulnerabilities by a score of 0 to 10 and other individual metrics used to assess the severity of security vulnerabilities. CVSS identifies several metrics or characteristics for measuring the severity of vulnerabilities. Each new vulnerability that is made public will include a CVSS score. The term “Bugtraq” is used to refer to a prescribed electronic mailing list dedicated to computer security issues. While prescribed electronic lists are described, such examples are not limited to other mailing lists and other community forums and / or social media posts or forums.

[0044] In some embodiments, a vulnerability may not include or be associated with a publicly disclosed CVSS score, or there may be a discrepancy between the disclosed score and the expected or estimated CVSS score from the CVP engine, in which case the CVP engine can generate a base CVSS score. In such embodiments, the CVP system 202 and / or the CVP engine 210 may determine and / or generate the base CVSS score. In further embodiments, the CVP system 202 and / or the CVP engine 210 may determine such a CVSS score based on objective factors or characteristics of the vulnerability (e.g., the type of vulnerability) and / or based on user input (e.g., the user entering a CVSS score). In other cases, the CVSS score may be generated / calculated manually.

[0045] Once a CPS occurs for any known vulnerability, the CVP engine 210 or CVP system 202 will utilize this CPS to prioritize the use of network / computation resources to address events arising for each known or detected vulnerability present on the network. For example, vulnerabilities with lower CPS may be considered lower risk than those with higher CPS / risk, and resources (e.g., analyst time) may be allocated accordingly. The CVP engine 210 or CVP system 202 may transmit the CPS to one or more computing devices 208A, 208B, 208N, or to a user interface for display, thereby prioritizing the determination of solutions for the vulnerabilities. The CPS may be displayed via the CVP system 202 on a connected user interface, as described. Such a user interface may display each CPS for each of one or more vulnerabilities as a list or in other graph format. Such lists or other graph formats may be presented in a manner that highlights and / or prioritizes vulnerabilities with higher CPS.

[0046] When executed, the CVP engine 210 may include instructions to detect or discover events and / or data generated by one or more computing devices 208A, 208B, 208N via events associated with one or more vulnerabilities. Such events may include, for example, network mapping, asset (e.g., computing devices 208A, 208B, 208N, storage locations, specified or pre-selected files or components) scanning, web application scanning, website scanning, external source scanning or detection, threat intelligence events (e.g., asset exposure, known threat linked, exposed asset quarantine, etc.), and / or others. In response to an event occurring or being carried out, data may be generated. The data may be detected, discovered by and / or transmitted to the CVP engine 210. The CVP engine 210 may then utilize one or more agents corresponding to the data type of the detected, discovered, and / or transmitted data. Each of the one or more agents used may generate a partial CPS. Each partial CPS may be weighted by the corresponding agent, the CVP engine 210, and / or other algorithms or instructions contained within the CVP system 202 or the CVP engine 210. Each partial CPS may be integrated into or incorporated into a previous CPS. The new and / or updated CPS may be transmitted to each computing device 208A, 208B, 208N and / or displayed via a user interface.

[0047] In some embodiments, events may occur and / or be detected continuously, substantially continuously, or over a selected period of time on one or more computing devices 208A, 208B, and 208N. In some embodiments, different events may occur differently and / or at different times on one or more computing devices 208A, 208B, and 208N. The number of events occurring at any given time may be large, such as hundreds, thousands, millions, or even more. Thus, each CPS addressing multiple vulnerabilities may be frequently updated. Events may occur or be executed in relation to a particular vulnerability continuously, substantially continuously, or over a selected period of time over a selected time interval. The time interval may be defined by the time over which a particular vulnerability affects computing devices 208A, 208B, and 208N. In other words, once a solution for a particular vulnerability is determined and implemented, events corresponding to that particular vulnerability may cease to be detected and / or executed.

[0048] Contextual data may include data relating to how vulnerabilities affect computing devices 208A, 208B, 208N, assets, networks, and / or other devices or components. Each different contextual data may be weighted differently from other contextual data. For example, contextual data may include vulnerability nature (e.g., vulnerability detection reliability, exploitability reliability, cross-site scripting (XSS) protection and misconfiguration, etc.), asset context (e.g., scan frequency, availability requirements, asset severity, tagging scheme, public accessibility, user access, software awareness, service awareness, anomalous services, anomalous port / service combinations, anomalous software, common database exposure services, common remote management services, website attack surface, website size, number of websites hosted by the server, operating system (OS) classification / severity, scan information date, etc.), network context (e.g. In another embodiment, context data may include prominent assets, simulated attack path exploration, attack paths likely to be found through simulation, etc., organizational context (e.g., organizational importance, vulnerability exposure within a timeframe for effective remediation, detection reliability, false positive prediction, etc.), and / or external context (e.g., types of trusted and available exploits, vulnerability trending, available remote exploits, available denial-of-service exploits, available web application exploits, exploits using local access, available unclassified exploits, citations in vulnerability and / or threat intelligence tools, etc.). In another embodiment, context data may include payload analysis, exploitability, detection reliability, threat intelligence, whether the content is linked to known malware, and / or vulnerability trends.Furthermore, contextual data may include, or exceed, one of the following: exposure data, software and services affected by the vulnerability, vulnerability-related behavioral analysis, website content, scan frequency, network attack surface, critical potential, prominent asset detection, or remediation time.

[0049] As described, the CVP engine 210 may include one or more agents. Each agent may correspond to one or more types of contextual data. For example, when determining partial CPS based on whether a server stands out from network content, an agent including a machine learning algorithm may be used to identify outlier assets based on the meta-characteristics of an asset (e.g., service, OS, port, etc.). The machine learning algorithm may generate partial CPS based on the identified characteristics. In another embodiment, several simulated attack vectors may occur, be probabilistically ranked, and, via an agent, determine which asset is most likely to be targeted. In such an embodiment, the agent may generate partial CPS based on the probabilistic ranking. In yet another embodiment, the CVP engine 210 may monitor vulnerability mentions or trends on social networks, dark web forums, and users involved in security (e.g., security agents and / or specialists). The CVP engine 210 may analyze arbitrary text data found in relation to vulnerabilities (e.g., discussions in the security community, topics mapped to vulnerabilities, etc.) via, for example, a natural language processing model. A natural language processing model may produce or generate a number that represents a partial CPS, which in this case may represent the context of a discussion related to the vulnerability.

[0050] Figure 2B is a schematic illustration of another configuration or non-limiting exemplary embodiment of the CVP system 202, configured to generate and dynamically update a CPS regarding new or updated vulnerabilities using contextual features or data from one or more events occurring substantially continuously, sequentially, or over a pre-selected period, according to one aspect of the present disclosure. The CVP system 202 in Figure 2B may be implemented in or by the Information Handling System 10 of Figure 1. The CVP system 202 may include a CVP engine 210 that starts on one or more processors 212, input / output modules 214, and / or memory 205. In such embodiments, the CVP engine 210 may consist of instructions stored in memory 205. In other embodiments, as described, the CVP engine 210 may consist of a network, sub-network, modules, submodules, and / or other hardware of the CVP system 202. The CVP engine 210 may utilize data 216 stored in memory 205, such as contextual features or data, CVSS scores, and / or other data corresponding to one or more vulnerabilities. The CVP engine 210 may connect to various internal or external databases 224, repositories, or data sources.

[0051] Figure 3 is a schematic diagram of a system for dynamically scoring vulnerabilities, representing one aspect of the present disclosure. System 300 may include a CVP engine 322. The CVP engine 322 may be a system (e.g., CVP system 202 in Figures 2A and 2B), a computing device, and / or an information handling system 14, or may be included therein. The CVP engine 322 may include one or more agents (e.g., agent 324A, agent 324B, etc., up to agent 324N). Each agent 324A, 324B, 324N may comprise an algorithm. The algorithm may be a trained machine learning algorithm or classifier (e.g., a supervised or unsupervised machine learning algorithm), a probabilistic model, a statistical model, or other model or classifier that takes some type of data as input and, based on the input, generates partial CPS (e.g., partial CPS 326A, partial CPS 326B, and partial CPS 326N). In one embodiment, an additional agent may be added to the CVP engine 322 based on the detection of a new type of data. The CVP engine 322 may also include a module or network for determining the CPS (e.g., CPS determination 328).

[0052] In one embodiment, for each vulnerability on the network, the CVP engine 322 may determine the CPS by using the CVSS score. In another embodiment, the initial CPS may be generated using CVSS and partial CPS 326A, 326B, 326N from agents 324A, 324B, 324N. In one embodiment, the updated CPS may be continuously determined based on a set of data associated with one or more events 312, 314, 316, 318, 320 associated with / related to each vulnerability.

[0053] The CVP engine 322 may receive or generate data corresponding to one or more events 312, 314, 316, 318, 320 from one or more different devices, routines, algorithms, computing devices, and / or other computing devices outside the CVP engine 322. For example, the CVP engine 322 may perform network mapping to computing devices or other devices in a network or cloud environment. The network mapping 302 may generate events 312 corresponding to one or more vulnerabilities. Such events 312 may include data, among other network-related data, of whether a server stands out significantly from its network context (e.g., whether the server or its use is an outlier relative to typical and / or previous use) and simulated attack vectors on the network. In some embodiments, a computing device may utilize vulnerability scanning 304 to provide events 314 containing various vulnerability properties. In other embodiments, the vulnerability properties may include data, which may include, but are not limited to, other data such as the reliability of vulnerability detection, the reliability of exploitability, and the protection and protection configuration.

[0054] In another embodiment, a computing device, for example, via an application and / or a local agent or diagnostic program, or the CVP engine 322, may utilize the web application scan 306 to provide an event 316 containing website vulnerability context and / or asset context. The website vulnerability context and / or asset context may include, but are not limited to, data such as scan frequency, availability requirements, asset or website severity, tagging scheme (e.g., whether a tag deviates from or stands out from most other tags relating to the asset, or whether the asset contains many user-defined tags), public accessibility, recognizable software used, recognizable services used, anomalous services found, anomalous software found, anomalous port / service combinations found, website attack surface, website size, and whether and how many servers host the website. In such an embodiment, event 316 may describe attack surface potential information for a new CPS calculation or determination (e.g., using a determined partial CPS).

[0055] In addition, the computing device or CVP engine 322 may utilize an external source 308 to obtain an event 318 containing an external data context. The external data context may include, among other data, data on whether exploit actions for the vulnerability are available, whether the vulnerability or a topic related to the vulnerability is gaining attention or being discussed in online communities or social media, and whether security tools are mentioning the vulnerability. In another embodiment, the computing device, security tool, or CVP engine 322 may utilize a threat intelligence tool 310 to obtain an event 320 containing threat intelligence data. The threat intelligence data may include, but is not limited to, threat intelligence data related to one or more vulnerabilities, among other data.

[0056] If one or more vulnerabilities correspond to one or more of events 312, 314, 316, 318, 320, the data generated by each event 312, 314, 316, 318, 320 corresponding to one or more vulnerabilities is directed to each of agents 324A, 324B, 324N, which are assigned to or associated with one or more data types relating to the particular vulnerability. In such embodiments, each agent 324A, 324B, 324N may generate partial CPS 326A, 326B, 326N in parallel and / or at various times. In embodiments, the CVP engine 322 may scan various computing devices or other devices for the occurrence of events 312, 314, 316, 318, 320.

[0057] Once one or more partial CPSs 326A, 326B, 326N are determined, each partial CPS 326A, 326B, 326N may be used to determine a CPS via a module or network for determining a CPS (e.g., CPS determination 328). CPS determination 328 may utilize aggregation or calculations based on the previous CPS and one or more partial CPSs 326A, 326B, 326N to determine a new CPS. Each partial CPS 326A, 326B, 326N may be used as a factor relating to the new CPS. In another embodiment, any new partial CPS 326A, 326B, 326N may replace a previous partial CPS that formed the overall previous CPS. The new CPS may replace a previous CPS relating to a particular vulnerability. In some embodiments, the new CPS can be discarded or replaced by the existing CPS, depending on a decision regarding whether the new CPS differs from the existing CPS by a selected threshold.

[0058] Once a new CPS is determined, the new CPS may be transmitted for display to one or more user components or devices 330A, 330B, 330N, computing devices, user interfaces, and / or other devices or components. The new CPS may also be used to generate another new CPS in response to the occurrence of any new partial CPS. In addition, in response to the occurrence of a new CPS, the new CPS may be stored in memory, storage devices, and / or databases. Data indicating a specific vulnerability may be included with the new CPS. Data used to generate a new CPS may also be stored with the new CPS.

[0059] Figure 4 shows an embodiment of a method / process for dynamic vulnerability scoring according to one aspect of the present disclosure. Three actions are illustrated in relation to time 436 in such a method. The three actions include an event being injected into the system 402, the score being updated 404, and the score being displayed 406. Although three actions are illustrated, the method is not limited to such actions, and the method may include additional types of actions. The system described in relation to Figure 4 may include the information handling system of Figure 1, the CVP system of Figures 2A and 2B, and / or the CVP engine of Figure 3.

[0060] In one embodiment, an event may be injected into the system in block 412. In block 412, a vulnerability may be detected or scanned. Data associated with and / or corresponding to the vulnerability may be injected into the system during such scanning or detection. The data may include CVSS. The vulnerability may include any vulnerability affecting a computing device, such as an exploit or method or process of taking advantage of the vulnerability, outdated or misconfigured software and / or modifications to a computing device or other device, an unauthorized IP address indicating that a threat has been realized (e.g., via a weak password), or an external file on an unprotected website. In 414, a CPS may be determined. The CPS may be a CVSS, at least with respect to the initial occurrence. In another embodiment, additional data such as contextual features or data and / or other historical data corresponding to the vulnerability may be included in such occurrence or determination. Once a CPS is determined, the CPS (e.g., CPS A416), in addition to the data identifying the vulnerability, may be displayed to the user or stored in memory, a storage device, and / or a database.

[0061] In block 418, an event indicating that an asset is exposed may be injected into the system. Depending on the type of asset (e.g., public / private, accessible / inaccessible, important / insignificant, etc.), the agent may determine a partial CPS and incorporate the partial CPS into the previous CPS (e.g., from 414) in CPS update 420. The new CPS (e.g., CPS B422) may then be displayed and replace the previous CPS in memory, storage devices, and / or databases.

[0062] In block 424, an event may be injected into the system indicating that a known threat is linked. In other words, a known threat is linked to a specific asset (e.g., indicating that the asset is under attack or targeted). Depending on the type of threat, the agent may determine a partial CPS and incorporate the partial CPS into the previous CPS (e.g., from 420 and 422) in CPS update 426. The new CPS (e.g., CPS C428) may then be displayed and replace the previous CPS in memory, storage devices, and / or databases.

[0063] In block 430, an event may be sent to the system indicating whether the asset is to be isolated. Depending on the accessibility of the asset, the agent may determine a partial CPS and incorporate the partial CPS into the previous CPS (e.g., from 426 and 428) in CPS update 432. The new CPS (e.g., CPS D434) may then be displayed and replace the previous CPS in memory, storage devices, and / or databases.

[0064] Other events may be injected into the system at any time (e.g., concurrently or sequentially). For example, an additional event indicating that another asset is exposed may be received. The corresponding CPS may be updated based on the received context data. Once a partial CPS score is determined, previous CPS may be updated and replaced. While the events injected into the system in Figure 4 are illustrated as being injected into the system in a sequential order, such embodiments are not limiting, and it should be understood that events may be injected at many different times, simultaneously, or in some combination thereof.

[0065] Figure 5 illustrates a method / process for dynamic vulnerability scoring according to one aspect of this disclosure. It should also be understood that any of the figures described herein, in particular Figures 1-3, may implement Method 500. The order in which the operations are described is not intended to be construed as limiting, and any number of described blocks may be combined in any order and / or in parallel to implement the disclosed method.

[0066] In block 502, one or more vulnerabilities may be detected or scanned. The CVP system (e.g., information handling system 14 / 22, CVP system 202, and / or CVP engine 322) may scan for such vulnerabilities, or may receive such vulnerabilities from one or more different computing devices or users (e.g., via a user interface). In another embodiment, the CVP system may scan external data sources for new or updated vulnerabilities. In yet another embodiment, vulnerability detection may be a continuous process.

[0067] In block 504, once a vulnerability is detected, received, or discovered by the CVP system, the CVP system may determine a CPS for each vulnerability detected, received, or discovered. In one embodiment, the initial CPS may be based on the CVSS of the vulnerability. In another embodiment, in addition to receiving the CVSS when a vulnerability is received, the CVP system may receive historical data. The historical data may include one or more contextual features or data related to the vulnerability. In such embodiments, the CPS may be based on one or more partial CPS generated for each of the one or more contextual features. Each partial CPS may be generated by one or more corresponding agents of the CVP system.

[0068] In block 506, the CVP system may scan for new events from one or more computing devices or other devices. The CVP system may scan continuously, substantially continuously, or over a pre-selected period. In another embodiment, instead of scanning for new events, the CVP system may wait until a new event is received. In such an embodiment, the CVP system may communicate with one or more computing devices or other devices. When an event occurs in one or more computing devices or other devices, the event, along with the corresponding data, may be transmitted to the CVP system.

[0069] In block 508, the CVP system may determine a partial CPS based on the received data corresponding to an event. In one embodiment, based on the type of received data and / or the context of the received data, the CVP system may generate a factor. In such embodiments, the factor may be considered a partial CPS as needed. A partial CPS or factor may be used by the CVP system to generate a new updated CPS. For example, if a factor is used for a partial CPS, the new factor may be applied to the current CPS to generate a new CPS. In addition, in embodiments, the new partial CPS may be weighted or compared to an existing partial CPS with respect to such a factor, and if it is found that this differs by a pre-selected threshold, the new CPS may be applied.

[0070] In block 510, the CVP system may determine whether a new CPS differs from a previous or current CPS. In another embodiment, the CVP system may determine whether a partial CPS differs from a previous partial CPS. In any embodiment, if no differences are detected, the CVP system may continue scanning or wait until a new event is detected or received.

[0071] In block 512, if a difference is detected in block 510, the CVP system may generate an updated CPS. As described above, if the partial CPS is a factor, the factor may be applied to the previous CPS. Other values ​​or types of partial CPS may be incorporated into or applied to the previous CPS. In block 514, the CVP system may transmit the new CPS to each computing device or other device. In another embodiment, the new CPS may be stored in memory, a storage device, and / or a database, in addition to or without transmitting the new CPS to each computing device or other device. The CVP system may also display the new CPS on a user interface.

[0072] Figure 6 shows a method / process for dynamic vulnerability scoring according to one aspect of this disclosure. It should also be understood that any of the figures described herein, in particular Figure 1-3, may implement Method 600. The order in which the operations are described is not intended to be construed as limiting, and any number of described blocks may be combined in any order and / or in parallel to implement the disclosed method.

[0073] In block 602, the CVP system may scan for new vulnerabilities. One or more vulnerabilities may be detected. The CVP system may scan for such vulnerabilities, or it may receive such vulnerabilities from one or more different computing devices or users. In other embodiments, the CVP system may wait until it receives such vulnerabilities from one or more different computing devices or users (e.g., via a user interface). In yet another embodiment, the CVP system may scan external data sources for new or updated vulnerabilities.

[0074] In block 604, the CVP system may scan for new events from one or more computing devices or other devices. The CVP system may scan continuously, substantially continuously, or over a pre-selected period. In another embodiment, instead of scanning for new events, the CVP system may wait until a new event is received. In such an embodiment, the CVP system may communicate with one or more computing devices or other devices. When an event occurs in one or more computing devices or other devices, the event, along with the corresponding data, may be transmitted to the CVP system.

[0075] In block 606, if a new vulnerability is detected, discovered, or received, the CVP system may obtain a CVSS for the new vulnerability. The CVP system may obtain other data corresponding to the new vulnerability. This other data may include historical data, contextual features or data, or other data related to the CVSS from an external source. In block 608, the CVP system may obtain contextual data or historical contextual data. In block 610, the CVP system may determine the CPS based on the CVSS, other data, and contextual data or historical contextual data. In block 612, the CPS may be transmitted to each computing device of one or more different computing devices.

[0076] If a new event is detected in block 604, in block 614 the CVP system may receive data corresponding to the newly detected event and direct different parts or types of data to corresponding or associated agents. In block 616, the CVP system may determine a partial CPS based on the data corresponding to the event, via agents corresponding to the data type of the data corresponding to the event. In block 618, the CVP may generate an updated CPS based on the previous CPS and partial CPS. In block 620, the CVP system may replace the previous CPS with the updated CPS. In block 612, the updated CPS may be transmitted to each of the computing devices.

[0077] Figure 7 shows an embodiment of an information handling system 700 capable of performing specific embodiments and variations of the present disclosure, including hosting a CVP engine and / or being scanned by a CVP engine. The information handling system 700 can represent the system shown in Figures 1-3. The information handling system 700 may include a computer system or processor 702, such as a central processing unit (CPU), a graphics processing unit (GPU), or both. The information handling system 700 may also include a main memory 704 and a static memory 706, which can communicate with each other via a bus 708. The information handling system 700 includes an antenna and an NFC device and interface 718, such as an NFC subsystem. The information handling system 700 may also include a disk drive unit 716 and a network interface device 720. As shown, the information handling system 700 may further include a video display unit 710 such as a liquid crystal display (LCD), organic light-emitting diode (OLED), flat panel display, solid-state display, or cathode ray tube (CRT), or other suitable display. The video display unit 710 may also act as an input that receives touchscreen input. In addition, the information handling system 700 may include a keyboard and an input device 712 such as a cursor control device 714 such as a mouse or touchpad, or a selectable interface on the display unit. The information handling system may also include a battery system or other backup power source and a disk drive unit 716. The information handling system 700 can represent a device that is telecommunicable and whose resources, voice communication, and data communication can be shared among multiple devices. The information handling system 700 can also represent a server device whose resources can be shared by multiple client devices, or this can represent individual client devices such as laptop or tablet personal computers.

[0078] The information handling system 700 may include a set of instructions that can be executed to cause the processor to perform one or more of the methods or computer-based functions disclosed herein. The processor 702 may operate as a standalone device or may be connected to other computer systems or peripheral devices using a network or the like.

[0079] In a networked deployment, the information handling system 700 may operate as a server, as a client user computer in a server-client user network environment, or as a peer computer system in a peer-to-peer (or distributed) network environment. The information handling system 700 may also be implemented as or incorporated into various devices such as personal computers (PCs), tablet PCs, set-top boxes (STBs), smartphones, PDAs, mobile devices, palmtop computers, laptop computers, desktop computers, communication devices, wireless telephones, landline telephones, control systems, cameras, scanners, facsimile machines, printers, pagers, trusted personal devices, web appliances, network routers, switches or bridges, or any other machines capable of executing (sequentially or otherwise) a set of instructions that define the actions to be performed by such machines. In certain embodiments, the computer system 700 may be implemented using electronic devices that provide voice, video, or data communications. Furthermore, while a single information handling system 700 is illustrated, the term “system” shall also be taken to include any set of systems or subsystems that individually or collectively perform one or more sets of instructions for performing one or more computer functions.

[0080] The disk drive unit 716 and / or static memory 706 may include a computer-readable medium 722 into which one or more sets of instructions 724, such as software, may be embedded, and which will generally contain sufficient space for data storage. Furthermore, the instructions 724 may embody one or more of the methods or logic described herein. In certain embodiments, the instructions 724 may reside entirely or at least partially in the main memory 704, the static memory 706, and / or the processor 702 during execution by the information handling system 700. The main memory 704 and the processor 702 may also include a computer-readable medium. The network interface device 720 can provide connectivity to a network 726, for example, a wide area network (WAN), a local area network (LAN), a wireless network (IEEE 802), or other network. The network interface device 720 may also interface with a macrocellular network, including a radio telecommunications network characterized as 2G, 3G, 4G, 5G, LTE, or similar radio telecommunications networks as described above. The network interface device 720 may also be a radio adapter having an antenna system 732 for various radio connectivity and a radio frequency subsystem 730 for signal reception, transmission, or related processing.

[0081] In alternative embodiments, dedicated hardware implementations such as application-specific integrated circuits, programmable logic arrays, and other hardware devices may be constructed to implement one or more of the methods described herein. Applications, which may include devices and systems of various embodiments, can broadly include a variety of electronic and computer systems. One or more embodiments described herein may implement functionality using two or more specific interconnected hardware modules or devices with relevant control and data signals that can be communicated between modules, or as part of an application-specific integrated circuit. Thus, the system encompasses software, firmware, and hardware implementations. According to various embodiments of this disclosure, the methods described herein may be implemented by software programs executable by a computer system. Furthermore, in exemplary non-limiting embodiments, implementations may include distributed processing, component / object distributed processing, and parallel processing. Alternatively, virtual computer system processing may be constructed to implement one or more of the methods or functionalities described herein.

[0082] This disclosure envisions a computer-readable medium that includes instructions 724, or receives and executes instructions 724 in response to propagating signals, so that a device connected to network 728 can communicate voice, video, or data over network 728. Furthermore, instructions 724 may be transmitted or received over network 728 via a network interface device 720. In certain embodiments, instructions may include BIOS / FW code, which includes machine-executable code that resides in memory 704 and is executed by processor 702 to perform various functions of information handling system 700.

[0083] The instructions 724 that can be operated by the information handling system 700 may include one or more application programs and basic input / output system and firmware (BIOS / FW) code. The BIOS / FW code functions to initialize the information handling system 700 when powered on, to call the operating system, and to manage input and output interactions between the operating system and other elements of the information handling system 700.

[0084] In another embodiment (not shown), the application program and BIOS / FW code reside in a separate storage medium of the information handling system 700. For example, the application program and BIOS / FW code may reside in the disk drive unit 716, in a ROM (not shown) associated with the information handling system 700, in an optional ROM (not shown) associated with various devices of the information handling system 700, in a primary or static memory storage device, in a storage system (not shown) associated with the network interface device 720 or network channel, in a separate storage medium of the information handling system 700, or in a combination thereof. The application program and / or BIOS / FW code may each be implemented on the machine handling system as a single program or as separate programs that perform various features as described herein.

[0085] While computer-readable media is expressed as a single medium, the term “computer-readable media” includes single or multiple media such as associated caches and servers that store a centralized or distributed database and / or a set of one or more instructions. The term “computer-readable media” also includes any medium capable of storing, encoding, or carrying a set of instructions for execution by a processor, or causing a computer system to perform one or more of the methods or operations disclosed herein.

[0086] In certain non-limiting exemplary embodiments, the computer-readable medium may include solid-state memory such as a memory card or other package that stores one or more non-volatile read-only memories. Furthermore, the computer-readable medium may be random-access memory or other volatile rewritable memory. In addition, the computer-readable medium may include magneto-optical or optical media such as disks or tapes or other storage devices for storing information received via carrier signals, such as signals communicated over a transmission medium. Furthermore, the computer-readable medium may store information received from distributed network resources, such as from a cloud-based environment. Digital file attachments to email or other embedded information archives or sets of archives may be considered distribution media equivalent to tangible storage media. Thus, this disclosure is deemed to include one or more computer-readable medium or distribution media and other equivalents and successor media in which data or instructions may be stored. The computer-readable medium may include “non-transient machine-readable storage media”. In some embodiments, non-transient machine-readable storage medium may be used to refer to any electronic, magnetic, optical, or other physical storage device for containing or storing information such as executable instructions, data, and equivalents. For example, any machine-readable storage medium described herein may be any of the following: random access memory (RAM), volatile memory, non-volatile memory, flash memory, storage drives (e.g., hard drives), solid-state drives, any type of storage disk, and equivalents, or any combination thereof. As described herein, memory may store or contain instructions that can be executed by a processor.

[0087] In embodiments described herein, an information handling system includes any means or set of means capable of operating to compute, classify, process, transmit, receive, read, transmit, switch, store, display, reveal, detect, record, copy, handle, or use any form of information, confidential information, or data for business, scientific, control, entertainment, or other purposes. For example, an information handling system may be a personal computer, a consumer electronic device, a network server or storage device, a switch router, a wireless router, or other network communication device, a network connection device (such as a cellular phone or tablet device), or any other suitable device, which may vary in size, shape, performance, price, and functionality.

[0088] An information handling system may include one or more processing resources, or any combination thereof, such as memory (volatile (e.g., random access memory), non-volatile (e.g., read-only memory, flash memory), or any combination thereof), a central processing unit (CPU), a graphics processing unit (GPU), hardware or software control logic, etc. Additional components of an information handling system may include one or more storage devices, one or more communication ports for communicating with external devices, and various input and output (I / O) devices, such as a keyboard, mouse, video / graphics display, or any combination thereof. An information handling system may also include one or more buses capable of transmitting communications between various hardware components. A part of an information handling system may be considered an information handling system in itself. The terms “processor,” “processing network,” and “processing resource” may also refer to one or more processors, either contained within a single device or distributed across multiple computing devices. The processor may be at least one of the following: a central processing unit (CPU), a semiconductor-based microprocessor, a graphics processing unit (GPU), a field-programmable gate array (FPGA) for reading and executing instructions, a real-time processor (RTP), another electronic network suitable for reading and executing instructions stored on a machine-readable storage medium, or a combination thereof.

[0089] When referred to as a “device,” “module,” or equivalent, the embodiments described herein may be configured as hardware. For example, a portion of an information handling system device may be hardware such as an integrated circuit (application-specific integrated circuit (ASIC), field-programmable gate array (FPGA), structured ASIC, or device embedded on a larger chip), a card (peripheral component interface (PCI) card, PCI-express card, Personal Computer Memory Card International Association (PCMCIA) card, or other such expansion card), or a system (motherboard, system-on-a-chip (SoC), or standalone device).

[0090] This device or module may include software, including firmware embedded in a device such as a Pentium® class or PowerPC brand processor or other such device, or software capable of operating the associated environment of the information handling system. This device or module may also include a combination of the aforementioned embodiments of hardware or software. Note that the information handling system may include a board-level product having an integrated circuit or a part thereof, which may be any combination of hardware and software.

[0091] Devices, modules, resources, or programs that communicate with each other do not need to communicate with each other continuously unless otherwise explicitly stated. In addition, devices, modules, resources, or programs that communicate with each other may communicate directly or indirectly through one or more intermediaries.

[0092] In another embodiment, the terms “computing device” or “system device” may be used to refer to any or all of the following: programmable logic controllers (PLCs), programmable automation controllers (PACs), industrial computers, desktop computers, personal digital assistants (PDAs), laptop computers, tablet computers, smartbooks, palmtop computers, personal computers, smartphones, wearable devices (such as headsets, smartwatches, or equivalents), and similar electronic devices that necessarily include at least a processor and any other physical components to perform the various operations described herein. Devices such as smartphones, laptop computers, tablet computers, and wearable devices are generally collectively referred to as mobile devices.

[0093] In another embodiment, the terms “server” or “server device” may be used to refer to any computing device capable of functioning as a server, such as a master exchange server, web server, mail server, document server, or any other type of server. A server may be a dedicated computing device, or a server module (e.g., an application) hosted by a computing device that causes the computing device to operate as a server. A server module (e.g., a server application) may be a full-featured server module, or a light or secondary server module (e.g., a light or secondary server application) configured to provide synchronization services between dynamic databases on the computing device. A light or secondary server is a slimmed-down version of server-type functionality that may be implemented on a computing device such as a smartphone, thereby enabling it to function as an internet server (e.g., a corporate email server) to the extent necessary to provide the functionality described herein.

[0094] The foregoing description illustrates and illustrates various embodiments of the present disclosure. However, it will be understood by those skilled in the art that various changes and modifications may be made to the structures discussed above in the present disclosure without departing from the spirit and scope of the present disclosure as disclosed herein, and that all matters contained in the foregoing description or shown in the accompanying drawings are intended to be interpreted illustratively and not limited in meaning. Furthermore, the scope of the present disclosure shall be interpreted to encompass various modifications, combinations, additions, alterations, etc., to the embodiments described above and herein, which shall be considered to be within the scope of the present disclosure. Thus, various features and characteristics of the present disclosure as discussed herein may be selectively substituted and applied to other illustrated and unillustrated embodiments of the present disclosure, and numerous variations, modifications, and additions may be made thereto without departing from the spirit and scope of the invention as described in the appended claims.

Claims

1. A system for dynamically assessing and ranking the security vulnerabilities of a network in which multiple computing devices are linked, wherein the system comprises: Contextual vulnerability prioritization engine The context vulnerability prioritization engine is equipped with, Detecting vulnerabilities and The context prioritization score (CPS) for the vulnerability is determined based on the aggregation of multiple partial CPSs generated for each of (a) multiple contextual features related to the vulnerability and (b) one or more non-contextual features related to the vulnerability. Scanning for the occurrence of events related to the vulnerability on the aforementioned multiple computing devices, In response to the detection of events related to the vulnerability on the plurality of computing devices, the directing of data corresponding to the detected events related to the vulnerability to the corresponding agents of the plurality of agents, wherein the directing is based on the data type of the data corresponding to the detected events. Each of the multiple partial CPSs of each of the multiple context features is dynamically calculated by the corresponding agent of the multiple agents based on the multiple context features related to the vulnerability and the data associated with the corresponding agent collected from the detected events. Determining a new partial CPS for each context feature applicable to the data corresponding to the occurrence of the detected event, via each corresponding agent receiving the data corresponding to the detected event, wherein the new partial CPS for each context feature is weighted based on the data type of the data corresponding to the detected event during the aggregation of the plurality of partial CPS, Based on the aforementioned new partial CPS, determine an updated CPS that represents the current state of the vulnerability, The updated CPS is transmitted to each of the plurality of computing devices. A system configured to perform the following actions.

2. The system according to claim 1, wherein each of the plurality of agents comprises one or more of the trained classifier, statistical model, or probabilistic model.

3. The system according to claim 2, wherein the trained classifier is generated via a plurality of additional contextual features related to the vulnerability, a plurality of additional non-contextual features related to the vulnerability, and one or more supervised machine learning algorithms or unsupervised machine learning algorithms.

4. The system according to claim 1, wherein the plurality of computing devices include one or more switches, access points, servers, storage devices, or user devices.

5. The system according to claim 1, wherein the one or more non-contextual features include a Common Vulnerability Scoring System (CVSS) score related to the vulnerability.

6. The system according to claim 1, wherein the plurality of contextual features include one or more of payload analysis, exploitability, detection reliability, threat intelligence, or vulnerability tendencies.

7. The system according to claim 6, wherein the plurality of contextual features further include one or more of the following: exposure data, software and services affected by the vulnerability, behavioral analysis related to the vulnerability, website content, scanning frequency, network attack surface, critical potential, prominent asset detection, or remediation time.

8. The system according to claim 1, wherein the data corresponding to the detected event comprises one or more of the following: exposure data, software and services affected by the vulnerability, behavioral analysis related to the vulnerability, website content, scan frequency, network attack surface, critical potential, prominent asset detection, or remediation time.

9. The system according to claim 1, wherein the context vulnerability prioritization engine is further configured to dynamically prioritize the plurality of vulnerabilities based on one or more dynamically updated CPSs relating to one or more vulnerabilities of the plurality of vulnerabilities.

10. The system according to claim 1, wherein the new partial CPS for each context feature is further weighted based on the importance of the corresponding agent.

11. A method for dynamically scoring network vulnerabilities, wherein the method is Detecting vulnerabilities in one or more computing devices of the network via a contextual vulnerability prioritization engine, Determining a context priority score (CPS) for each of the one or more vulnerabilities based on historical data via one or more agents of the context vulnerability prioritization engine, wherein the historical data includes a set of contextual features corresponding to each of the one or more vulnerabilities, In response to the detection of an event related to one of the one or more vulnerabilities on one or more computing devices of the network, Determining a partial CPS for each of the one or more received contextual features associated with the event, wherein each partial CPS is dynamically determined by an agent of the one or more agents of the contextual vulnerability prioritization engine based on the data associated with the vulnerability and the associated contextual entities associated with the vulnerability, and each agent of the one or more agents is associated with one of the data types of the one or more received contextual features, and When the partial CPS is determined with respect to at least one received contextual feature, A modified CPS relating to the vulnerability is generated based on the CPS and the partial CPS, wherein the partial CPS is weighted based on the data type of the at least one received context feature associated with the partial CPS. Transmitting the updated CPS to each of the one or more computing devices via the context vulnerability prioritization engine. To do To do Methods that include...

12. The method according to claim 11, wherein the event includes vulnerability detection based on one or more of the following: network mapping, vulnerability scanning, web application scanning, external sources, or threat intelligence.

13. The method according to claim 11, wherein the occurrence of one or more additional events relating to one or more of the vulnerabilities on one or more of the computing devices occurs continuously, substantially continuously, or at periodic time intervals.

14. The method according to claim 11, wherein multiple partial CPSs are determined in parallel based on the detection of the additional occurrence of one or more events associated with one of the one or more vulnerabilities.

15. The method according to claim 11, wherein the partial CPS is further weighted based on the emphasis placed on the agent that generated the partial CPS.

16. The method according to claim 11, wherein the historical data includes a Common Vulnerability Scoring System (CVSS) score.

17. A non-transient machine-readable storage medium, the non-transient machine-readable storage medium storing processor-executable instructions, and when the processor-executable instructions are executed by at least one processor, the at least one processor is provided with Detecting vulnerabilities in one or more computing devices, Determining a context prioritization score (CPS) for each of the one or more vulnerabilities based on historical data corresponding to each of the one or more vulnerabilities via one or more agents, wherein the historical data includes one or more contextual features, Detecting the occurrence of one or more events related to one or more of the vulnerabilities on the plurality of computing devices, Receiving one or more contextual features corresponding to the detection of the occurrence of one or more events related to one of the one or more vulnerabilities on the plurality of computing devices, Determining a corresponding partial CPS via at least one of the one or more agents corresponding to one data type of the one or more contextual features corresponding to the detection of the occurrence of one or more events related to one of the one or more vulnerabilities on the plurality of computing devices, The process involves generating an updated CPS based on the CPS and the corresponding partial CPS, wherein the corresponding partial CPS determined for each context feature is weighted based on one of the data types among the one or more context features corresponding to the detection of the occurrence of one or more events, The updated CPS is transmitted to the plurality of computing devices. A non-transient machine-readable memory medium that enables the following.

18. A non-transient machine-readable storage medium according to claim 17, wherein multiple partial CPSs are determined in parallel or substantially in parallel.

19. The non-transient machine-readable storage medium according to claim 17, wherein each of the one or more vulnerabilities is prioritized based on the CPS corresponding to each of the one or more vulnerabilities, or, if determined, one of the updated CPS.

20. The non-transient machine-readable storage medium according to claim 17, wherein, in response to a determination of the CPS for each of the one or more vulnerabilities based on historical data corresponding to each of the one or more vulnerabilities, the instruction, when executed by the at least one processor, causes the at least one processor to transmit the CPS corresponding to each of the one or more vulnerabilities to the plurality of computing devices.