Patents
Literature
Patsnap Eureka AI that helps you search prior art, draft patents, and assess FTO risks, powered by patent and scientific literature data.

99 results about "Vulnerability management" patented technology

Vulnerability management is the "cyclical practice of identifying, classifying, prioritizing, remediating, and mitigating" software vulnerabilities. Vulnerability management is integral to computer security and network security, and must not be confused with Vulnerability assessment.

Vulnerability management method and system based on adaptive security platform

The invention relates to the technical field of vulnerability management, and discloses a vulnerability management method and system based on an adaptive security platform. The method comprises the following steps: constructing an asset information database based on all IT assets in an organization network environment, and calculating a time sensitivity parameter set; based on the asset information database and the time sensitivity parameter set, executing aperiodic time stratification vulnerability data collection and dynamic self-shaping processing to obtain a standardized structure vulnerability data set; performing vulnerability utilization chain topology analysis through the bidirectional adversarial neural network model to generate a vulnerability risk score and a vulnerability association relationship graph; and generating vulnerability risk decision information according to the vulnerability risk score and the vulnerability association relationship graph, and performing constraint perception adaptive repair arrangement based on the vulnerability risk decision information to generate an optimal vulnerability repair scheme. The vulnerability discovery process is more efficient and accurate, the repair success rate is improved, the service interruption time is shortened, and continuous optimization of the repair process is achieved.
Owner:SHAOGUAN COLLEGE

CAPEC vulnerability management system based on large language model

The invention discloses a CAPEC vulnerability management system based on a large language model, and belongs to the technical field of network security. The system comprises three modules: a vulnerability-CAPEC dynamic mapping module jointly encodes vulnerability description and code context through a bimodal large language model, accurately associates vulnerability logic with a CAPEC attack mode in combination with comparative learning and knowledge graph construction, and breaks through semantic limitation of traditional rule matching; the adversarial repair code generation module is used for generating high-robustness repair codes through adversarial training and syntax tree verification by fusing CAPEC relieving suggestions and code features on the basis of the association result, so that the secondary vulnerability risk is remarkably reduced; and the full-process automatic verification and DevOps integration module performs multi-dimensional security verification such as symbolic execution, fuzzy testing and the like on the generated repair code, and deeply integrates a development tool chain to realize real-time pushing and closed-loop management of a repair scheme.
Owner:BEIJING SHIXING TECH CO LTD

Container vulnerability management by a data platform

An illustrative method includes accessing, by a data platform, an alert generation policy associated with an entity that deploys containers in a cloud environment, the alert generation policy modifiable by the entity and specifying criteria for providing alerts associated with one or more vulnerabilities associated with the containers; detecting, by the data platform based on a scan of a container included in the containers, a vulnerability associated with the container; determining, by the data platform, an attribute of the vulnerability; and generating, by the data platform when the attribute meets the criteria specified in the alert generation policy, an alert associated with the vulnerability.
Owner:FORTINET INC

Internet of vehicles vulnerability management method, system and device based on block chain, and medium

The invention provides an Internet of Vehicles vulnerability management method, system, device and medium based on a block chain, and relates to the technical field of vehicle networks, the method can comprehensively identify potential safety risks of vehicles through a dynamic and static combined vulnerability detection mechanism, and generates a structured vulnerability report; hash abstract chaining evidence storage is performed on key data of reports and subsequent repair links by using a block chain, so that the whole process of vulnerability discovery, analysis and repair is ensured not to be tampered and traceable, and the authenticity and credibility of data are improved; the integrity of the report is verified at the cloud end, and an AI analysis engine is combined to associate a CVE database and threat intelligence, so that intelligent generation and decision support of a repair scheme are realized; the hash abstract on the chain of the OTA patch is verified at the vehicle end, so that the credibility of the patch source and the integrity of the content are guaranteed; and finally, through feedback of an installation result and secondary uplink archiving, complete closed-loop management from vulnerability discovery to repair verification is formed.
Owner:FIFTH ELECTRONICS RSCH INST OF MINISTRY OF IND & INFO TECH

Security vulnerability management method and system based on big data

The invention relates to the technical field of security vulnerability analysis, in particular to a big data-based security vulnerability management method, which comprises the following steps of: constructing a real-time data acquisition strategy, capturing an internal source network equipment log, a server running state and application system flow data through a distributed log collection component, and storing the internal source network equipment log, the server running state and the application system flow data; meanwhile, vulnerability information of the exogenous threat intelligence platform is synchronized through an API interface; constructing a dynamic risk assessment model, and updating the risk assessment of the security vulnerability in real time by taking the four-dimensional model [IP address, service type, port number and software version] as a reference; and triggering a response strategy according to risk value grading, wherein the response strategy comprises automatic isolation of high-risk equipment, dynamic configuration of firewall rules and generation of a repair work order. According to the invention, through the synergistic effect of real-time data acquisition, dynamic asset modeling, intelligent risk assessment, a hierarchical response mechanism and a closed-loop verification system, the accuracy, efficiency and defense capability of security vulnerability management are significantly improved.
Owner:ZHENGZHOU BIG DATA DEV CO LTD

CAPEC vulnerability association identification system based on ATTCK framework

The invention discloses a method based on ATTamp; the invention discloses a CAPEC vulnerability association identification system of a CK framework, and relates to the technical field of network security. Comprising a data integration module, an attack path analysis engine module, a vulnerability association analysis engine module, a dynamic update and intelligence integration module and a visual display module which are connected in sequence. In combination with a CAPEC framework, deeper threat intelligence and defense suggestions are provided from a behavior mode and an attack path of an attacker. Meanwhile, latest vulnerability information is obtained in real time through a dynamic updating and intelligence integration module, the vulnerability management efficiency and the threat detection accuracy are improved by automatically analyzing the incidence relation between the attack path and the vulnerability, the incidence relation between the attack path and the vulnerability is displayed through a graphical interface, a user is helped to visually understand the full view of the threat, and the threatening effect is improved. And a vulnerability influence range and restoration suggestion information are provided.
Owner:BEIJING SHIXING TECH CO LTD

Vulnerability closed-loop processing method and system based on intelligent collaboration

The invention discloses a vulnerability closed-loop disposal method and system based on intelligent collaboration, and belongs to the technical field of information security management. Vulnerability data and disposal information in a plurality of independent security systems are collected, and a multi-dimensional vulnerability semantic model is constructed; constructing a state perception graph based on a semantic model, extracting candidate state paths, and constructing a time sequence closed-loop prediction model in combination with a shortest closed-loop path and a historical track; according to a vulnerability influence range, a service dependency chain and a prediction path key node, adaptively dividing responsibility affiliation, generating a dynamic disposal responsibility graph and realizing automatic assignment; combining the node response capability and the task saturation, dynamically calculating the priority and scheduling the processing task; monitoring an actual disposal behavior, correcting an edge weight of the state diagram in real time and updating the model; according to the method, the whole-process intelligence, collaboration and dynamic evolution of vulnerability management are realized, and the processing efficiency and the prediction precision are improved.
Owner:山东九州信泰信息科技股份有限公司

Risk-based vulnerability management

Various systems and methods for providing risk-based vulnerability management are described herein. A system is configured to access an attack graph, the attack graph including exploits represented as preconditions and postconditions; access vulnerability information of a plurality of nodes in the network, the vulnerability information including conditions of the plurality of nodes in the network; access a network connectivity graph that represents a logical network topology of the plurality of nodes in the network; identify a set of attack paths in the attack graph by comparing the conditions of the plurality of nodes in the network with preconditions and postconditions in the attack graph; calculate a risk score for each of the set of attack paths in the attack graph; and present the risk score for each of the set of attack paths.
Owner:MCKESSON CORPORATION

Internet of Things vulnerability data restoration system

The invention relates to the technical field of Internet of Things security, in particular to an Internet of Things vulnerability data restoration system, which is used for solving the problems that in the prior art, multi-dimensional vulnerability features cannot be accurately extracted and propagated, potential vulnerabilities cannot be efficiently identified, high-risk vulnerabilities cannot be preferentially processed according to a dynamic resource adjustment strategy, and the vulnerability data restoration efficiency cannot be improved. And the accuracy, the automation level and the response efficiency of vulnerability management are reduced. According to the method, a heterogeneous relation graph between equipment and components is constructed through the vulnerability identification and positioning module, multi-dimensional vulnerability features are accurately extracted and propagated, efficient identification of potential vulnerabilities is realized, priority ranking is performed in combination with CVSS scores and equipment importance, high-risk vulnerabilities are preferentially processed through scientific scores and a dynamic resource adjustment strategy, and the efficiency of vulnerability identification is improved. And the to-be-fixed vulnerability list containing multi-aspect information is generated, so that the vulnerability management accuracy, the automation level and the response efficiency are remarkably improved.
Owner:DONGYING YINZHI INFORMATION TECHNOLOGY CO LTD

Collection analysis and utilization linkage method for full life cycle of vulnerability intelligence

PendingCN121530613AKnowledge representationSecuring communicationCollection analysisCritical information infrastructure
The invention discloses a collection, analysis and utilization linkage method for the full life cycle of vulnerability intelligence, which comprises the following steps: respectively acquiring original vulnerability intelligence of a plurality of heterogeneous data sources, and carrying out standardization processing on the original vulnerability intelligence to obtain vulnerability description information; constructing an asset knowledge graph, wherein the asset knowledge graph is used for representing IT asset objects in the enterprise and dependency and deployment relationships among the IT asset objects; performing graph traversal query on the vulnerability description information based on an asset knowledge graph, and identifying an affected asset list affected by vulnerabilities; and according to a preset response strategy, generating a safety response instruction from the affected asset list and sending the safety response instruction to the safety protection system. According to the method, the asset knowledge graph is constructed and the multi-source vulnerability information is subjected to standardization and mapping correlation analysis, so that the accurate and rapid identification of the affected assets of the power system and the automatic response strategy generation are realized, and the efficiency and the accuracy of the vulnerability management of the key information infrastructure of the power grid are effectively improved.
Owner:HUANENG POWER INT INC +1

Vulnerability severity score prediction method based on large language model and retrieval enhancement

The invention belongs to the technical field of network security, and particularly relates to a vulnerability severity score prediction method based on a large language model and retrieval enhancement. According to the method, an automatic scoring framework integrating data preprocessing, hierarchical CWE classification and an RAG technology is constructed; firstly, redundant noise of vulnerability description is eliminated through a version number cleaning algorithm driven by a regular rule, and then domain knowledge modeling is enhanced in combination with a hierarchical CWE classifier based on MITRE View-1003; and an RAG technology is adopted to fuse semantic features of historical similar vulnerabilities and a large language model generation capability, so that high-precision and interpretable CVSS score prediction is realized. Experiments show that the method can be widely applied to severity score prediction of various types of vulnerabilities, has good prediction robustness and effectiveness, significantly improves vulnerability management efficiency and decision transparency, and provides an effective tool for evaluation and management of software supply chain security.
Owner:FUDAN UNIVERSITY

Generative systems and methods for adaptive vulnerability management

Systems and methods are disclosed comprising instructions to collect vulnerability information over a network from a publishing source, collect network asset information of a communications network, generate a self-executing scanner agent configured to automatically scan the communications network for a known vulnerability based on an input including the collected vulnerability information and the collected network asset information, deploy the scanner agent at any network assets of the communications network that match a particular type of network asset indicated in the collected vulnerability information, generate a record including an indication of a particular network asset of the communications network in association with the known vulnerability in response to the scanner agent executing and detecting the known vulnerability in the particular network asset, and store the record in a data repository that aggregates records of detected known vulnerabilities in association with network assets of the communications network.
Owner:T MOBILE US INC

Cyber and property management system

A system and method are provided for integrating a property management system and a cyber vulnerability management system to provide remediation for assets in an environment. Information obtained about network connected mechanical assets within the environment is respectively obtained from a tag on the asset. For each asset the asset is identified through a property management database based on the information in the tag and a cyber position of the asset is obtained through a digital network identifier in the tag from the cyber vulnerability management system. In response to identification of the asset having a cyber vulnerability, remediation for the cyber vulnerability is determined, scheduled, and initiated.
Owner:RAYTHEON CO

Vulnerability proofing container orchestration platform deployment

Vulnerability proofing container orchestration platform deployment includes a remote access controller detecting a container orchestration platform installer comprising vulnerability management service instructions and executing the vulnerability management service instructions. This causes the remote controller to identify configurations for one or more of the hardware component(s) of the IHS in the container orchestration platform installer, access a plurality of catalogs specifying known vulnerabilities of hardware components and determine whether the hardware component configuration(s) in the container orchestration platform installer are identified as vulnerable in one or more of the catalogs. The remote controller blocks use of the container orchestration platform installer by the IHS until the hardware component configurations within the container orchestration platform installer are modified to include no configurations with vulnerabilities identified in the plurality of catalogs.
Owner:DELL PROD LP

Combining policy compliance and vulnerability management for risk assessment

An apparatus, a method, and a computer program product are provided that combine policy compliance with vulnerability management to provide a more accurate risk assessment of an environment. The method includes training a policy machine learning model using a first training dataset to generate a policy machine learning model to produce mitigation technique classifications and training a vulnerability machine learning model using a second training dataset to generate a vulnerability machine learning model to produce weakness type classifications. The method also includes mapping the mitigation technique classifications to attack techniques to produce a policy mapping and mapping the weakness type classifications to the attack techniques to produce a vulnerability mapping. The method further includes producing a risk assessment of a vulnerability based on the policy mapping and the vulnerability mapping.
Owner:INTERNATIONAL BUSINESS MACHINE CORPORATION

Vulnerability remediation based on priority of policies

A system for policy based vulnerability management of a network equipment of an enterprise is disclosed. A plurality of vulnerabilities associated with an end user device and a plurality of policies associated with the plurality of vulnerabilities is identified. Factors including a type of vulnerability, risks associated with the vulnerabilities and a time of action for a remediation of the vulnerabilities are identified. Based on the factors, each vulnerability is assigned a priority. Remediation for the plurality of vulnerabilities is determined based on the plurality of policies and the priority. A route based on a high compliance rate with the plurality of policies is selected. The cloud service is provided to the end user device via the route. Remediation of the plurality of vulnerabilities is executed based on the policies in accordance with the priority and the route with the high compliance rate.
Owner:NETSKOPE INC

Cyber and property management system

A system and method are provided for integrating a property management system and a cyber vulnerability management system to provide remediation for assets in an environment. Information obtained about network connected mechanical assets within the environment is respectively obtained from a tag on the asset. For each asset the asset is identified through a property management database based on the information in the tag and a cyber position of the asset is obtained through a digital network identifier in the tag from the cyber vulnerability management system. In response to identification of the asset having a cyber vulnerability, remediation for the cyber vulnerability is determined, scheduled, and initiated.
Owner:RAYTHEON CO

Contextual vulnerability management

Techniques are described for providing a software-based platform for context-based vulnerability management of information technology (IT) environments. In some examples, a vulnerability management application collects vulnerability scan data, from potentially many different scanning agents, as well as vulnerability information from other third-party sources. The vulnerability management application also accesses asset and activity data associated with an IT environment. The vulnerability management application can provide a user interface contextualizing vulnerabilities, based on the contextual asset or activity data, allowing for user-configured or automated vulnerability risk adjustments to impact the management and remediation of vulnerabilities for the IT environment.
Owner:CISCO TECHNOLOGY INC

A network security vulnerability automatic management method based on network security intelligence

The application provides a network security vulnerability automatic management method based on network security intelligence, belongs to the field of network security vulnerability management, and is used for solving the problems of low automation, large risk assessment deviation and poor collaboration in the related art. The method comprises network security intelligence collection, screening, storage and analysis, attack path prediction, key asset identification, hazard scene enhancement and vulnerability management. Through technologies such as dynamic weight, high-order probability graph model and multi-agent game, accurate intelligence processing, dynamic risk quantification, attack forward-looking prediction and cross-enterprise collaborative disposal are realized, the vulnerability management efficiency and accuracy are improved, and the network security of the ECUs is ensured.
Owner:SONKWO COM

Data leakage protection and monitoring system

The invention discloses a data leakage protection and monitoring system, and relates to the technical field of data security supervision. The system specifically comprises a data classification and marking module, a data access control module, a data encryption module, a data monitoring and analysis module, a data auditing and reporting module, a data shielding and desensitization module and a threat intelligence and vulnerability management module. The data access control module sets different access permissions according to data classification and marks, the data encryption module carries out encryption protection on sensitive data, the data detection and analysis module monitors the flow and access conditions of the data, and the data auditing and reporting module records access and operation logs of the data. According to the method, an enterprise is helped to quickly deal with and solve security problems, the flow direction of the data is tracked, the source and the destination of the data are known, security holes and risk points in a data transmission path can be identified, and the enterprise is helped to enhance the security of data transmission.
Owner:STATE GRID HUBEI ELECTRIC POWER INFORMATION & TELECOMMUNICATION COMPANY +1

Vulnerability management via a graphical interface

A computing machine displays a first interface region including indications of original software blocks and corresponding original vulnerability metrics, and a second interface region including subregions respectively associated with the original software blocks, each subregion presenting selectable compatible replacement software blocks and associated replacement vulnerability metrics. The computing machine presents aggregate vulnerability metrics including a first aggregate metric representing a count of vulnerabilities across the original software blocks and a second aggregate metric representing a count of vulnerabilities across indicated replacement software blocks. The computing machine receives a user selection of replacement software blocks for a selected subregion and responsively updates the associated replacement vulnerability metrics and the second aggregate metric to reflect vulnerabilities of the selected replacement software blocks. The computing machine displays a severity breakdown of vulnerabilities associated with at least one of the first aggregate metric or the second aggregate metric.
Owner:RAPIDFORT INC

A vulnerability patching method and system

ActiveCN122293434BAvoid additional scheduling overheadMaximize resource utilizationResource poolLower priority
The application provides a vulnerability repair method and system, and relates to the technical field of network security vulnerability verification and enterprise vulnerability management. The application obtains a task containing a vulnerability identifier, asset information and to-be-verified repair content, processes the task in parallel according to a pipeline split according to business execution steps, and configures a resource pool matching external dependencies for each stage; a stage fingerprint is generated when the task is transferred, a result is reused when a subtask is executed, otherwise the execution is scheduled according to vulnerability harm, asset importance and threat intelligence, and the vulnerability repair is completed according to the verification result. The application solves the problems of low throughput of the existing general pipeline, slow response of high-priority tasks, and easy starvation of low-priority tasks, and achieves the effect of collaborative optimization of throughput improvement, emergency task response acceleration and low-priority task starvation prevention without changing the original business and hardware.
Owner:CHINA UNICOM INTERNET OF THINGS CO LTD +1

Big model-based cvss intelligent scoring and repair decision method and system

The application provides a large model-based CVSS intelligent scoring and repair decision method and system, relates to the technical field of large model decision, and comprises the following steps: when it is detected that a CVSS score version is missing in vulnerability data information, a large model is used to analyze a CVSS index data set and output score index options, and a corresponding CVSS score is calculated; a risk repair data set is constructed according to asset information, vulnerability data and the CVSS score, a targeted repair scheme is generated by the large model, and the repair scheme is sent to a risk device for execution. The application realizes automatic completion of vulnerability scoring and generation of a device customized repair scheme, and improves vulnerability management efficiency.
Owner:JIANGSU BOZHI SOFTWARE TECH CO LTD

An intelligent network security situation monitoring and early warning platform for industrial control systems

ActiveCN116257021BMeet real-time monitoring and operation requirementsMeet traceable real-time monitoring operation requirementsTotal factory controlProgramme total factory controlData graphData acquisition
The application discloses an intelligent network security situation monitoring and early warning platform of an industrial control system, which comprises a device layer, a data acquisition layer, a data storage layer, an application service layer and a display layer; wherein the device layer comprises an industrial control host module, a network device module, a security device module and a third-party system; the data acquisition layer comprises an agent, a flow probe and a log collector; the data storage layer comprises a Redis cache, a MySQL database, an ELK real-time data analysis system and a Hadoop big data processing ecological module; distributed storage is adopted; the application service layer comprises an asset management module, a vulnerability management module, a threat analysis module, a workbench, a knowledge base, a data source management module, an alarm management module, a report management module, a device management module and a system management module; and the display layer comprises operation and maintenance monitoring, asset statistics, risk display and an industrial network topology, and is used for abstracting data and graphically displaying and providing visual display for final security operation.
Owner:CHINA DATANG CORPORATION SCIENCE AND TECHNOLOGY GENERAL RESEARCH INSTITUTE

Methods for handling code vulnerabilities

This application discloses a method for handling code vulnerabilities, relating to the field of vulnerability management technology. The method includes: scanning a target code segment to obtain initial vulnerability data, extracting features to form an initial vulnerability feature set, and obtaining category feature vectors; using a false positive detection model to filter the initial vulnerability feature set to obtain a vulnerability feature set; using a retrieval-enhanced generative agent to determine the false positive vulnerability feature set and non-false positive vulnerability feature set within the vulnerability feature set, as well as the corresponding processing actions; executing the processing actions to obtain the corresponding processing results, thereby determining the actual vulnerability data of the target code segment. This method solves the technical problems of dependency on project-specific code structures, difficulty in cross-project reuse, lengthy and difficult-to-maintain false positive lists as project scale expands, and increased maintenance costs due to code modifications leading to the recurrence of false positives. It achieves real-time analysis and processing, not only with high accuracy but also by generating effective processing solutions, thereby improving work efficiency.
Owner:INSPUR SUZHOU INTELLIGENT TECH CO LTD

Information security-based vulnerability management and control method and system

The application provides a vulnerability management and control method and system based on information security, which is applied to a vulnerability management and control system of information security, and comprises a server, a security vulnerability scanning module and a security management and control module. The security vulnerability scanning module is used for scanning security vulnerabilities, and the security management and control module is used for performing security management and control on the security vulnerabilities. First, the security vulnerabilities are scanned out by the security vulnerability scanning module, and are classified by the server according to types. Then, the security vulnerabilities are managed by the security management and control module according to strategies. Finally, the server proposes a high-risk and low-risk security patch upgrade package according to the high-risk and low-risk security vulnerabilities. The application can perform security management and control on the security vulnerabilities in a network, and has high practicability.
Owner:SHENZHEN POWER SUPPLY BUREAU

A vulnerability risk reachability analysis method, electronic device and storage medium

The present application relates to the technical field of data analysis, and particularly relates to a vulnerability risk reachability analysis method, an electronic device and a storage medium, wherein the initial risk evaluation value of a vulnerability is obtained by performing vulnerability scanning analysis on target code, and the reachability analysis weight is determined in combination with the path reachability analysis value and the conditional reachability analysis value, and finally the target risk evaluation is obtained, the actual possibility of the vulnerability being exploited is fully considered, compared with the traditional risk assessment based on inherent harm only, the real risk degree of the vulnerability can be more accurately reflected, a more reliable basis is provided for security decision, the target risk evaluation value can provide a reference for resource allocation, high-risk vulnerabilities can be preferentially processed in the vulnerability repair process, blind repair of vulnerabilities is avoided, and the efficiency of vulnerability management is greatly improved.
Owner:QINGDAO WANDAO (BEIJING) INFORMATION TECH CO LTD

Cybersecurity vulnerability management program evaluation system

Methods and systems described herein are directed to measuring cybersecurity vulnerability management programs and readiness. A vulnerability management program evaluation system can define vulnerability management capabilities and technologies supporting execution of those capabilities. Once defined, the system can conduct an initial assessment including scoring for the capabilities representing a depth of vulnerability management, as well as scoring for the technologies representing a breadth of vulnerability management. To update the initial assessment, the system can track the ongoing progress of projects that can affect the depth and / or breadth of vulnerability management, and then recalculate the scoring. At any time, the system can combine the depth and breadth to determine a comprehensive vulnerability management score.
Owner:UNITED SERVICES AUTOMOBILE ASSOCIATION (USAA)

Blockchain-based methods, systems, devices, and media for managing vulnerabilities in the Internet of Vehicles (IoV).

This invention provides a blockchain-based method, system, device, and medium for managing vehicle network vulnerabilities, relating to the field of vehicle network technology. The method utilizes a dynamic and static vulnerability detection mechanism to comprehensively identify potential vehicle security risks and generate structured vulnerability reports. By using blockchain to hash and store key data from the report and subsequent remediation processes, the entire process of vulnerability discovery, analysis, and remediation is tamper-proof and traceable, enhancing data authenticity and trustworthiness. Cloud-based verification of report integrity, combined with an AI analysis engine linking CVE databases and threat intelligence, enables intelligent generation and decision support for remediation solutions. On-vehicle verification of OTA patches via on-chain hash digests ensures the credibility of patch sources and the integrity of content. Finally, feedback on installation results and re-archiving on the blockchain completes a closed-loop management system from vulnerability discovery to remediation verification.
Owner:FIFTH ELECTRONICS RSCH INST OF MINISTRY OF IND & INFO TECH

Intelligent pre-boot indicators of vulnerability

A disclosed method provides a Device Integrity and Zero Trust (DIZ) protocol to implement proactive as well as reactive firmware vulnerability management. The DIZ protocol identifies device-level firmware versions and vulnerabilities and dynamically compiles appropriate firmware updates. The protocol may further construct a telemetry of the security vulnerability statistics for dynamic identification of Signs of Compromise (SoC) and collectively interpret various other platform telemetry stats for compiling vulnerability resolutions. An artificial intelligence (AI) based scalable and continuous Adaptive and Trust Assessment (ATA) method is employed for dynamic integration of partner solutions based on threat intelligence and remediation data. Disclosed solutions may further implement a geo location independent security adaption method. The identification and assessment of SoCs beneficially reduces an attacker's ability to breach an organization's IT systems. The DIZ protocol weeds out low-risk items from telemetry stats, and intelligently focuses on items most in need of remediation.
Owner:DELL PROD LP