Adaptive Vulnerability Prioritization Using Environmental Scoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing cybersecurity solutions are inadequate in prioritizing and remediating security vulnerabilities in computer networks, as they rely solely on the Common Vulnerability Scoring System (CVSS) scores without considering environment-specific factors, leading to overwhelming numbers of vulnerabilities and potential critical ones being left unresolved.

Innovation Solution

A cybersecurity solution that uses adaptive scoring by incorporating environmentally-dependent factors such as network connectivity, criticality, confidentiality, integrity, availability, and urgency, alongside CVSS scores, to prioritize and remediate vulnerabilities based on a calculated prioritization score.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If CVSS scores alone are used to prioritize vulnerabilities, then the prioritization process is simple and fast, but the accuracy and relevance to specific network environments deteriorates

Engineering Contradiction:
Improvevulnerability prioritization accuracyVSAvoidscoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent transforms the single CVSS score parameter into a multi-parameter scoring system that includes environmental factors (network connectivity, criticality, confidentiality, integrity, availability, urgency). This parameter expansion allows the system to adapt vulnerability prioritization to specific network environments, resolving the contradiction between simplicity and accuracy by making the system configurable rather than fundamentally complex.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The vulnerability scoring system is segmented into distinct components: base CVSS score, environmental factors, and weighted prioritization score. Each component serves a specific function and can be independently configured. This segmentation allows organizations to adjust the weight of different factors based on their specific needs without redesigning the entire system, maintaining ease of use while improving accuracy.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If environmental factors are incorporated into vulnerability scoring, then the relevance to specific network environments improves, but the computational complexity and processing time increases

Engineering Contradiction:
Improveenvironmental adaptabilityVSAvoidvulnerability assessment time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by pre-defining environmental factors and their weightings before vulnerability assessment begins. Organizations can configure their specific environmental context ahead of time, so when vulnerabilities are discovered, the system can quickly apply the pre-established scoring model without needing to analyze environmental factors in real-time, thus reducing assessment time while maintaining adaptability.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The environmental factor framework is designed as a universal model that can be applied across different network environments and vulnerability types. The same six environmental factors (network connectivity, criticality, confidentiality, integrity, availability, urgency) serve multiple purposes and can be configured with different weightings to suit various organizational needs, reducing the need for environment-specific customization and speeding up assessment.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If comprehensive environmental factors are analyzed, then the prioritization accuracy improves, but the ease of operation deteriorates

Engineering Contradiction:
Improveprioritization score accuracyVSAvoidsystem operation simplicity
Core Design Contradiction:
Measurement precisionVSEase of operation

Solution Approach 1:

The system enables self-service operation by automatically collecting environmental factor data and calculating prioritization scores without requiring manual intervention. The vulnerability management platform integrates with existing infrastructure to gather information about network connectivity, asset criticality, and other environmental factors, then automatically applies the scoring model and generates prioritized vulnerability lists, making the comprehensive assessment process as simple as initiating a scan.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent introduces an intermediary layer between vulnerability detection and remediation that automatically processes environmental factors and calculates prioritization scores. This intermediary scoring system acts as a mediator that translates complex environmental data into actionable prioritization recommendations, shielding operators from the complexity of analyzing multiple environmental factors while maintaining high accuracy.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS11438362B2Method and system for prioritizing and remediating security vulnerabilities based on adaptive scoring
Publication Date: 2022.09.06 SAUDI ARABIAN OIL CO
  • US11438362B2 patent drawing
  • US11438362B2 patent drawing
  • US11438362B2 patent drawing

AI summary

A system, a method, and a computer program for remediating a vulnerability on a computing resource asset located in a computer network that has a plurality of other computing resource assets each having at last one vulnerability, where a Common Vulnerability Scoring System (CVSS) score is determined for the vulnerability. Vulnerability scanning results data corresponding to the computing resource asset can be analyzed and an environmental factor weighting score value determined for each of a plurality of environmentally-dependent factors. The environmental factor weighting score values and CVSS score can be aggregated and an adjusted environmental factor weighting score aggregate value generated. A prioritization score value for the vulnerability on the computing resource asset can be determined based on the adjusted environmental factor weighting score aggregate value and the vulnerability remediated on each of the computing resource assets according to the prioritization score value.