AI Patch Management Through Vulnerability-Based Prediction

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Applying patches to a computing environment introduces system downtime and extra workload, and manually identifying and applying security patches is time-consuming, labor-intensive, and error-prone, especially when deciding which patches to install among thousands of available patches.

Innovation Solution

A prediction-based patch management system using AI models, such as deep reinforced learning (DRL) or Long Short-Term Memory (LSTM), scans the environment, predicts relevant patches, and automates the patching process, reducing the number of patches to be installed and minimizing downtime by prioritizing critical security patches.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual patch identification and application is performed, then security compliance is maintained, but time consumption and labor intensity increase significantly

Engineering Contradiction:
Improvesecurity complianceVSAvoidtime consumption
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enables automated self-service through AI models that automatically scan vulnerabilities, predict applicable patches, prioritize them by security criticality, and schedule installations without manual intervention. This resolves the contradiction by making the system serve itself, maintaining security compliance while eliminating time-consuming manual operations.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces manual mechanical operations with automated AI-based systems. The AI prediction models substitute human analysts, automatically processing vulnerability data and patch information to generate prioritized remediation plans, thereby maintaining security standards while dramatically reducing time investment.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Reliability

If all available patches are installed, then security vulnerabilities are addressed, but system downtime and workload increase

Engineering Contradiction:
Improvesecurity vulnerability resolutionVSAvoidsystem downtime
Core Design Contradiction:
ReliabilityVSDuration of action of moving object

Solution Approach 1:

The AI prediction models extract only the most critical and relevant patches from the full set of available updates. By filtering out non-essential patches and focusing solely on high-priority security vulnerabilities, the system addresses critical security issues while minimizing the number of installations required, thus reducing system downtime.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The system applies different prioritization levels to different patches based on their security criticality and relevance to specific vulnerabilities. Critical security patches are identified and scheduled first, while less critical updates are deferred, creating a localized quality approach that optimizes security remediation while minimizing overall downtime.

Inventive Principle:
Principle #3Local quality

3Ease of operation

If manual review of scan reports is performed, then patch priority is determined, but labor intensity and error rate increase

Engineering Contradiction:
Improvepatch priority determinationVSAvoidmanual review process
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The AI-based prediction models perform self-service by automatically analyzing vulnerability scan reports, cross-referencing patch databases, and determining priority levels without human intervention. This eliminates the need for manual review processes, reducing labor intensity and human error while maintaining accurate patch prioritization.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system implements automated feedback loops where AI models continuously learn from patch installation outcomes and vulnerability resolution data. This feedback mechanism improves the accuracy of priority determination over time, replacing manual review with an increasingly accurate automated system that reduces both labor intensity and errors.

Inventive Principle:
Principle #23Feedback

4Reliability

If security patches are prioritized over non-security patches, then security risks are reduced, but total patching time increases due to selective application

Engineering Contradiction:
Improvesecurity risk reductionVSAvoidpatch selection time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The AI prediction models perform preliminary action by pre-analyzing vulnerability data and pre-prioritizing patches before the actual patching process begins. This advance preparation automates the selection and prioritization work, allowing security patches to be identified and scheduled first without adding manual time to the overall process.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces manual patch selection and prioritization mechanics with automated AI-based systems. The AI models rapidly process vulnerability and patch data to determine priority, substituting human decision-making with automated algorithms that achieve the same security risk reduction without the time cost of manual analysis.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS12423439B2AI based patch management
Publication Date: 2025.09.23 ORACLE INT CORP
  • US12423439B2 patent drawing
  • US12423439B2 patent drawing
  • US12423439B2 patent drawing

AI summary

Systems, methods, and other embodiments associated with managing patches are described. In one embodiment, a method includes obtaining metadata associated with target assets in an IP address range. The target assets are scanned, and an initial list of security vulnerabilities and patches is generated along. A prediction model predicts which patches from the initial list are applicable to the target assets and removes unapplicable patches to generate a predicted list of patches. An interactive GUI is generated based on the predicted list of patches where each displayed patch includes an approve option and a reject option that are selectable by a user. An approved list of patches is generated which had the approve option selected. An electronic change request is automatically generated from the approved list of patches and presented for final approval, which causes the approved patches to be installed.