Asset Grouping Rules for Vulnerability Detection in IT Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Vulnerability detection and management in IT systems is challenging due to their dynamic nature and increasing complexity, making timely and efficient detection and management difficult, especially with evolving external threats.

Innovation Solution

A system and method that utilize asset grouping rules to categorize assets and perform vulnerability management actions, along with determining trend records to track changes in vulnerability status over time, enabling precise and computationally efficient processing of large datasets to inform users effectively.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If vulnerability detection is performed on individual assets in large IT systems, then detection precision is improved, but processing time and system complexity increase significantly

Engineering Contradiction:
Improvevulnerability detection precisionVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent segments the large IT system into multiple asset groups based on common attributes (operating system, application software, hardware configuration). Instead of processing each asset individually, the vulnerability detection system processes groups of assets together, reducing the overall processing time while maintaining detection precision through attribute-based segmentation.

Inventive Principle:
Principle #1Segmentation

2Measurement precision

If vulnerability management is performed on each asset individually, then management accuracy is improved, but device complexity and operational difficulty increase

Engineering Contradiction:
Improvemanagement accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent merges assets with similar attributes into asset groups, allowing vulnerability management actions to be applied to multiple assets simultaneously. This reduces system complexity by consolidating management operations while maintaining accuracy through the structured grouping framework that preserves individual asset attributes for precise matching.

Inventive Principle:
Principle #5Merging (Combining)

3Measurement precision

If comprehensive asset attributes are collected for precise vulnerability detection, then detection accuracy is improved, but data processing complexity increases

Engineering Contradiction:
Improvedetection accuracyVSAvoiddata processing complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent extracts and utilizes only the most relevant asset attributes (operating system type, application software, hardware configuration) for vulnerability detection and grouping purposes. By selecting and extracting only the necessary attributes rather than processing all possible asset data, the system achieves high detection accuracy while reducing data processing complexity.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20240111874A1Asset Grouping Rules for Vulnerability Detection and Management in IT Systems
Publication Date: 2024.04.04 NUCLEUS SECURITY INC
  • US20240111874A1 patent drawing
  • US20240111874A1 patent drawing
  • US20240111874A1 patent drawing

AI summary

Disclosed are methods, systems and non-transitory computer readable memory for vulnerability detection and management. For instance, a method may include obtain asset information for an organization, wherein the asset information indicates a plurality of assets; obtain a set of grouping rules, wherein the set of grouping rules defines a plurality of groups based on asset attributes; obtain asset data from at least one source, wherein the asset data indicates particular attributes for at least a subset of assets of the plurality of assets; determine at least one specific group for each of the subset of assets; generate a data structure associating each asset of the subset of assets to a first group, thereby grouping the subset of assets into the first group; and perform at least one vulnerability management action using a command that applies to all of the assets, and only the assets, of the first group.