Grouping Assets for Vulnerability Management
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Vulnerability detection and management in IT systems is challenging due to their dynamic nature and increasing complexity, making timely and efficient detection and management difficult, especially with evolving external threats.
Innovation Solution
A system and method that utilize asset grouping rules to categorize assets and perform vulnerability management actions on a group basis, along with determining trend records to track changes in vulnerability status over time, ensuring precise and computationally efficient processing of large datasets.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If vulnerability management is performed on individual assets in complex IT systems, then detection precision is improved, but processing time and system complexity increase significantly
Solution Approach 1:
The patent combines multiple individual asset vulnerability management tasks into group-level operations. Assets with similar vulnerability profiles are merged into groups, allowing a single vulnerability management action to be applied to multiple assets simultaneously, thereby reducing processing time while maintaining detection precision through the grouping logic.
Solution Approach 2:
The system creates universal vulnerability management commands that can be applied across multiple asset groups. A single vulnerability management action serves multiple functions by being applicable to different groups of assets with similar characteristics, reducing the overall number of operations needed while maintaining comprehensive coverage.
2Reliability
If comprehensive vulnerability scanning is performed across all assets, then vulnerability detection completeness is improved, but computational resources and processing time increase
Solution Approach 1:
The patent segments the comprehensive vulnerability scanning task into group-level scans. Instead of scanning each asset individually across the entire system, assets are divided into groups based on similarity, and vulnerability management actions are performed at the group level, reducing computational resource requirements while maintaining detection completeness through representative sampling and grouping logic.
Solution Approach 2:
The system performs vulnerability management actions on representative groups rather than every single asset. By selecting groups that represent broader categories of assets, the system achieves sufficient vulnerability detection coverage without the excessive computational cost of scanning every individual asset in detail.
3Productivity
If asset grouping is implemented to reduce processing complexity, then processing efficiency is improved, but grouping accuracy may decrease leading to false positives
Solution Approach 1:
The patent applies local quality by creating heterogeneous groups where assets are grouped based on specific relevant attributes rather than uniform characteristics. Each group maintains local precision by considering asset-specific properties that are critical for vulnerability management, ensuring that assets within a group share the same vulnerability profile while still allowing for targeted management actions.
Data Source
AI summary
Disclosed are methods, systems and non-transitory computer readable memory for vulnerability detection and management. For instance, a method may include obtain asset information for an organization, wherein the asset information indicates a plurality of assets; obtain a set of grouping rules, wherein the set of grouping rules defines a plurality of groups based on asset attributes; obtain asset data from at least one source, wherein the asset data indicates particular attributes for at least a subset of assets of the plurality of assets; determine at least one specific group for each of the subset of assets; generate a data structure associating each asset of the subset of assets to a first group, thereby grouping the subset of assets into the first group; and perform at least one vulnerability management action using a command that applies to all of the assets, and only the assets, of the first group.


