Automated Configuration Vulnerability Assessment for Networked Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

As networked computer systems become increasingly complex, they introduce vulnerabilities that make it difficult to proactively prevent security breaches and other undesirable events, particularly due to software issues and configuration flaws in distributed computing environments.

Innovation Solution

The implementation of Secure Configuration Assessment (SCA) tools that generate vulnerability avoidance policies and provide monitoring tools for policy compliance across networked environments, enabling enhanced vulnerability management and risk scoring to prioritize remediation efforts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If networked computer systems incorporate more computer resources to increase capabilities, then system functionality and productivity are improved, but system complexity and vulnerability increase

Engineering Contradiction:
Improvesystem capabilitiesVSAvoidsystem complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent segments the complex networked system into individual configuration items (CIs) and their associated configuration parameters. Each CI represents a discrete component that can be independently assessed for compliance. This segmentation allows the system to manage complexity by breaking down the overall system into manageable units while maintaining the ability to assess the entire networked environment.

Inventive Principle:
Principle #1Segmentation

2Adaptability or versatility

If manual methods are used to assess configuration compliance, then flexibility and adaptability are maintained, but time consumption and productivity decrease

Engineering Contradiction:
Improveassessment flexibilityVSAvoidcompliance assessment speed
Core Design Contradiction:
Adaptability or versatilityVSProductivity

Solution Approach 1:

The system enables automated self-assessment of configuration compliance by having configuration items automatically report their configuration parameters to the assessment system. This self-service approach eliminates the need for manual data collection while maintaining the ability to assess diverse and evolving configurations, thereby improving productivity without sacrificing adaptability.

Inventive Principle:
Principle #25Self-service

3Measurement precision

If comprehensive configuration assessment is performed across all system parameters, then measurement precision and reliability are improved, but assessment time and resource consumption increase

Engineering Contradiction:
Improvecompliance detection accuracyVSAvoidassessment time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies local quality by focusing assessment efforts on specific configuration parameters that are most critical to compliance. Rather than uniformly assessing all parameters across all configuration items, the system identifies and prioritizes key configuration parameters based on their relevance to compliance requirements, thereby achieving high measurement precision for critical areas without the time cost of comprehensive assessment everywhere.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS11611480B2Systems and methods for automated governance, risk, and compliance
Publication Date: 2023.03.21 SERVICENOW INC
  • US11611480B2 patent drawing
  • US11611480B2 patent drawing
  • US11611480B2 patent drawing

AI summary

Systems and methods for configuration vulnerability checking and remediation are provided. The systems provided herein identify risk based upon service indications of a particular configuration, such that automated risk analysis may be facilitated.