Backup Image Patch Level Data for Security Vulnerability Resolution

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing backup systems fail to incorporate patch level data, leaving restored systems vulnerable to security vulnerabilities that have been addressed by post-backup patches, as these patches are not included in the backup images.

Innovation Solution

Incorporating image patch level data into backup images and using current patch level data to identify and update files to the latest patch levels during the restore process, ensuring that the restored system receives the latest security updates.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If backup images are created without patch level data, then backup storage requirements are reduced and backup process simplicity is maintained, but restored systems become vulnerable to security holes that were patched after the backup was made

Engineering Contradiction:
Improvesystem securityVSAvoidbackup image structure
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent embeds patch level data within the backup image structure, nesting metadata about file versions and security patches inside the existing backup framework. This allows the backup image to contain both the original files and the patch information needed to assess security vulnerabilities, resolving the contradiction between maintaining simple backup structures and ensuring restored systems are secure.

Inventive Principle:
Principle #7Nested doll (Nesting)

Solution Approach 2:

The patent performs preliminary analysis of patch levels during the backup creation process, capturing file version information and known security vulnerabilities before the backup is completed. This preliminary action allows the restore process to identify and address security holes without adding complexity to the actual restore operation, as the security assessment data is already prepared and embedded in the backup image.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If patch level data is incorporated into backup images, then restored systems can be updated with latest security patches, but backup image size and processing complexity increase

Engineering Contradiction:
Improvesecurity vulnerability coverageVSAvoidbackup image data volume
Core Design Contradiction:
ReliabilityVSQuantity of substance

Solution Approach 1:

The patent extracts only the essential patch level metadata from the full patch data set, storing minimal information such as file version identifiers and associated security vulnerability IDs in the backup image. The actual patch files and detailed vulnerability descriptions remain separate, allowing the backup image to contain sufficient security information without duplicating large amounts of patch data, thus minimizing the increase in backup image size.

Inventive Principle:
Principle #2Taking out (Extraction)

Solution Approach 2:

The patent creates a universal backup image structure that serves multiple functions: it stores original files for restoration, embeds patch level metadata for security assessment, and provides a framework for automatic patch application. This multi-functional approach consolidates what would otherwise require separate backup and patch management processes into a single integrated system, reducing overall data volume by eliminating redundancy.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If manual patch application is required after restore, then flexibility is maintained, but time loss increases and security vulnerabilities persist longer

Engineering Contradiction:
Improvesecurity patch applicationVSAvoidpatch application time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent implements a feedback mechanism where the backup image contains patch level data that is automatically read and processed during the restore operation. The system provides feedback about which files need patching based on the embedded metadata, and can automatically apply the appropriate patches without requiring manual intervention. This closed-loop approach eliminates the time loss associated with manual patch assessment and application while maintaining the flexibility to selective patch based on user-defined criteria.

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS8843444B2Systems and methods to determine security holes of a backup image
Publication Date: 2014.09.23 CA TECH INC
  • US8843444B2 patent drawing
  • US8843444B2 patent drawing
  • US8843444B2 patent drawing

AI summary

A system and method provide for backing up and restoring using patch level data for operating system and application files. Patch level data for the files in the backup image may be displayed along with current patch level data. Further, files in a backup image may be replaced based on current patch level data indicating a patched version of the file in the backup image is available. Further, upon a restore, if a patched file is available for a corresponding file in a backup image, the patched file may be retrieved from a patch source and used in place of the file that would have been restored from the backup image.