Centralized Vulnerability Triage for Networked Computing Devices
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Managing data security for large quantities of networked computing devices operated by different individuals and parties is cumbersome due to the complexity of structuring, prioritizing, and ensuring performance of data security tasks, especially in enterprise environments.
Innovation Solution
A centralized server system interacts with multiple third-party software applications to identify, prioritize, and notify owners of security vulnerabilities, providing a unified dashboard for security vulnerability data and generating real-time reports.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual data security management is performed for each computing device, then security tasking can be performed individually, but management complexity increases significantly as the organization grows
Solution Approach 1:
The patent combines multiple data security management functions (vulnerability scanning, classification data retrieval, vulnerability identification, ownership determination, and priority assignment) into a single automated centralized system. This merges previously separate manual tasks into one unified automated process, reducing management complexity while maintaining security reliability across all computing devices
Solution Approach 2:
The automated data security system performs multiple functions simultaneously: it scans for vulnerabilities, retrieves classification data, identifies actual vulnerabilities, determines ownership, and assigns priority levels. This multi-functional approach eliminates the need for separate manual processes for each security task, resolving the contradiction between comprehensive security coverage and management complexity
2Measurement precision
If automated vulnerability scanning is performed across all devices, then security vulnerability detection is improved, but processing time and computational resources increase
Solution Approach 1:
The system performs preliminary actions by maintaining a pre-configured database of classification data for potential security vulnerabilities. This classification data is prepared in advance and can be quickly retrieved during vulnerability scanning, enabling fast and accurate vulnerability identification without requiring extensive real-time analysis, thus improving detection accuracy while minimizing processing time
Solution Approach 2:
The patent uses classification data that serves as a template or copy of known vulnerability patterns. By comparing scan results against these pre-stored classification templates, the system can quickly identify actual vulnerabilities without performing complex real-time analysis, thereby improving detection precision while reducing the time and computational resources required
Data Source
AI summary
A method for enhancing data security for computing devices over a network is provided. The method performs an automated data security process for at least one external computing device, according to a schedule, including: performing a scan of the at least one external computing device using one or more third-party software applications; obtaining classification data for potential security vulnerabilities applicable to the at least one external computing device; identifying an actual security vulnerability, based on the scan and the classification data; accessing a first database storing organizational data associated with the potential security vulnerabilities; determining current ownership for the actual security vulnerability, based on the organizational data; and determining a priority level for the actual security vulnerability. The method also presents a dashboard including graphical elements and text associated with the actual security vulnerability, and transmits a notification or ticket to the current ownership, based on the priority level.


