Centralized Vulnerability Triage for Networked Computing Devices

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Managing data security for large quantities of networked computing devices operated by different individuals and parties is cumbersome due to the complexity of structuring, prioritizing, and ensuring performance of data security tasks, especially in enterprise environments.

Innovation Solution

A centralized server system interacts with multiple third-party software applications to identify, prioritize, and notify owners of security vulnerabilities, providing a unified dashboard for security vulnerability data and generating real-time reports.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual data security management is performed for each computing device, then security tasking can be performed individually, but management complexity increases significantly as the organization grows

Engineering Contradiction:
Improvedata securityVSAvoidmanagement complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple data security management functions (vulnerability scanning, classification data retrieval, vulnerability identification, ownership determination, and priority assignment) into a single automated centralized system. This merges previously separate manual tasks into one unified automated process, reducing management complexity while maintaining security reliability across all computing devices

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The automated data security system performs multiple functions simultaneously: it scans for vulnerabilities, retrieves classification data, identifies actual vulnerabilities, determines ownership, and assigns priority levels. This multi-functional approach eliminates the need for separate manual processes for each security task, resolving the contradiction between comprehensive security coverage and management complexity

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Measurement precision

If automated vulnerability scanning is performed across all devices, then security vulnerability detection is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvevulnerability detection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by maintaining a pre-configured database of classification data for potential security vulnerabilities. This classification data is prepared in advance and can be quickly retrieved during vulnerability scanning, enabling fast and accurate vulnerability identification without requiring extensive real-time analysis, thus improving detection accuracy while minimizing processing time

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent uses classification data that serves as a template or copy of known vulnerability patterns. By comparing scan results against these pre-stored classification templates, the system can quickly identify actual vulnerabilities without performing complex real-time analysis, thereby improving detection precision while reducing the time and computational resources required

Inventive Principle:
Principle #26Copying

Data Source

PatentUS20250272408A1Methods, systems, and apparatus for enhancing data security for computing devices over a network
Publication Date: 2025.08.28 EVERNORTH STRATEGIC DEVELOPMENT INC
  • US20250272408A1 patent drawing
  • US20250272408A1 patent drawing
  • US20250272408A1 patent drawing

AI summary

A method for enhancing data security for computing devices over a network is provided. The method performs an automated data security process for at least one external computing device, according to a schedule, including: performing a scan of the at least one external computing device using one or more third-party software applications; obtaining classification data for potential security vulnerabilities applicable to the at least one external computing device; identifying an actual security vulnerability, based on the scan and the classification data; accessing a first database storing organizational data associated with the potential security vulnerabilities; determining current ownership for the actual security vulnerability, based on the organizational data; and determining a priority level for the actual security vulnerability. The method also presents a dashboard including graphical elements and text associated with the actual security vulnerability, and transmits a notification or ticket to the current ownership, based on the priority level.