Context-Aware Vulnerability Prioritization Using CMDB Trust Zones

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current networked computer systems face challenges in efficiently prioritizing vulnerabilities due to limited resources, as existing methods do not adequately consider the network topology and trust zones, leading to suboptimal vulnerability assessment and resource allocation.

Innovation Solution

An apparatus and method utilizing a configuration management database (CMDB) to collect and analyze configuration item records, combining external vulnerability data with trust zone data to perform vulnerability calculations and prioritize remediation actions based on contextual severity scores, taking into account network topology and protective layers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If traditional vulnerability assessment methods are used, then all vulnerabilities can be identified, but resources are inefficiently allocated due to inability to prioritize based on network context

Engineering Contradiction:
Improvevulnerability remediation efficiencyVSAvoidtime to assess and prioritize vulnerabilities
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent applies local quality by assigning different trust zone classifications to different network segments and devices. Each configuration item is evaluated within its specific trust zone context rather than using a uniform assessment approach. This allows vulnerability priority to be determined based on the local network environment, resource availability, and protective layers specific to each zone, thereby improving remediation efficiency without requiring exhaustive analysis of all vulnerabilities equally.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent segments the network into multiple trust zones with different security requirements and resource availability characteristics. By dividing the network assessment into discrete trust zone segments, the system can prioritize vulnerabilities independently in each zone based on local factors such as protective layers and resource constraints. This segmentation enables more efficient resource allocation compared to treating the entire network as a single assessment unit.

Inventive Principle:
Principle #1Segmentation

2Reliability

If comprehensive vulnerability scanning is performed across the entire network, then all security risks are identified, but resource allocation becomes suboptimal due to lack of contextual prioritization

Engineering Contradiction:
Improvesecurity risk coverageVSAvoidcomplexity of vulnerability management system
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a configuration management database (CMDB) as an intermediary that stores trust zone data, protective layer information, and resource availability data. This intermediary layer bridges the gap between raw vulnerability data and contextual prioritization needs, allowing the system to maintain comprehensive security coverage while simplifying the prioritization process through pre-stored contextual information about each trust zone and configuration item.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent performs preliminary action by pre-establishing trust zone classifications, protective layer configurations, and resource availability data in the CMDB before vulnerability assessment occurs. This preliminary structuring of network context information enables faster vulnerability prioritization during actual assessment, as the contextual framework is already in place rather than needing to be constructed during the vulnerability scanning process.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If vulnerability prioritization considers network topology and trust zones, then resource allocation improves, but calculation complexity increases

Engineering Contradiction:
Improveresource allocation efficiencyVSAvoidcalculation complexity for vulnerability scoring
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The patent applies parameter changes by transforming the vulnerability assessment from a single-dimension severity score to a multi-parameter evaluation that includes trust zone classification, protective layer presence, and resource availability. By changing the parameters used in vulnerability scoring to include these contextual factors, the system achieves better resource allocation efficiency. The complexity is managed by using standardized parameters stored in the CMDB rather than performing complex real-time calculations.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentEP3923545A1Method and apparatus for reducing security risk in a networked computer system architecture
Publication Date: 2021.12.15 SERVICENOW INC
  • EP3923545A1 patent drawingFigure 1
  • EP3923545A1 patent drawingFigure 2
  • EP3923545A1 patent drawingFigure 3A~3B

AI summary

A method may comprise: receiving, at a security computing system in a network communicatively coupled to a configuration management database, CMDB, external vulnerability data from an external source; identifying, using configuration item data stored in the CMDB and the external vulnerability data, configuration items in the network to which a respective vulnerability applies; inferring a network topology based on CMDB information; determining an original risk level for each identified configuration item based on the configuration item data stored in the CMDB and on the external vulnerability data; calculating a context dependent risk for each identified configuration item based on the respective original risk level, the network topology, and CMDB information; and prioritizing vulnerability remediation work based on the calculated context dependent risk.