Cognitive Security Vulnerability Analysis Engine

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security measures are inadequate in identifying and prioritizing security vulnerabilities in enterprise computing systems, leading to delayed responses and inefficient resource allocation due to the time-consuming nature of staying informed about the latest hacking attempts and the lack of awareness about vulnerabilities across the enterprise infrastructure.

Innovation Solution

A cognitive security vulnerability analysis engine that performs trend analysis on external and internal data sources, utilizing natural language processing and machine learning to identify and rank security vulnerabilities based on their criticality and potential impact, generating a prioritized listing and automatic or semi-automatic responses to mitigate risks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual security monitoring and analysis is performed, then security experts can identify vulnerabilities, but the process is time-consuming and delays response time

Engineering Contradiction:
Improvevulnerability identification accuracyVSAvoidresponse time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent replaces manual mechanical analysis with automated machine learning models and natural language processing systems. The cognitive system automatically ingests security content, performs trend analysis, and generates vulnerability assessments without human intervention, thereby eliminating the time delay inherent in manual processes while maintaining or improving identification accuracy through algorithmic precision.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent introduces a cognitive system as an intermediary between security data sources and decision-makers. This intermediary automatically processes vast amounts of security content, performs trend analysis, and generates prioritized vulnerability listings, acting as a bridge that accelerates information flow and reduces the time gap between vulnerability discovery and response initiation.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Reliability

If comprehensive security monitoring is implemented across the enterprise, then all vulnerabilities can be identified, but the complexity of managing and analyzing data increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent creates a universal cognitive system that performs multiple security functions through a single platform. The system simultaneously ingests content from diverse sources, performs trend analysis, identifies vulnerabilities, prioritizes risks, and generates responses across the entire enterprise infrastructure, thereby achieving comprehensive security coverage without proportionally increasing system complexity.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent transforms unstructured security data into structured, prioritized information through automated parameter extraction and analysis. By changing the state of data from raw, unprocessed content to structured vulnerability assessments with priority ratings, the system manages comprehensive security monitoring without overwhelming complexity in data handling and analysis.

Inventive Principle:
Principle #35Parameter changes

3Productivity

If security vulnerabilities are prioritized based on criticality, then resource allocation is optimized, but the analysis required to determine criticality increases processing time

Engineering Contradiction:
Improveresource allocation efficiencyVSAvoidanalysis time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent performs preliminary automated analysis of security vulnerabilities, pre-calculating criticality scores and prioritization rankings before resources need to be allocated. The cognitive system proactively processes security data, identifies vulnerabilities, and generates prioritized listings in advance, eliminating the need for time-consuming analysis at the moment resource allocation decisions must be made.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces manual criticality assessment with automated machine learning algorithms that rapidly evaluate vulnerability severity, exploitability, and business impact. These algorithms process multiple parameters simultaneously and generate prioritized rankings instantaneously, achieving both optimized resource allocation and rapid analysis that manual processes cannot deliver.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10771493B2Cognitive security exposure analysis and resolution based on security trends
Publication Date: 2020.09.08 INTERNATIONAL BUSINESS MACHINE CORPORATION
  • US10771493B2 patent drawing
  • US10771493B2 patent drawing
  • US10771493B2 patent drawing

AI summary

A security vulnerability analysis mechanism is provided that ingests content from a plurality of content source computing devices to identify instances of security vulnerability content in the ingested content. The mechanism performs a security trend analysis on the instances of security vulnerability content to identify a relative ranking of security vulnerabilities. The mechanism identifies computing resources of a specified computing infrastructure and a criticality of the computing resources to an operation of the computing infrastructure. The mechanism generates a prioritized listing of security vulnerabilities associated with the computing infrastructure based on the relative ranking of security vulnerabilities and the criticality of the computing resources in the computing infrastructure. The mechanism outputs a notification to a user via a user computing device, indicating the prioritized listing of security vulnerabilities.