Condensing Security Solution Sets for Enterprise Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current security management systems face challenges in efficiently assessing and mitigating software vulnerabilities across dynamic and diverse enterprise networks, particularly due to the manual and subjective nature of threat ranking and the complexity introduced by virtualization, cloud, and DevOps environments.

Innovation Solution

A security auditing component that condenses a solution set for security issues by combining related solutions and filtering out redundant or superseded ones using rules, asset-specific metadata, and static metadata, thereby streamlining the remediation process.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If a comprehensive solution set is generated to address all security issues, then coverage of security vulnerabilities is improved, but the complexity of managing and applying solutions increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidsolution management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent combines multiple related solutions into consolidated solution sets. When multiple security issues share common remediation steps or affect the same asset, the system merges these solutions to reduce redundancy. This allows comprehensive security coverage to be maintained while reducing the overall number of discrete solutions that security teams must manage and apply.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If all identified solutions are applied to mitigate security issues, then security resilience is improved, but the workload for security teams increases

Engineering Contradiction:
Improvesecurity resilienceVSAvoidremediation efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system extracts and identifies redundant or superseded solutions from the complete solution set. By analyzing relationships between solutions and determining which ones are duplicates or have been rendered obsolete by more effective remedies, the system removes these unnecessary solutions. This extraction process reduces the workload for security teams while preserving the essential remediation actions needed to maintain security resilience.

Inventive Principle:
Principle #2Taking out (Extraction)

3Adaptability or versatility

If manual threat ranking is used to prioritize vulnerabilities, then resource allocation flexibility is improved, but the time required for assessment increases

Engineering Contradiction:
Improveresource allocation flexibilityVSAvoidassessment time
Core Design Contradiction:
Adaptability or versatilityVSLoss of time

Solution Approach 1:

The system performs preliminary automated assessment and initial ranking of vulnerabilities based on established criteria before human reviewers finalize the prioritization. This preliminary action pre-processes the vulnerability data, performs initial threat evaluation, and prepares draft rankings, thereby reducing the time required for manual assessment while allowing security teams to maintain flexibility in making final resource allocation decisions.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11621974B2Managing supersedence of solutions for security issues among assets of an enterprise network
Publication Date: 2023.04.04 TENABLE INC
  • US11621974B2 patent drawing
  • US11621974B2 patent drawing
  • US11621974B2 patent drawing

AI summary

In an embodiment, a security auditing component obtains a solution set that is based upon a security audit of an enterprise network, the solution set characterizing a set of solutions associated with a set of security issues associated with one or more assets of the enterprise network, detects that the solution set can be condensed into a condensed solution set that mitigates the set of security issues to the same degree as the solution set, the detection being based at least in part upon (i) one or more rules applied to one or more solution texts and/or (ii) asset-specific metadata and/or (iii) static metadata, and condenses, based on the detecting, the solution set into the condensed solution set by combining two or more subsets of related solutions and/or filtering the solution set to remove one or more subsets of redundant or superseded solutions.