Connected Device Vulnerability Scoring via Contextual Weighting
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current vulnerability management systems for connected devices in enterprise environments, such as medical and industrial devices, fail to adequately account for device-specific exploit factors and context, leading to inadequate risk assessment and mitigation.
Innovation Solution
A system and method that calculates vulnerability scores by equally weighting impact and exploitability metrics, considering device configuration, environmental factors, and topology, to predict security incidents and recommend remediation measures, with the ability to automatically mitigate risks and notify users.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If existing vulnerability scoring mechanisms weight impact metrics more heavily for connected devices, then security risk assessment becomes more conservative, but exploitability factors and device context are inadequately accounted for
Solution Approach 1:
The patent applies local quality by introducing device-specific contextual factors (device type, network topology, configuration) that modify the general vulnerability scoring approach. Different device types receive different weighting of exploitability vs impact metrics based on their specific characteristics, rather than applying a uniform scoring method to all connected devices.
Solution Approach 2:
The system dynamically changes scoring parameters based on device context. The weighting between impact and exploitability metrics is adjusted according to device type and network position, allowing the vulnerability assessment to adapt to local conditions rather than using fixed parameters for all devices.
2Reliability
If vulnerability assessment considers device configuration and topology context, then risk prediction improves, but computational complexity increases
Solution Approach 1:
The patent segments the vulnerability assessment into distinct components: base vulnerability scoring, device context evaluation, and risk calculation. Each component processes specific aspects independently, then integrates results to produce the final risk assessment, reducing overall system complexity through modular design.
Solution Approach 2:
The system performs preliminary actions by pre-establishing device profiles and context parameters before vulnerability assessment. Device metadata, network topology information, and configuration details are collected and structured in advance, enabling faster and simpler real-time vulnerability scoring without repeating complex data gathering during assessment.
3Measurement precision
If equal weighting is applied to impact and exploitability metrics, then connected device risk assessment becomes more accurate, but general computing system assessment may become less optimal
Solution Approach 1:
The patent implements dynamic weighting that adapts based on device type. For connected devices (IoT, industrial, medical), the system applies equal or adjusted weighting to exploitability and impact metrics. For traditional computing systems, conventional weighting schemes are used. This dynamic adaptation allows the same scoring system to optimize for different device categories.
Solution Approach 2:
The vulnerability scoring system is designed to be universal across multiple device types while allowing configuration-specific optimizations. The core scoring framework remains consistent, but weighting parameters and contextual factors are adjusted based on whether the target is a connected device, traditional computer, server, or other system type.
Data Source
AI summary
Embodiments herein provide a system, method and an apparatus for vulnerability management for connected devices on a network. The proposed method includes identifying vulnerability in a device. The method includes determining whether the vulnerability affects the device by applying one or more rules. Further, the method includes calculating vulnerability score by assigning weights to impact metric and exploitability metric. In various embodiments, the method includes predicting security incident for the device based on the computed vulnerability score, security capabilities of the device and various anomalies on the device.


