Connected Device Vulnerability Scoring via Contextual Weighting

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current vulnerability management systems for connected devices in enterprise environments, such as medical and industrial devices, fail to adequately account for device-specific exploit factors and context, leading to inadequate risk assessment and mitigation.

Innovation Solution

A system and method that calculates vulnerability scores by equally weighting impact and exploitability metrics, considering device configuration, environmental factors, and topology, to predict security incidents and recommend remediation measures, with the ability to automatically mitigate risks and notify users.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If existing vulnerability scoring mechanisms weight impact metrics more heavily for connected devices, then security risk assessment becomes more conservative, but exploitability factors and device context are inadequately accounted for

Engineering Contradiction:
Improvevulnerability score accuracyVSAvoiddevice context consideration
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent applies local quality by introducing device-specific contextual factors (device type, network topology, configuration) that modify the general vulnerability scoring approach. Different device types receive different weighting of exploitability vs impact metrics based on their specific characteristics, rather than applying a uniform scoring method to all connected devices.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system dynamically changes scoring parameters based on device context. The weighting between impact and exploitability metrics is adjusted according to device type and network position, allowing the vulnerability assessment to adapt to local conditions rather than using fixed parameters for all devices.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If vulnerability assessment considers device configuration and topology context, then risk prediction improves, but computational complexity increases

Engineering Contradiction:
Improvesecurity incident predictionVSAvoidassessment system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent segments the vulnerability assessment into distinct components: base vulnerability scoring, device context evaluation, and risk calculation. Each component processes specific aspects independently, then integrates results to produce the final risk assessment, reducing overall system complexity through modular design.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary actions by pre-establishing device profiles and context parameters before vulnerability assessment. Device metadata, network topology information, and configuration details are collected and structured in advance, enabling faster and simpler real-time vulnerability scoring without repeating complex data gathering during assessment.

Inventive Principle:
Principle #10Preliminary action

3Measurement precision

If equal weighting is applied to impact and exploitability metrics, then connected device risk assessment becomes more accurate, but general computing system assessment may become less optimal

Engineering Contradiction:
Improveconnected device vulnerability scoringVSAvoidscoring system flexibility
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The patent implements dynamic weighting that adapts based on device type. For connected devices (IoT, industrial, medical), the system applies equal or adjusted weighting to exploitability and impact metrics. For traditional computing systems, conventional weighting schemes are used. This dynamic adaptation allows the same scoring system to optimize for different device categories.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The vulnerability scoring system is designed to be universal across multiple device types while allowing configuration-specific optimizations. The core scoring framework remains consistent, but weighting parameters and contextual factors are adjusted based on whether the target is a connected device, traditional computer, server, or other system type.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Data Source

PatentUS11522899B2System and method for vulnerability management for connected devices
Publication Date: 2022.12.06 ASIMILY INC
  • US11522899B2 patent drawing
  • US11522899B2 patent drawing
  • US11522899B2 patent drawing

AI summary

Embodiments herein provide a system, method and an apparatus for vulnerability management for connected devices on a network. The proposed method includes identifying vulnerability in a device. The method includes determining whether the vulnerability affects the device by applying one or more rules. Further, the method includes calculating vulnerability score by assigning weights to impact metric and exploitability metric. In various embodiments, the method includes predicting security incident for the device based on the computed vulnerability score, security capabilities of the device and various anomalies on the device.