Container Image Deduplication for Consistent Vulnerability Detection
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Vulnerability detection and management in IT systems is challenging due to the dynamic nature of IT systems, inconsistency in scanner data output, and the complexity of managing large numbers of assets and vulnerabilities, leading to issues like false positives and false negatives.
Innovation Solution
A system and method for container image deduplication that includes obtaining and processing scanner data to identify and match container images using repository identifiers and hash fields, generating or updating records, and displaying vulnerability status through a graphical user interface, while employing tiered match rules for host matching to enhance accuracy and efficiency.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If multiple scanners are used to detect vulnerabilities across diverse IT assets, then detection coverage is improved, but data consistency and reliability deteriorate due to varying output formats and error rates
Solution Approach 1:
The patent introduces a standardized data representation layer that acts as an intermediary between multiple scanners with different output formats and the vulnerability management system. This mediator normalizes scanner outputs into a common schema, enabling consistent processing while maintaining the ability to work with diverse scanner types and asset categories.
Solution Approach 2:
The system transforms scanner outputs by changing data parameters into a standardized format. Different scanner output formats are converted into a unified data structure with consistent fields and types, allowing reliable comparison and processing across all scanners while preserving the essential detection information.
2Measurement precision
If comprehensive vulnerability scanning is performed across all assets, then detection accuracy is improved, but processing time and system complexity increase
Solution Approach 1:
The patent segments the vulnerability management process into distinct phases: asset indexing, vulnerability scanning, data normalization, deduplication, and reporting. Each phase operates independently on specific data subsets, enabling optimized processing of different asset types and vulnerability types without requiring sequential processing of all data simultaneously.
Solution Approach 2:
The system performs preliminary asset indexing and data structure preparation before actual vulnerability scanning begins. By pre-organizing asset information and scanning parameters, the system reduces processing time during the actual vulnerability detection phase while maintaining comprehensive coverage.
3Adaptability or versatility
If vulnerability data from multiple time periods is stored and analyzed, then trend analysis capability is improved, but data management complexity and storage requirements increase
Solution Approach 1:
The patent creates standardized copies of vulnerability data in a normalized format that preserves temporal information while eliminating redundant variations. This standardized copying approach enables efficient storage and comparison of historical data across time periods without the complexity of managing multiple data formats and versions.
Solution Approach 2:
The normalized data structure serves multiple functions simultaneously: it stores historical vulnerability data, enables trend analysis, supports comparison across time periods, and maintains data consistency. This universal data representation eliminates the need for separate systems for different data management tasks.
4Productivity
If scanner outputs are processed without standardization, then processing speed is maintained, but false positives and false negatives increase due to inconsistency
Solution Approach 1:
The system transforms scanner output parameters into standardized formats that enable reliable data comparison. By converting different scanner representations into a common parameter set, the system maintains processing efficiency while eliminating false positives and false negatives that would result from direct comparison of inconsistent formats.
Data Source
AI summary
Disclosed are methods, systems and non-transitory computer readable memory for container image or host deduplication in vulnerability management systems. For instance, a method may include: obtaining source data from at least one source, wherein the source data includes a plurality of assets and/or findings; extracting data bits for each asset or finding from the source data; determining a first asset or finding concerns a first container image or first host based on the data bits for the first asset or finding; in response to determining the first asset or finding concerns the first container image or first host, obtaining a container image dataset or a search structure; determining whether the data bits match any of the plurality of sets of values of the container image dataset or the search structure; and, based on a match result, generating or updating records for the first container image or the first host.


