Container Image Deduplication for Consistent Vulnerability Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Vulnerability detection and management in IT systems is challenging due to the dynamic nature of IT systems, inconsistency in scanner data output, and the complexity of managing large numbers of assets and vulnerabilities, leading to issues like false positives and false negatives.

Innovation Solution

A system and method for container image deduplication that includes obtaining and processing scanner data to identify and match container images using repository identifiers and hash fields, generating or updating records, and displaying vulnerability status through a graphical user interface, while employing tiered match rules for host matching to enhance accuracy and efficiency.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If multiple scanners are used to detect vulnerabilities across diverse IT assets, then detection coverage is improved, but data consistency and reliability deteriorate due to varying output formats and error rates

Engineering Contradiction:
Improvedetection coverageVSAvoiddata consistency
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The patent introduces a standardized data representation layer that acts as an intermediary between multiple scanners with different output formats and the vulnerability management system. This mediator normalizes scanner outputs into a common schema, enabling consistent processing while maintaining the ability to work with diverse scanner types and asset categories.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The system transforms scanner outputs by changing data parameters into a standardized format. Different scanner output formats are converted into a unified data structure with consistent fields and types, allowing reliable comparison and processing across all scanners while preserving the essential detection information.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If comprehensive vulnerability scanning is performed across all assets, then detection accuracy is improved, but processing time and system complexity increase

Engineering Contradiction:
Improvedetection accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent segments the vulnerability management process into distinct phases: asset indexing, vulnerability scanning, data normalization, deduplication, and reporting. Each phase operates independently on specific data subsets, enabling optimized processing of different asset types and vulnerability types without requiring sequential processing of all data simultaneously.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The system performs preliminary asset indexing and data structure preparation before actual vulnerability scanning begins. By pre-organizing asset information and scanning parameters, the system reduces processing time during the actual vulnerability detection phase while maintaining comprehensive coverage.

Inventive Principle:
Principle #10Preliminary action

3Adaptability or versatility

If vulnerability data from multiple time periods is stored and analyzed, then trend analysis capability is improved, but data management complexity and storage requirements increase

Engineering Contradiction:
Improvetrend analysis capabilityVSAvoiddata management complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent creates standardized copies of vulnerability data in a normalized format that preserves temporal information while eliminating redundant variations. This standardized copying approach enables efficient storage and comparison of historical data across time periods without the complexity of managing multiple data formats and versions.

Inventive Principle:
Principle #26Copying

Solution Approach 2:

The normalized data structure serves multiple functions simultaneously: it stores historical vulnerability data, enables trend analysis, supports comparison across time periods, and maintains data consistency. This universal data representation eliminates the need for separate systems for different data management tasks.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Productivity

If scanner outputs are processed without standardization, then processing speed is maintained, but false positives and false negatives increase due to inconsistency

Engineering Contradiction:
Improveprocessing speedVSAvoidfalse positive rate
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system transforms scanner output parameters into standardized formats that enable reliable data comparison. By converting different scanner representations into a common parameter set, the system maintains processing efficiency while eliminating false positives and false negatives that would result from direct comparison of inconsistent formats.

Inventive Principle:
Principle #35Parameter changes

Data Source

PatentUS20250252189A1Container Image Deduplication For Vulnerability Detection And Management In IT Systems
Publication Date: 2025.08.07 NUCLEUS SECURITY INC
  • US20250252189A1 patent drawing
  • US20250252189A1 patent drawing
  • US20250252189A1 patent drawing

AI summary

Disclosed are methods, systems and non-transitory computer readable memory for container image or host deduplication in vulnerability management systems. For instance, a method may include: obtaining source data from at least one source, wherein the source data includes a plurality of assets and/or findings; extracting data bits for each asset or finding from the source data; determining a first asset or finding concerns a first container image or first host based on the data bits for the first asset or finding; in response to determining the first asset or finding concerns the first container image or first host, obtaining a container image dataset or a search structure; determining whether the data bits match any of the plurality of sets of values of the container image dataset or the search structure; and, based on a match result, generating or updating records for the first container image or the first host.