Container Vulnerability Prioritization via Impact and Access Frequency
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
In application execution platforms using container technology, vulnerabilities in multiple containers often lead to delayed security updates due to lack of free resources, posing a risk of security incidents.
Innovation Solution
A vulnerability management system that calculates an impact factor and access frequency factor for each container, determining a weighting determination value to prioritize security measures, and schedules updates accordingly to efficiently resolve vulnerabilities.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If security updates are performed for multiple containers with vulnerabilities, then security reliability is improved, but resource availability deteriorates due to lack of free resources
Solution Approach 1:
The patent segments the security update process by dividing containers into multiple priority groups based on vulnerability impact factors. Instead of updating all containers simultaneously or using a simple first-come-first-served approach, the system performs segmented updates where high-priority containers are updated first, followed by medium-priority, and then low-priority containers. This segmentation allows efficient resource utilization while maintaining security reliability.
Solution Approach 2:
The patent introduces parameter changes by calculating impact factors based on multiple variables including vulnerability severity, container importance, and resource availability. The system dynamically adjusts update priorities by changing these parameters, allowing flexible resource allocation that adapts to current system conditions while ensuring critical security updates are performed first.
2Quantity of substance
If security updates are delayed due to resource constraints and manual scheduling, then resource availability is preserved, but time consumption increases leading to security incidents
Solution Approach 1:
The patent implements self-service by enabling the system to automatically calculate impact factors, determine update priorities, and schedule security updates without manual administrator intervention. The automated scheduling system continuously monitors container vulnerabilities and resources, then autonomously performs updates in the optimal sequence, eliminating delays caused by manual scheduling while preserving resource availability.
Solution Approach 2:
The patent applies preliminary action by pre-calculating and storing impact factors for each container based on their vulnerability profiles and operational characteristics. When security updates are needed, the system retrieves these pre-calculated values and immediately executes updates according to the predetermined priority order, significantly reducing the time from vulnerability detection to patch deployment.
3Reliability
If all containers are updated simultaneously, then security reliability is improved, but productivity deteriorates due to resource exhaustion
Solution Approach 1:
The patent applies dynamics by making the update schedule flexible and adaptive rather than static. The system dynamically adjusts the update sequence based on real-time impact factor calculations, resource availability, and container operational status. This dynamic approach allows the system to maintain high security reliability while optimizing productivity by updating containers at times and in sequences that minimize resource exhaustion.
Solution Approach 2:
The patent segments the container update process into multiple batches based on calculated impact factors. Instead of simultaneous updates that exhaust resources, the system divides containers into priority groups and updates them in sequential batches. This segmentation maintains security reliability by ensuring all containers are eventually updated while improving productivity by preventing resource exhaustion through controlled, staged updates.
Data Source
AI summary
A vulnerability management system calculates an impact factor based on vulnerability information, which indicates a magnitude of an impact of a vulnerability of a container in an application execution system on the application execution system. The vulnerability information is information in which the vulnerability and an evaluation value thereof are associated with each other. An access frequency factor is calculated based on access frequency information, the access frequency factor being an evaluation value of a vulnerability deriving from a form of communication performed by the container. The access frequency information is related to a transmission or reception range and a transmission or reception frequency of data of the container. A weighting determination value is calculated based on the impact factor and the access frequency factor, the weighting determination value indicating a priority of a measure against the vulnerability of the container; and the order of measures is determined.


