Context-Aware Vulnerability Risk Scores for IHS Hardware
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Information Handling Systems (IHSs) face vulnerabilities due to varying hardware and software configurations, which can lead to security and functional issues, as administrators may unknowingly configure servers with known vulnerabilities, exacerbated by inconsistent administration practices and differing protocols.
Innovation Solution
Implementing a remote access controller that detects proposed configurations, assesses them against catalogs of known vulnerabilities, and increases a risk score if vulnerabilities are identified, disabling the hardware component until the configurations are modified to exclude vulnerabilities, using factory-provisioned identity certificates and vulnerability proofing requirements to ensure secure configurations.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Adaptability or versatility
If administrators manually configure hardware and software components of servers, then the servers can be customized and adapted to specific customer requirements, but the servers become vulnerable to known security and functional vulnerabilities due to inconsistent administration practices and lack of awareness
Solution Approach 1:
The system continuously monitors hardware component configurations and provides feedback by adjusting risk scores based on detected vulnerability conditions. When a configuration matches known vulnerability patterns, the risk score increases, triggering notifications or automated remediation actions, creating a closed-loop feedback system that prevents vulnerable configurations from being deployed
Solution Approach 2:
The system performs preliminary vulnerability assessment by checking proposed hardware configurations against known vulnerability databases before the configurations are applied to servers. This advance detection allows administrators to modify configurations before deployment, preventing vulnerabilities from being introduced in the first place
2Adaptability or versatility
If multiple administrators configure servers according to changing policies, then the servers can adapt to evolving requirements, but inconsistent configuration practices cause the servers to become increasingly vulnerable
Solution Approach 1:
The system enforces homogeneous configuration standards across all servers by evaluating each hardware component configuration against a centralized vulnerability database and standardized risk criteria. This ensures that regardless of which administrator performs the configuration, all servers are assessed using the same security baseline, eliminating inconsistencies introduced by different administration practices
Solution Approach 2:
The system provides continuous feedback to administrators about configuration compliance by monitoring and adjusting risk scores. When configurations deviate from secure baselines, the system notifies administrators and can automatically correct inconsistencies, ensuring uniform security standards across the infrastructure
3Productivity
If hardware components are updated and reconfigured throughout the server lifetime, then the servers can receive maintenance and functionality improvements, but each configuration change introduces new vulnerability risks
Solution Approach 1:
The system performs preliminary vulnerability assessment on proposed hardware configurations before maintenance updates are applied. By checking configurations against known vulnerability databases in advance, the system identifies potential security risks associated with maintenance changes, allowing administrators to review and approve only safe configuration updates
Solution Approach 2:
The system continuously monitors configuration changes during maintenance operations and adjusts risk scores in real-time. This feedback mechanism detects when maintenance activities introduce vulnerable configurations and triggers immediate remediation, ensuring that productivity-generating maintenance operations do not compromise security
Data Source
AI summary
Systems and methods are provided for vulnerability proofing the use of risk scores in the administration of hardware components of an IHS (Information Handling System). Proposed configurations for a first of the hardware components of the IHS are detected, where the proposed configurations are associated with a risk score. Catalogs specifying known vulnerabilities of hardware components are accessed and used to determine whether any of the proposed configurations of the first hardware component are identified as vulnerable in one or more of the catalogs. When a vulnerability for the proposed configuration is identified in the catalogs, the risk score of the configuration is increased based on the vulnerabilities identified in the plurality of catalogs. When the risk score is increased to an elevated level, the hardware component is disabled until the proposed configurations are changed to include no configurations with vulnerabilities identified in the catalogs.


