Context-Aware Vulnerability Risk Scores for IHS Hardware

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Information Handling Systems (IHSs) face vulnerabilities due to varying hardware and software configurations, which can lead to security and functional issues, as administrators may unknowingly configure servers with known vulnerabilities, exacerbated by inconsistent administration practices and differing protocols.

Innovation Solution

Implementing a remote access controller that detects proposed configurations, assesses them against catalogs of known vulnerabilities, and increases a risk score if vulnerabilities are identified, disabling the hardware component until the configurations are modified to exclude vulnerabilities, using factory-provisioned identity certificates and vulnerability proofing requirements to ensure secure configurations.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If administrators manually configure hardware and software components of servers, then the servers can be customized and adapted to specific customer requirements, but the servers become vulnerable to known security and functional vulnerabilities due to inconsistent administration practices and lack of awareness

Engineering Contradiction:
Improveconfiguration flexibilityVSAvoidvulnerability risk
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system continuously monitors hardware component configurations and provides feedback by adjusting risk scores based on detected vulnerability conditions. When a configuration matches known vulnerability patterns, the risk score increases, triggering notifications or automated remediation actions, creating a closed-loop feedback system that prevents vulnerable configurations from being deployed

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system performs preliminary vulnerability assessment by checking proposed hardware configurations against known vulnerability databases before the configurations are applied to servers. This advance detection allows administrators to modify configurations before deployment, preventing vulnerabilities from being introduced in the first place

Inventive Principle:
Principle #10Preliminary action

2Adaptability or versatility

If multiple administrators configure servers according to changing policies, then the servers can adapt to evolving requirements, but inconsistent configuration practices cause the servers to become increasingly vulnerable

Engineering Contradiction:
Improvepolicy adaptabilityVSAvoidconfiguration consistency
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system enforces homogeneous configuration standards across all servers by evaluating each hardware component configuration against a centralized vulnerability database and standardized risk criteria. This ensures that regardless of which administrator performs the configuration, all servers are assessed using the same security baseline, eliminating inconsistencies introduced by different administration practices

Inventive Principle:
Principle #33Homogeneity

Solution Approach 2:

The system provides continuous feedback to administrators about configuration compliance by monitoring and adjusting risk scores. When configurations deviate from secure baselines, the system notifies administrators and can automatically correct inconsistencies, ensuring uniform security standards across the infrastructure

Inventive Principle:
Principle #23Feedback

3Productivity

If hardware components are updated and reconfigured throughout the server lifetime, then the servers can receive maintenance and functionality improvements, but each configuration change introduces new vulnerability risks

Engineering Contradiction:
Improvemaintenance efficiencyVSAvoidvulnerability exposure
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary vulnerability assessment on proposed hardware configurations before maintenance updates are applied. By checking configurations against known vulnerability databases in advance, the system identifies potential security risks associated with maintenance changes, allowing administrators to review and approve only safe configuration updates

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system continuously monitors configuration changes during maintenance operations and adjusts risk scores in real-time. This feedback mechanism detects when maintenance activities introduce vulnerable configurations and triggers immediate remediation, ensuring that productivity-generating maintenance operations do not compromise security

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS12141294B2Systems and methods for context-aware vulnerability risk scores
Publication Date: 2024.11.12 DELL PROD LP
  • US12141294B2 patent drawing
  • US12141294B2 patent drawing
  • US12141294B2 patent drawing

AI summary

Systems and methods are provided for vulnerability proofing the use of risk scores in the administration of hardware components of an IHS (Information Handling System). Proposed configurations for a first of the hardware components of the IHS are detected, where the proposed configurations are associated with a risk score. Catalogs specifying known vulnerabilities of hardware components are accessed and used to determine whether any of the proposed configurations of the first hardware component are identified as vulnerable in one or more of the catalogs. When a vulnerability for the proposed configuration is identified in the catalogs, the risk score of the configuration is increased based on the vulnerabilities identified in the plurality of catalogs. When the risk score is increased to an elevated level, the hardware component is disabled until the proposed configurations are changed to include no configurations with vulnerabilities identified in the catalogs.