CPE Configuration Converter for Automated Vulnerability Detection

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The complexity of the Common Platform Enumeration (CPE) format makes it difficult and costly to manually create and manage vulnerability information for products, hindering effective vulnerability monitoring systems that compare product configurations with publicly disclosed vulnerabilities.

Innovation Solution

An information processing apparatus that includes a configuration information converter to transform first configuration information into a standardized CPE format, utilizing vulnerability information from specific and versatile servers to identify and convert software identifiers, enabling efficient detection of vulnerabilities across diverse devices.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual creation of CPE configuration information is performed, then vulnerability monitoring accuracy is improved, but time consumption and costs increase

Engineering Contradiction:
Improvevulnerability monitoring accuracyVSAvoidtime consumption
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system automatically retrieves configuration information from the target device and converts it to CPE format without requiring manual intervention. The converter autonomously performs the transformation process by obtaining device configuration, extracting software identifiers, and generating standardized CPE strings, thereby eliminating the need for manual CPE creation while maintaining high accuracy in vulnerability monitoring.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the manual mechanical process of creating CPE configuration information with an automated information processing system. The converter uses automated tools and algorithms to transform device configuration data into standardized CPE format, substituting human labor with computational processes that are both faster and more consistent.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Measurement precision

If manual creation of CPE configuration information is performed, then vulnerability monitoring accuracy is improved, but costs increase

Engineering Contradiction:
Improvevulnerability monitoring accuracyVSAvoidcreation costs
Core Design Contradiction:
Measurement precisionVSEase of manufacture

Solution Approach 1:

The system performs self-service by automatically obtaining device configuration information and converting it to CPE format without requiring manual expertise or labor. This automation eliminates the need for specialized personnel to manually create CPE strings, thereby reducing both time consumption and operational costs while maintaining high accuracy in vulnerability identification.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent substitutes the manual mechanical process of CPE creation with an automated information processing system. The converter uses computational algorithms to transform raw device configuration data into standardized CPE format, replacing human labor with cost-effective automated processing that maintains or improves accuracy while significantly reducing creation costs.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Adaptability or versatility

If CPE format is used for configuration information, then vulnerability comparison capability is improved, but device complexity increases

Engineering Contradiction:
Improvevulnerability comparison capabilityVSAvoidformat complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The converter acts as an intermediary between the target device and the vulnerability monitoring system. It automatically retrieves configuration information from the device, transforms it into standardized CPE format, and provides it to the vulnerability monitoring system. This intermediary process handles the complexity of CPE format conversion, allowing the vulnerability comparison capability to be enhanced without requiring the target device itself to become more complex.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The converter extracts the necessary configuration information from the target device and separates it from the device's operational complexity. By pulling out only the relevant configuration data and transforming it into standardized CPE format, the system enables comprehensive vulnerability comparison capability while keeping the target device's complexity unchanged.

Inventive Principle:
Principle #2Taking out (Extraction)

Data Source

PatentUS20240070290A1Information processing apparatus, information processing method and system
Publication Date: 2024.02.29 KK TOSHIBA
  • US20240070290A1 patent drawing
  • US20240070290A1 patent drawing
  • US20240070290A1 patent drawing

AI summary

An information processing apparatus according to one embodiment, comprising: a first vulnerability information obtainer configured to obtain, from a first server, first vulnerability information; a second vulnerability information obtainer configured to obtain, from a second server, second vulnerability information; a first configuration information obtainer configured to obtain first configuration information included in the target device; a scanner configured to detect a first identifier, from the first vulnerability information, based on the first configuration information, and identify the vulnerability identifier associated with the detected first identifier; a searcher configured to identify a second identifier that is associated with the vulnerability identifier identified, and includes a name of software identical to the name of the target software, based on the second vulnerability information; and an output processor configured to generate a third identifier by replacing the version included in the second identifier identified with the version of the target software.