Customized Vulnerability Scoring for Distributed Systems

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current cybersecurity solutions fail to effectively bridge the gap between vulnerability and weakness abstraction levels, leading to generalized security assessments that are not tailored to specific systems, resulting in inefficient security measurements and increased exposure to cyber threats.

Innovation Solution

A method for prioritized remediation of security weaknesses in distributed systems, which involves obtaining cybersecurity data, customizing metrics based on user-input variables, and calculating a likelihood of exploitation and exposure factor for each vulnerability, allowing for a customized ranking and targeted remediation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If standardized vulnerability scoring systems (e.g., CVSS) are used to assess security weaknesses, then a unified scoring method is provided, but the scores are generic and do not reflect the specific needs or context of individual distributed systems

Engineering Contradiction:
Improveadaptability to specific system needsVSAvoidprecision of security assessment
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The system enables dynamic customization of vulnerability scoring by allowing users to select and weight different vulnerability characteristics (e.g., exploitability, impact, prevalence) based on their specific system context. This transforms the static, fixed scoring system into a dynamic one that adapts to different organizational needs and threat landscapes, resolving the contradiction between standardization and adaptability.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The invention applies local quality by allowing each distributed system to customize its vulnerability assessment metrics according to its specific architecture, critical assets, and risk tolerance. Instead of a uniform scoring approach, the system enables localized tailoring of assessment criteria to match the unique security priorities of each system, thereby improving measurement precision for specific contexts.

Inventive Principle:
Principle #3Local quality

2Quantity of substance

If multiple vulnerability scanning tools are deployed to comprehensively identify weaknesses, then coverage of vulnerability detection is improved, but the volume of scanning reports becomes voluminous and difficult to analyze

Engineering Contradiction:
Improvecompleteness of vulnerability identificationVSAvoidcomplexity of security assessment
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The system merges the outputs of multiple vulnerability scanning tools by consolidating their findings into a unified vulnerability database. It integrates data from various sources (network scanners, application scanners, configuration checkers) and combines them with contextual information from the distributed system architecture, thereby reducing the complexity of analyzing multiple separate reports while maintaining comprehensive coverage.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The vulnerability assessment system is designed with multi-functionality to handle diverse scanning results and contextual data uniformly. It provides a universal framework for processing different types of vulnerability information, ranking them based on customized criteria, and presenting prioritized remediation recommendations, thus simplifying the analysis of voluminous scanning reports.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Ease of manufacture

If existing vulnerability ranking systems are used, then a baseline security assessment is provided, but they rely on predefined risk notions and fixed equations that cannot be fine-tuned for specific systems

Engineering Contradiction:
Improveease of security assessmentVSAvoidflexibility in risk assessment
Core Design Contradiction:
Ease of manufactureVSAdaptability or versatility

Solution Approach 1:

The system replaces fixed, static risk assessment equations with a dynamic, configurable framework. Users can dynamically adjust the weights and thresholds of vulnerability characteristics based on their specific organizational policies and risk tolerance levels. This enables the system to maintain ease of use while providing the flexibility to adapt to different risk management strategies and system contexts.

Inventive Principle:
Principle #15Dynamics

Data Source

PatentUS20240396930A1System and method for scoring and ranking common weaknesses mapped to vulnerabilities found in networked and/or distributed systems
Publication Date: 2024.11.28 GEORGE MASON UNIVERSITY
  • US20240396930A1 patent drawing
  • US20240396930A1 patent drawing
  • US20240396930A1 patent drawing

AI summary

A method of performing prioritized remediation for a distributed system includes: obtaining cyber security; outputting a standard security weakness ranking based on the cyber security data; determining that one or more vulnerabilities exist in one or more system components of the distributed system based on the standard security weakness ranking; customizing metrics for calculating an exploitation likelihood and an exposure factor associated with a vulnerability based on a user input including at least one variable influencing the likelihood or the exposure factor and capturing a specific applicative domain of each vulnerability, priorities of the system, types of potential attackers; calculating the customized metrics; outputting a customized ranking of the one or more vulnerabilities based on the calculation; and performing a prioritized remediation of a target vulnerability selected by the user based on the customized ranking and specific needs and resources of the system.