Dynamic Patch Management in Virtual Desktop Infrastructure
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Conventional patch management in Virtual Desktop Infrastructure (VDI) platforms is inefficient, leading to manpower wastage, downtime, and increased vulnerability to cyberattacks due to manual intervention, lack of real-time monitoring, and inability to identify and update virtual machines promptly.
Innovation Solution
A dynamic patch management method that retrieves operational and vulnerability remediation data, detects patching gaps, calculates a patch prediction score, and executes an optimal patching plan based on industrial standards and prediction parameters to minimize downtime and ensure timely updates.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual patch management is performed by shutting down virtual machines, then patches can be installed, but service availability deteriorates and downtime increases
Solution Approach 1:
The system performs preliminary actions by identifying and prioritizing patches before shutdown is required. The patch management system analyzes patch requirements, determines priority levels, and prepares patching schedules in advance, allowing patches to be applied during planned maintenance windows rather than causing unexpected service interruptions.
Solution Approach 2:
The system implements continuous feedback loops by monitoring patch compliance status, service performance, and security vulnerability levels. This feedback enables dynamic adjustment of patching schedules and priorities, ensuring that critical security patches are applied while minimizing impact on service availability through informed decision-making.
2Reliability
If continuous monitoring and real-time patch management is implemented, then security vulnerability detection improves, but system complexity increases
Solution Approach 1:
The patch management system is designed as a multi-functional platform that combines vulnerability scanning, patch analysis, compliance tracking, and automated deployment capabilities into a single unified system. This universal approach consolidates multiple functions that would otherwise require separate tools, reducing overall system complexity while maintaining comprehensive security monitoring.
Solution Approach 2:
The system incorporates self-service capabilities through automated patch compatibility testing, risk assessment, and deployment scheduling. The patch management system autonomously evaluates patches against the virtualized environment, determines optimal deployment timing, and executes patching operations without requiring constant manual intervention, thereby reducing operational complexity.
3Reliability
If patches are applied during business hours, then security updates are timely, but work interruption and productivity loss occur
Solution Approach 1:
The system dynamically adjusts patch deployment timing based on real-time monitoring of service usage patterns, business criticality levels, and user activity. Patches are automatically scheduled for deployment during periods of lowest impact, such as off-hours or maintenance windows, while critical security patches receive priority scheduling that balances security needs with business continuity requirements.
Solution Approach 2:
The patch management system implements periodic assessment and scheduling cycles that evaluate patch priorities, service availability requirements, and business operational patterns. This periodic action enables the system to identify optimal patching windows and schedule deployments in a rhythm that maintains security compliance while minimizing disruption to business operations.
4Productivity
If drone virtual machines are used for asynchronous patch management, then service interruption is reduced, but patching time and resource overhead increase
Solution Approach 1:
The system extracts the patching operation from the production virtualized environment by utilizing isolated patching infrastructure. Drone virtual machines or separate patching servers are employed to apply patches to cloned or snapshot versions of virtual machines, thereby completely isolating patching activities from production services and eliminating service interruption while managing patching time through efficient resource allocation.
Data Source
AI summary
The present disclosure is related to Virtual Desktop Infrastructure (VDI) that discloses a method and system for performing dynamic patch management in VDI platform. A patch managing system retrieves operational data and vulnerability remediation data related to IT services and infrastructures of the VDI platform from first and second data sources. Thereafter, the patch managing system detects gap in patching level based on operational data, vulnerability remediation data and corresponding industrial standard, and rolls out patches based on detected gap in patching level. Further, a patch prediction score that facilitates in identifying a probability of rolling back the patches rolled out for patching IT services and infrastructures of VDI platform is determined based on prediction parameters. A plan is generated based on the patch prediction score and executed to optimally patch the patches to IT services and infrastructures of the VDI platform, based on patching rules.


