Dynamic Vulnerability Management for Cloud Infrastructure

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current vulnerability management approaches in cloud-based infrastructures are inadequate for proactive and comprehensive security, as they lack the ability to dynamically track and control numerous vulnerabilities, leading to reactive and resource-intensive remediation efforts, especially in sensitive data environments like financial data processing.

Innovation Solution

A method and system for dynamic and comprehensive vulnerability management that involves obtaining and processing vulnerability management data, generating scanner data, and applying relevant scanner tests and remedies to identify and mitigate vulnerabilities proactively, with a focus on self-healing processes and automated remediation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If comprehensive vulnerability scanning and management is implemented across all cloud assets, then security coverage and vulnerability detection capability are improved, but system complexity and resource requirements increase significantly

Engineering Contradiction:
Improvesecurity coverageVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The vulnerability management system is segmented into multiple independent components: vulnerability scanners, asset management modules, remediation systems, and reporting tools. Each component handles specific tasks independently, allowing the system to scale without proportionally increasing overall complexity. The segmentation enables modular deployment where organizations can activate only the components needed for their specific security requirements.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The vulnerability management system is designed with universal components that can handle multiple asset types (cloud infrastructure, applications, data) through standardized interfaces and protocols. The scanner can adapt to different cloud environments (AWS, Azure, Google Cloud) without requiring separate specialized tools, reducing system complexity while maintaining comprehensive security coverage across diverse assets.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If proactive vulnerability identification and remediation are implemented before deployment, then security against attacks is improved, but development time and resource requirements increase

Engineering Contradiction:
Improvesecurity against attacksVSAvoiddevelopment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs vulnerability scanning and security assessment during the development phase, before applications are deployed to production environments. By identifying and remediating vulnerabilities in advance, the system prevents security issues from reaching production, thereby improving security without requiring additional remediation time after deployment. The preliminary action is integrated into the CI/CD pipeline to minimize impact on development workflows.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The vulnerability management system provides automated feedback to developers through integrated reporting tools that deliver security findings directly to development teams in real-time. This immediate feedback loop enables developers to address vulnerabilities during the development process rather than during separate security audits, reducing overall development time while maintaining high security standards through continuous monitoring and rapid response.

Inventive Principle:
Principle #23Feedback

3Productivity

If automated vulnerability scanning and remediation systems are deployed, then resource requirements for manual security management are reduced, but initial implementation costs and system complexity increase

Engineering Contradiction:
Improveefficiency of vulnerability managementVSAvoidimplementation complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The vulnerability management system incorporates automated self-service capabilities including self-provisioning of scanners, automatic asset discovery and classification, and automated remediation execution. The system can autonomously manage its own operations without requiring extensive manual configuration or ongoing administrative overhead, thereby improving productivity while reducing the complexity burden on security teams. The automated orchestration handles scanner deployment, vulnerability assessment, and remediation application without human intervention.

Inventive Principle:
Principle #25Self-service

4Adaptability or versatility

If continuous monitoring and dynamic policy adjustment are implemented, then adaptability to new threats is improved, but computational resources and processing requirements increase

Engineering Contradiction:
Improveadaptability to new threatsVSAvoidcomputational resources
Core Design Contradiction:
Adaptability or versatilityVSUse of energy by moving object

Solution Approach 1:

The system implements periodic vulnerability scanning and policy evaluation cycles rather than continuous monitoring, strategically scheduled to balance security needs with resource consumption. Scanning frequency and policy update intervals are dynamically adjusted based on risk levels, asset criticality, and threat intelligence, allowing the system to maintain high adaptability to new threats while optimizing computational resource usage by reducing unnecessary processing during low-risk periods.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentEP3036645B1Method and system for dynamic and comprehensive vulnerability management
Publication Date: 2020.02.26 INTUIT INC
  • EP3036645B1 patent drawingFigure 1
  • EP3036645B1 patent drawingFigure 2A
  • EP3036645B1 patent drawingFigure 2B

AI summary

One or more relevant scanners used to identify asset vulnerabilities are identified, obtained, and logically arranged for deployment on an asset in accordance with a vulnerability management policy and a scanner deployment policy such that the relevant scanners are deployed at, or before, a determined ideal time to minimize the resources necessary to correct the vulnerabilities, if found. The relevant scanners are then automatically deployed in accordance with the scanner deployment policy and, if a vulnerability is identified, one or more associated remedies or remedy procedures are applied to the asset. At least one of the one or more relevant scanners are then re-deployed on the asset to determine if the identified vulnerability has been corrected and, if the vulnerability is not corrected at, or before, a defined time, protective measures are automatically taken.