Dynamic Vulnerability Scoring With Contextual Priority Updates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing vulnerability scoring systems rely heavily on manual input and review by security experts, requiring significant human intervention and lacking dynamic, automated methods to account for contextual and temporal factors, leading to inefficiencies in vulnerability prioritization.

Innovation Solution

A contextual vulnerability prioritization engine (CVP engine) that continuously scans internal and external databases for new vulnerabilities, utilizes machine learning models to generate contextual prioritization scores (CPS) based on historical and contextual features, and updates scores dynamically in response to events, enabling automated and context-aware vulnerability prioritization.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manual input and review by security experts is used for vulnerability scoring, then scoring accuracy can be maintained, but significant human intervention and time are required

Engineering Contradiction:
Improvevulnerability scoring accuracyVSAvoidtime for manual review
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system enables automated vulnerability scoring where the computational system performs scoring operations autonomously without requiring human intervention. The engine automatically processes vulnerability data, applies scoring algorithms, and generates priority rankings, allowing the system to serve itself in the scoring process while maintaining consistency and speed.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent replaces the manual mechanical process of expert review with an automated computational engine. Machine learning models and algorithms substitute for human analysts, performing vulnerability assessment and scoring through automated data processing, pattern recognition, and computational analysis rather than manual examination.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Ease of operation

If static CVSS base scores are used for vulnerability ranking, then simplicity is maintained, but dynamic contextual factors are not captured

Engineering Contradiction:
Improvescoring simplicityVSAvoidcontextual adaptability
Core Design Contradiction:
Ease of operationVSAdaptability or versatility

Solution Approach 1:

The system transforms static vulnerability scores into dynamic, time-varying assessments. The engine continuously updates vulnerability priority rankings based on changing contextual factors such as emerging threats, asset criticality changes, and environmental conditions. Scores evolve over time rather than remaining fixed, allowing the system to adapt to new information and changing security landscapes.

Inventive Principle:
Principle #15Dynamics

Solution Approach 2:

The system incorporates feedback loops where vulnerability scoring results are continuously refined based on observed security events, threat intelligence updates, and organizational context changes. The engine uses feedback from multiple data sources to adjust and recalibrate scores, creating a self-correcting system that improves accuracy over time through iterative refinement.

Inventive Principle:
Principle #23Feedback

3Extent of automation

If existing severity databases with manual input are used, then some automation is achieved, but manual input and expert review are still required

Engineering Contradiction:
Improvescoring automationVSAvoidsystem complexity
Core Design Contradiction:
Extent of automationVSDevice complexity

Solution Approach 1:

The vulnerability scoring engine is designed as a universal system that handles multiple vulnerability types, data sources, and scoring scenarios through a single unified platform. The engine can process diverse input formats from various sources, apply multiple scoring methodologies, and generate comprehensive outputs, eliminating the need for separate manual processes for different vulnerability categories.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The system achieves full automation where the computational engine independently performs all scoring operations without requiring human input or review. The engine self-manages data collection, processing, analysis, and score generation, completely eliminating the manual intervention step while maintaining systematic and consistent scoring across all vulnerabilities.

Inventive Principle:
Principle #25Self-service

Data Source

PatentUS12556566B2Systems and methods for dynamic vulnerability scoring
Publication Date: 2026.02.17 SECUREWORKS CORP
  • US12556566B2 patent drawing
  • US12556566B2 patent drawing
  • US12556566B2 patent drawing

AI summary

The present disclosure provides systems and methods for substantially continuous and dynamic vulnerability scoring. According to the present disclosure, the method includes detecting one or more vulnerabilities. The method includes determining a contextual prioritization score (CPS) for each of the one or more vulnerabilities based on historical data, the historical data including a series of contextual features corresponding to each one of the one or more vulnerabilities. The method may include, in response to detection of an event, determining a partial CPS score by an agent. The method may include, if a new partial CPS is determined, generating an updated CPS based on the CPS and the new partial CPS and transmitting the updated CPS to each of one or more computing devices.