Exploit Detector for Software Vulnerability Monitoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing systems face challenges in protecting against vulnerability exploits between the time a security bulletin is posted and when a corresponding security fix is applied, due to potential downtime and disruption costs, as well as delays in applying fixes by administrators or users.

Innovation Solution

An exploit detector is transmitted along with the security fix, which can be installed on the system to detect and mitigate exploits before the security fix is fully implemented, using standard programming languages and tools like host-based firewalls to monitor for system state changes and network patterns, and notify administrators of attacks.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security fixes are applied immediately after a vulnerability is discovered, then system protection against exploits is improved, but system downtime and service disruption increase

Engineering Contradiction:
Improvesystem protectionVSAvoidsystem downtime
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies preliminary action by implementing an exploit detector that is deployed and activated before the security fix is applied. This detector monitors for exploit attempts during the delay period, enabling early detection and response to attacks before the system is patched, thus maintaining protection without requiring immediate system downtime.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The exploit detector serves as an intermediary solution between the vulnerability discovery and the security fix application. It bridges the gap by providing active monitoring and detection capabilities during the interim period, allowing administrators to delay fix application without completely compromising system security.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If security fixes are delayed to avoid downtime, then system availability is improved, but vulnerability exposure time increases

Engineering Contradiction:
Improvesystem availabilityVSAvoidvulnerability exposure time
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The exploit detector implements feedback by continuously monitoring for exploit attempts and providing real-time alerts to administrators. This feedback mechanism allows the system to maintain high availability while compensating for the extended vulnerability exposure period through active detection and notification, enabling timely response to actual attack attempts.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The exploit detector acts as an intermediary monitoring system that operates during the delay period between vulnerability discovery and fix application. It reduces the effective risk exposure by providing detection capabilities without requiring the system to be taken offline, thus maintaining productivity while managing vulnerability exposure.

Inventive Principle:
Principle #24Intermediary (Mediator)

3Stability of the object's composition

If administrators wait to test security fixes, then system stability is improved, but security response time decreases

Engineering Contradiction:
Improvesystem stabilityVSAvoidsecurity response time
Core Design Contradiction:
Stability of the object's compositionVSLoss of time

Solution Approach 1:

The exploit detector is deployed as a preliminary measure before the security fix is applied and tested. This allows the system to maintain stability by avoiding premature patching while simultaneously providing security monitoring capabilities that reduce the effective response time gap by detecting exploits during the testing delay period.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS8739288B2Automatic detection of vulnerability exploits
Publication Date: 2014.05.27 HEWLETT PACKARD ENTERPRISE DEV LP
  • US8739288B2 patent drawing
  • US8739288B2 patent drawing
  • US8739288B2 patent drawing

AI summary

An embodiment of the invention provides an apparatus and method for automatic detection of a vulnerability exploit. The apparatus and method are configured to post a security vulnerability warning indicating a vulnerability of software; provide an exploit detector; and use the exploit detector to detect an attempted exploit that targets the vulnerability.