Network Host Criticality Scoring for Security Patch Prioritization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems lack an efficient method to prioritize and apply security patches based on the criticality of network hosts, leading to suboptimal security measures and potential vulnerabilities.

Innovation Solution

A method and system that calculates a criticality score for network hosts by analyzing device category, number of services, functionality, and use case, enabling prioritization of security patches on more critical hosts before less critical ones.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If security patches are applied uniformly to all network hosts without prioritization, then implementation simplicity is maintained, but network security effectiveness deteriorates due to delayed patching of critical hosts

Engineering Contradiction:
Improvenetwork security effectivenessVSAvoidpatch management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies local quality by assigning different criticality scores to different network hosts based on their specific characteristics (device category, services running, functionality, use case). This allows the patch management system to treat each host differently according to its local security importance, rather than applying uniform patching policies across the entire network.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes the parameter of patch prioritization from a uniform approach to a differentiated approach based on calculated criticality scores. By introducing criticality score as a new parameter that combines multiple host attributes, the system transforms patch management from a simple chronological process to a priority-based process that responds to varying security needs across different hosts.

Inventive Principle:
Principle #35Parameter changes

2Measurement precision

If comprehensive host analysis is performed to calculate criticality scores, then security prioritization accuracy is improved, but processing time and computational resources increase

Engineering Contradiction:
Improvecriticality score accuracyVSAvoidpatch management time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-calculating and storing criticality scores for network hosts before patch management activities begin. This allows the system to have prioritization information ready in advance, eliminating the need for time-consuming analysis during actual patch deployment operations.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent implements partial action by selecting only the most critical hosts for immediate patching based on calculated scores, rather than attempting to patch all hosts simultaneously. This allows the system to focus computational resources on the most important security tasks while maintaining acceptable security posture.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS20250358306A1Computer-based systems configured for network characterization and management based on device criticality score and methods of use thereof
Publication Date: 2025.11.20 VIRTUALITICS INC
  • US20250358306A1 patent drawing
  • US20250358306A1 patent drawing
  • US20250358306A1 patent drawing

AI summary

A method includes scanning a network having a first and second host, obtaining, via the scanning, a first and second type information of the first and second host, respectively, the first or second type information including a device category the first or second host belongs to, obtaining, via the scanning, a first and second scaling factor of the first and second host, respectively, calculating, a first criticality score of the first host based on the first type information and the first scaling factor, calculating a second criticality score of the second host based on the second type information and the second scaling factor, and facilitating to apply a security patch on the first host prior to the second host when the first criticality score is higher than the second criticality score.