Network Host Risk Scoring for Context-Aware Patch Prioritization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing network security systems lack a comprehensive method to contextualize vulnerability risks based on device criticality and exploitability, leading to inefficient patch management and potential security gaps.

Innovation Solution

A computer-implemented method that calculates a vulnerability risk score (VRS) and host risk score (HRS) by integrating device category, criticality, and exploitability metrics, enabling prioritized patching based on relative risk.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If traditional network security systems are used without contextualized risk scoring, then the system structure remains simple, but the ability to prioritize patch management and identify critical vulnerabilities is insufficient

Engineering Contradiction:
Improvevulnerability risk assessment accuracyVSAvoidsystem complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The patent transforms vulnerability assessment from a static CVSS score to a dynamic contextualized risk score by changing key parameters: device criticality (based on device type and network position), exploitability metrics (active exploitation status, time since patch), and vulnerability characteristics (CVSS base score, exploit availability). This parameter transformation enables precise prioritization of patch management while maintaining manageable system complexity through structured data collection and processing.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If comprehensive vulnerability scanning and risk calculation are implemented, then network security monitoring capability is improved, but the time and computational resources required increase

Engineering Contradiction:
Improvenetwork security monitoring capabilityVSAvoidpatch management time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent performs preliminary actions by continuously collecting and pre-processing vulnerability data, device inventory information, and exploitability metrics before actual patch management decisions are needed. The system pre-calculates contextualized risk scores by integrating CVSS base scores with current exploitability conditions (active exploitation, time since patch release), so that when patch management is required, prioritization can be immediately determined without time-consuming analysis.

Inventive Principle:
Principle #10Preliminary action

3Productivity

If contextualized risk scores are calculated for all devices, then patch management prioritization is improved, but the computational resources and data processing requirements increase

Engineering Contradiction:
Improvepatch management efficiencyVSAvoidcomputational resource consumption
Core Design Contradiction:
ProductivityVSUse of energy by moving object

Solution Approach 1:

The patent applies local quality by calculating contextualized risk scores differently for different device types and network positions. Device criticality is determined locally based on device type (server, workstation, network device, IoT device) and network position, rather than applying a uniform assessment methodology to all devices. This allows the system to focus computational resources on high-criticality devices that require prioritized patch management, reducing overall computational resource consumption while maintaining high patch management efficiency for critical assets.

Inventive Principle:
Principle #3Local quality

Data Source

PatentUS12418560B1Computer-based systems configured for network characterization and management and methods of use thereof
Publication Date: 2025.09.16 VIRTUALITICS INC
  • US12418560B1 patent drawing
  • US12418560B1 patent drawing
  • US12418560B1 patent drawing

AI summary

A method includes scanning a network having a first and second host, obtaining, via the scanning, a first and second type information of the first and second host, respectively, the first or second type information including a device category, obtaining, via the scanning, a first and second scaling factor of the first and second host, respectively, calculating, a first criticality score of the first host based on the first type information and the first scaling factor, calculating a second criticality score of the second host based on the second type information and the second scaling factor, calculating a first host risk score (HRS) for the first host based on the first criticality score, calculating a second HRS for the second host based on the second criticality score, and applying a security patch on the first host prior to the second host first HRS is higher than the second HRS.