Network Host Risk Scoring for Context-Aware Patch Prioritization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Existing network security systems lack a comprehensive method to contextualize vulnerability risks based on device criticality and exploitability, leading to inefficient patch management and potential security gaps.
Innovation Solution
A computer-implemented method that calculates a vulnerability risk score (VRS) and host risk score (HRS) by integrating device category, criticality, and exploitability metrics, enabling prioritized patching based on relative risk.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If traditional network security systems are used without contextualized risk scoring, then the system structure remains simple, but the ability to prioritize patch management and identify critical vulnerabilities is insufficient
Solution Approach 1:
The patent transforms vulnerability assessment from a static CVSS score to a dynamic contextualized risk score by changing key parameters: device criticality (based on device type and network position), exploitability metrics (active exploitation status, time since patch), and vulnerability characteristics (CVSS base score, exploit availability). This parameter transformation enables precise prioritization of patch management while maintaining manageable system complexity through structured data collection and processing.
2Reliability
If comprehensive vulnerability scanning and risk calculation are implemented, then network security monitoring capability is improved, but the time and computational resources required increase
Solution Approach 1:
The patent performs preliminary actions by continuously collecting and pre-processing vulnerability data, device inventory information, and exploitability metrics before actual patch management decisions are needed. The system pre-calculates contextualized risk scores by integrating CVSS base scores with current exploitability conditions (active exploitation, time since patch release), so that when patch management is required, prioritization can be immediately determined without time-consuming analysis.
3Productivity
If contextualized risk scores are calculated for all devices, then patch management prioritization is improved, but the computational resources and data processing requirements increase
Solution Approach 1:
The patent applies local quality by calculating contextualized risk scores differently for different device types and network positions. Device criticality is determined locally based on device type (server, workstation, network device, IoT device) and network position, rather than applying a uniform assessment methodology to all devices. This allows the system to focus computational resources on high-criticality devices that require prioritized patch management, reducing overall computational resource consumption while maintaining high patch management efficiency for critical assets.
Data Source
AI summary
A method includes scanning a network having a first and second host, obtaining, via the scanning, a first and second type information of the first and second host, respectively, the first or second type information including a device category, obtaining, via the scanning, a first and second scaling factor of the first and second host, respectively, calculating, a first criticality score of the first host based on the first type information and the first scaling factor, calculating a second criticality score of the second host based on the second type information and the second scaling factor, calculating a first host risk score (HRS) for the first host based on the first criticality score, calculating a second HRS for the second host based on the second criticality score, and applying a security patch on the first host prior to the second host first HRS is higher than the second HRS.


