Vulnerability Proofing IHS Application Templates

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Information Handling Systems (IHSs) often become vulnerable due to known hardware and software vulnerabilities, which can be exploited by malicious actors, especially when administrators are unaware of these vulnerabilities during configuration changes.

Innovation Solution

Implementing a remote access controller that detects application instances launching with potentially vulnerable configurations, accesses catalogs of known vulnerabilities, and prevents the launch until the configurations are modified to exclude identified vulnerabilities.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If administrators manually configure hardware and software components of IHS, then the system can be customized and adapted to specific needs, but the system becomes vulnerable to known security and functional vulnerabilities

Engineering Contradiction:
Improveconfiguration flexibilityVSAvoidvulnerability exposure
Core Design Contradiction:
Adaptability or versatilityVSReliability

Solution Approach 1:

The system performs preliminary vulnerability detection on application templates before they are executed. The remote access controller checks the template against vulnerability catalogs in advance, preventing vulnerable configurations from being deployed to the IHS system.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The remote access controller acts as an intermediary between the application template and the IHS system. It intercepts the template, performs vulnerability validation, and only allows execution if the template passes the security checks, thereby mediating between configuration flexibility and security requirements.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Productivity

If administrators update hardware and software configurations to improve system functionality, then the system can adapt to new requirements, but vulnerabilities may be introduced through inconsistent configuration protocols

Engineering Contradiction:
Improvesystem functionalityVSAvoidconfiguration consistency
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system implements feedback by continuously monitoring and validating configuration templates against up-to-date vulnerability catalogs. When vulnerabilities are detected, the system provides feedback to administrators through notifications and warnings, enabling them to correct inconsistent configurations before deployment.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

Before applying configuration updates, the system performs preliminary validation checks on the configuration templates. This ensures that updates maintaining functionality do not introduce vulnerabilities, thereby ensuring configuration consistency across system updates.

Inventive Principle:
Principle #10Preliminary action

3Duration of action of stationary object

If the system allows free configuration changes to maintain operational availability, then system uptime is maximized, but security vulnerabilities can be exploited before detection

Engineering Contradiction:
Improvesystem availabilityVSAvoidsecurity exploitation risk
Core Design Contradiction:
Duration of action of stationary objectVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary vulnerability assessment on configuration templates before they are applied to the running system. This allows safe configuration changes to be implemented without interrupting system operations, while vulnerable configurations are blocked before exploitation can occur.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The remote access controller serves as a security intermediary that validates configuration changes in real-time. It allows legitimate configuration updates to proceed while blocking vulnerable ones, thereby maintaining system availability without exposing the system to security exploits.

Inventive Principle:
Principle #24Intermediary (Mediator)

Data Source

PatentUS12223059B2Systems and methods for vulnerability proofing when configuring an IHS
Publication Date: 2025.02.11 DELL PROD LP
  • US12223059B2 patent drawing
  • US12223059B2 patent drawing
  • US12223059B2 patent drawing

AI summary

Systems and methods are provided for vulnerability proofing the launching of application instances by an IHS (Information Handling System). The launching of an application instance on the IHS is detected, where the application instance is launched using an application template that includes configurations for one or more hardware components of the IHS. One or more catalogs are accessed that specify known vulnerabilities of hardware components. Hardware component configurations included in the application template are identified as vulnerable in one or more of the catalogs. If the application template includes configurations that are identified as vulnerable in the catalogs, launching of the application is prevented until the hardware component configurations within the application template are modified to include no configurations with vulnerabilities identified in the catalogs.