IT Vulnerability Assessment via Application Metadata Correlation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Complex IT infrastructures face increased security risks due to flaws, common software, poor password management, and network connectivity, making it difficult to identify and prioritize vulnerabilities effectively.

Innovation Solution

A vulnerability assessment system that obtains application metadata and global security risk metadata to generate a vulnerable application dataset, correlating unique software identifiers with security risks, allowing for real-time risk assessment and prioritization of remediation efforts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Device complexity

If organizations use common code/software, common operating systems, and common hardware to simplify infrastructure, then device complexity is reduced, but security vulnerability increases due to common attack targets

Engineering Contradiction:
ImproveIT infrastructure complexityVSAvoidsecurity vulnerability
Core Design Contradiction:
Device complexityVSObject-affected harmful factors

Solution Approach 1:

The patent transforms vulnerability assessment from static software version checking to dynamic behavior-based assessment. By monitoring runtime parameters such as API calls, system calls, and execution patterns, the system identifies vulnerabilities based on actual behavior rather than predetermined software identifiers, resolving the contradiction between using common software and maintaining security

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent replaces traditional mechanical vulnerability identification methods (comparing software versions against known vulnerability databases) with a behavioral analysis system. The system uses runtime monitoring and pattern recognition to detect vulnerabilities, substituting static mechanical checks with dynamic observational methods that work across diverse software implementations

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

2Productivity

If organizations increase network connectivity and Internet browsing to enhance operations, then productivity increases, but exposure to threats and vulnerabilities increases

Engineering Contradiction:
Improveoperational efficiencyVSAvoidattack surface
Core Design Contradiction:
ProductivityVSObject-affected harmful factors

Solution Approach 1:

The patent implements continuous feedback loops where the vulnerability assessment system constantly monitors application behavior, compares it against known attack patterns, and provides real-time alerts. This feedback mechanism enables organizations to maintain high network connectivity while receiving immediate notifications of potential security threats, allowing productivity to increase without proportionally increasing risk exposure

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent introduces a behavioral analysis intermediary layer between network traffic and vulnerable applications. This intermediary monitors and analyzes application behavior patterns, acting as a mediator that detects threats before they can exploit vulnerabilities, thereby enabling safe network connectivity expansion

Inventive Principle:
Principle #24Intermediary (Mediator)

3Ease of manufacture

If traditional vulnerability assessment methods are used that rely on software version identification, then implementation is straightforward, but accuracy decreases due to obfuscated or modified software identifiers

Engineering Contradiction:
Improveassessment implementation easeVSAvoidvulnerability identification accuracy
Core Design Contradiction:
Ease of manufactureVSMeasurement precision

Solution Approach 1:

The patent replaces mechanical software identifier matching with behavioral pattern recognition. Instead of relying on software versions, build numbers, or hardcoded identifiers that can be obfuscated, the system monitors runtime behavior such as API calls, system calls, memory access patterns, and execution flow. This substitution maintains ease of implementation through automated monitoring while dramatically improving accuracy by detecting vulnerabilities based on immutable behavioral characteristics

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The patent creates behavioral copies or models of vulnerable application patterns. By establishing reference models of how vulnerable applications behave during execution, the system can identify vulnerabilities through behavioral matching rather than identifier matching. This copying approach remains easy to implement through automated modeling while achieving high precision in vulnerability detection

Inventive Principle:
Principle #26Copying

Data Source

PatentUS9928369B2Information technology vulnerability assessment
Publication Date: 2018.03.27 CISCO TECHNOLOGY INC
  • US9928369B2 patent drawing
  • US9928369B2 patent drawing
  • US9928369B2 patent drawing

AI summary

Presented herein are vulnerability assessment techniques for highlighting an organization's information technology (IT) infrastructure security vulnerabilities. For example, a vulnerability assessment system obtains application metadata for each of a plurality of executable applications observed at one or more devices forming part of an organization's IT infrastructure. The application metadata includes unique software identifiers for each of the plurality of executable applications. The vulnerability assessment system obtains global security risk metadata for executable applications observed at the one or more devices. The vulnerability assessment system maps one or more unique software identifiers in the application metadata to global security risk metadata that corresponds to applications identified by the one or more unique software identifiers, thereby generating a vulnerable application dataset.