Machine Learning Patch Risk Assessment System

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Identifying and addressing vulnerabilities in computer systems is challenging due to communication complexity and dynamicity, especially when multiple components share risk impacts, and existing patch management processes struggle to keep pace with the number of patches required.

Innovation Solution

A system comprising a vertical stack component, a horizontal stack component, and a risk classification component that uses machine learning to identify patch profiles from software and hardware systems, assess risks, and generate execution plans for remediation, improving the identification and repair of vulnerabilities across computer system environments.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If traditional patch management processes are used to identify and address vulnerabilities, then vulnerability repair can be achieved, but the process becomes inefficient and cannot keep pace with the number of patches required due to communication complexity and system dynamicity

Engineering Contradiction:
Improvepatch management efficiencyVSAvoidcommunication complexity
Core Design Contradiction:
ProductivityVSDevice complexity

Solution Approach 1:

The system segments the complex communication process into distinct components: a vertical stack component for software patch profiling, a horizontal stack component for hardware patch profiling, and a risk classification component for machine learning-based risk assessment. This segmentation allows each component to handle specific tasks independently, reducing overall communication complexity while improving patch management productivity

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent introduces an intermediary machine learning model that acts as a mediator between patch profiles and risk assessment. This intermediary automatically processes and classifies risk levels based on input data, eliminating the need for complex manual communication and coordination between system components, thereby improving efficiency while managing complexity

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If comprehensive risk assessment is performed across software and hardware systems, then better vulnerability identification is achieved, but the processing complexity and time required increase

Engineering Contradiction:
Improverisk assessment accuracyVSAvoidprocessing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by collecting and organizing patch profile data from both software and hardware systems before conducting the actual risk assessment. The vertical and horizontal stack components prepare standardized input data in advance, allowing the machine learning model to perform rapid classification without time-consuming data preparation during the assessment phase

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent replaces manual or traditional mechanical risk assessment methods with a machine learning-based automated system. The risk classification component uses trained models to automatically evaluate risks based on patch profiles, significantly reducing processing time while maintaining or improving assessment accuracy compared to traditional methods

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS10649758B2Group patching recommendation and/or remediation with risk assessment
Publication Date: 2020.05.12 KYNDRYL INC
  • US10649758B2 patent drawing
  • US10649758B2 patent drawing
  • US10649758B2 patent drawing

AI summary

Techniques that facilitate group patching recommendation and/or remediation with risk assessment are provided. In one example, a system includes a vertical stack component, a horizontal stack component and a risk classification component. The vertical stack component identifies a first patch profile from a software system associated with a computer system environment. The horizontal stack component identifies a second patch profile from a hardware system associated with network nodes of the computer system environment. The system learns over time to identify repetitive patterns using machine learning techniques. Then, the risk classification component performs a machine learning process to determine a risk classification for the computer system environment based on the first patch profile and the second patch profile.