ML-Based Security Vulnerability Detection and Prioritization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current approaches for determining the security of computing platforms and systems are hindered by reliance on outdated and inaccurate publicly available information, leading to delayed recognition of newly discovered security vulnerabilities and inefficient prioritization of mitigation efforts.

Innovation Solution

The development of a system that utilizes machine learning models to analyze platform-specific data and generate real-time security labels, providing a graphical representation of computing aspect impact levels to facilitate informed decision-making by network engineers.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If manually determined security vulnerabilities are used, then security assessment can be performed, but the process is time-consuming and prone to errors

Engineering Contradiction:
Improvesecurity vulnerability detection accuracyVSAvoidtime to identify and prioritize vulnerabilities
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent replaces manual mechanical analysis by network engineers with an automated machine learning system that processes security data, generates vulnerability predictions, and prioritizes threats algorithmically, eliminating human subjectivity and time constraints

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Solution Approach 2:

The system enables self-service security assessment by automatically collecting security data, analyzing vulnerabilities, and generating prioritized recommendations without requiring manual intervention from security engineers

Inventive Principle:
Principle #25Self-service

2Reliability

If publicly available security information is used, then security assessment can be performed, but the information is outdated and inaccurate

Engineering Contradiction:
Improvesecurity information accuracyVSAvoiddelay in detecting new vulnerabilities
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary security assessments and continuously monitors for new vulnerabilities before they are publicly disclosed, using machine learning to predict and detect emerging threats in advance of traditional public information sources

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements continuous feedback loops that collect real-time security data from multiple sources, update vulnerability predictions, and refine security assessments dynamically, ensuring information remains current and accurate

Inventive Principle:
Principle #23Feedback

3Productivity

If network engineers manually prioritize vulnerabilities, then mitigation efforts can be directed, but disagreements lead to delayed corrections

Engineering Contradiction:
Improvevulnerability mitigation efficiencyVSAvoidtime to resolve vulnerabilities
Core Design Contradiction:
ProductivityVSLoss of time

Solution Approach 1:

The patent replaces subjective human prioritization decisions with an automated machine learning system that objectively ranks vulnerabilities based on predicted impact and exploitability, eliminating disagreements and enabling immediate action on highest-risk threats

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS12314406B1Generative cybersecurity exploit discovery and evaluation
Publication Date: 2025.05.27 CITIBANK N A
  • US12314406B1 patent drawing
  • US12314406B1 patent drawing
  • US12314406B1 patent drawing

AI summary

Described herein are systems and methods for discovering and proactively mitigating previously unknown security vulnerabilities. The systems and methods herein can utilize security vulnerability information to discover potential security threats and can utilize this information to generate an attack using a machine learning model, such as a large language model. Generated attacks can be carried out to assess impact of a security vulnerability. An output can be provided that represents the assessed impact. In some implementations, the systems and methods herein generate patches or other mitigations for security vulnerabilities, which can be tested and deployed to address security vulnerabilities.