Machine Learning Vulnerability Metrics Generation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
There is a significant delay between the disclosure of software vulnerabilities and the availability of their metadata in public databases, such as the US NVD, which can lead to inconsistencies in vulnerability scoring and metrics provided by different authorities, including CNAs and the US NVD.
Innovation Solution
A supervised Machine Learning model is trained to generate vulnerability metrics, specifically CVSS metrics, based on textual descriptions of vulnerabilities, using a corpus of existing data from the US NVD, enabling automated and accurate calculation of vulnerability scores without requiring manual intervention or complex rules.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If vulnerability metadata is manually processed and entered into public databases like US NVD, then data accuracy and consistency are maintained, but significant time delays occur between vulnerability disclosure and metadata availability
Solution Approach 1:
The patent replaces the manual mechanical process of vulnerability metadata entry and processing with an automated machine learning system. The ML model automatically generates CVSS metrics and vulnerability metadata from vulnerability descriptions, eliminating the time-consuming manual processes while maintaining scoring consistency through algorithmic standardization.
Solution Approach 2:
The vulnerability metadata generation system performs self-service by automatically creating and populating vulnerability records in public databases without requiring manual intervention. The ML model autonomously processes vulnerability descriptions, generates appropriate metadata, and prepares data for database insertion, enabling the system to serve itself rather than relying on external manual processing.
2Adaptability or versatility
If multiple authorities independently assess and score vulnerabilities, then diverse perspectives and expertise are utilized, but inconsistencies in scoring and metrics arise between different authorities
Solution Approach 1:
The machine learning model serves as a universal scoring mechanism that can process vulnerability assessments from multiple authorities (CNAs, vendors, researchers) using the same standardized algorithms. This multi-functional system maintains the ability to handle diverse input sources while ensuring consistent CVSS metric generation across all authorities, eliminating scoring inconsistencies.
Solution Approach 2:
The patent standardizes vulnerability scoring by transforming diverse vulnerability descriptions into consistent CVSS metric parameters through the ML model. By changing the assessment parameters from subjective human judgment to objective algorithmic evaluation, the system maintains scoring consistency while still accommodating multiple authority perspectives through standardized parameter interpretation.
3Reliability
If manual processes are used for vulnerability metadata generation and database population, then data quality control is maintained, but productivity and speed of metadata availability are significantly reduced
Solution Approach 1:
The patent replaces manual data quality control processes with automated machine learning-based validation and generation systems. The ML model inherently maintains data quality through trained patterns and consistency checks while operating at automated speeds, eliminating the trade-off between quality control and productivity that exists in manual processes.
Solution Approach 2:
The machine learning system enables continuous automated generation of vulnerability metadata without the interruptions and bottlenecks inherent in manual processes. The system can process multiple vulnerability reports simultaneously and continuously populate databases in real-time, maintaining data quality through automated validation while achieving sustained high-speed productivity.
Data Source
AI summary
Techniques, methods and/or apparatuses are disclosed that enable generation of vulnerability vectors of newly identified vulnerabilities (e.g., CVEs). Based on the textual description of the vulnerability, vulnerability vectors are generated. The generated vulnerability vectors may represent a prediction of how a third party vulnerability scorer (e.g., US NVD) would score the identified vulnerability.


