Mobile Device Management for Automated Vulnerability Remediation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
The rapid growth of application libraries and threat disclosures in organizational environments due to BYOA trends leads to inefficient and time-consuming manual processes for responding to security vulnerabilities in software suites, making it unmanageable to detect and remediate security vulnerabilities effectively.
Innovation Solution
A computer-implemented method and system that receives security statements from a threat feed server, parses them to create a custom threat feed of common vulnerabilities and exposures, selectively creates alerts with remediation actions, and determines managed devices to transmit messages for remediation, utilizing a mobile device management server, threat feed server, and push notification server for efficient vulnerability management.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If manual processes are used to respond to security vulnerabilities, then flexibility and control are maintained, but the process becomes time-consuming and unmanageable
Solution Approach 1:
The system performs preliminary actions by continuously monitoring threat feeds and pre-parsing security statements before vulnerabilities affect managed devices. Security vulnerabilities are identified and alerts are prepared in advance, enabling rapid response when vulnerabilities are detected on devices without requiring manual analysis at the time of compromise.
Solution Approach 2:
The system implements self-service through automated vulnerability detection, parsing, and remediation execution. The mobile device management server automatically monitors threat feeds, parses security statements, identifies vulnerable devices, and executes remediation actions without requiring manual intervention, thereby improving response efficiency and reducing time loss.
2Reliability
If comprehensive security monitoring is implemented across all managed devices, then security coverage is improved, but system complexity increases
Solution Approach 1:
The mobile device management server serves multiple functions: it manages device configurations, monitors security threats, parses vulnerability data, identifies vulnerable devices, and executes remediation actions. This multi-functional approach consolidates complexity into a single system rather than requiring separate specialized systems for each function.
Solution Approach 2:
The system introduces a mobile device management server as an intermediary between threat intelligence sources and managed devices. This intermediary centralizes the complexity of vulnerability management, including threat feed monitoring, security statement parsing, and remediation coordination, while presenting a simplified interface to both threat sources and endpoint devices.
3Productivity
If automated remediation actions are executed on managed devices, then response speed is improved, but precision in identifying affected devices may be compromised
Solution Approach 1:
The system implements feedback mechanisms where the mobile device management server continuously monitors managed devices for security vulnerabilities, compares detected vulnerabilities against parsed security statements from threat feeds, and uses this feedback to accurately identify which specific devices require remediation. This feedback loop ensures precise device identification before automated remediation is executed.
Solution Approach 2:
The system performs preliminary parsing of security statements and pre-identification of vulnerability patterns before executing remediation. By preparing vulnerability detection criteria in advance and pre-scanning devices for matching vulnerabilities, the system ensures both rapid response execution and accurate identification of affected devices through pre-established matching criteria.
Data Source
AI summary
According to certain aspects of the present disclosure, a computer-implemented method is provided. The method includes receiving, at a mobile device management server from a threat feed server, at least one security statement. The method includes parsing the at least one security statement into parsed information. The method includes creating a custom threat feed of common vulnerabilities and exposures with at least the parsed information. The method includes selectively creating an alert associated with one common vulnerability and exposure of the common vulnerabilities and exposures, wherein the alert comprises a remediation action associated with the one common vulnerability and exposure. The method includes determining at least one managed device, managed by the mobile device management server, and associated with the remediation action of the alert. Systems and machine-readable media are also provided.


