Network Asset Operational Dependence Scoring for Vulnerability Prioritization
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
IT administrators face challenges in efficiently managing and remediating vulnerabilities in large computer networks due to the difficulty in prioritizing assets based on their relative importance, leading to inefficient use of resources and time.
Innovation Solution
A system and method for network-based asset operational dependence scoring, which involves monitoring network traffic to calculate an operational dependence score for assets, ranking them based on their services, connections, and data importance, and adjusting vulnerability risk scores accordingly, to prioritize remediation efforts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If IT administrators manually manage and remediate vulnerabilities in large computer networks, then comprehensive security coverage can be achieved, but the time and resources required increase significantly
Solution Approach 1:
The system changes the parameter of asset prioritization from uniform treatment to differentiated scoring based on operational dependence metrics. By calculating dependence scores based on network traffic analysis, service relationships, and connection patterns, the system transforms vulnerability management from a time-consuming manual process to an automated prioritization system that maintains security coverage while reducing remediation time through focused resource allocation.
2Reliability
If IT administrators focus remediation efforts on all assets equally, then no critical assets are missed, but resource allocation becomes inefficient
Solution Approach 1:
The system applies local quality by assigning different priority levels to different assets based on their operational dependence scores. Instead of uniform remediation approaches, the system identifies critical assets with high dependence scores and focuses remediation resources on those specific locations in the network, while applying less intensive monitoring to low-dependence assets. This localized approach maintains comprehensive security coverage while significantly improving remediation efficiency through targeted resource allocation.
3Adaptability or versatility
If the number of executable software files in a network environment increases, then functionality and services improve, but the ability to control, maintain, and remediate these files efficiently deteriorates
Solution Approach 1:
The system replaces manual mechanical processes of vulnerability management with automated electronic analysis. By implementing automated network traffic monitoring, service dependency analysis, and operational dependence scoring, the system substitutes human administrators' manual tracking and prioritization efforts with computational algorithms that can handle large numbers of software files and assets. This substitution maintains ease of operation even as network functionality and asset numbers increase.
Data Source
AI summary
A system and method in one embodiment includes modules for identifying an asset with a vulnerability risk, identifying a service running on a port on the asset, identifying a connection to the port, calculating an operational dependence role of the asset as a function of the service and the connection, and modifying the vulnerability risk based on the operational dependence role. Other embodiments include identifying a protocol of a data packet at the port, classifying the protocol into a protocol category with a protocol importance score, calculating a connection average for the asset, classifying the connection average into a connection category with a connection score, and calculating a service dependence score. Other embodiments include calculating a host dependence score, assigning a data importance score to data communicated by the asset, and calculating the operational dependence role as a function of the host dependence score and data importance score.


