Network Asset Operational Dependence Scoring for Vulnerability Prioritization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

IT administrators face challenges in efficiently managing and remediating vulnerabilities in large computer networks due to the difficulty in prioritizing assets based on their relative importance, leading to inefficient use of resources and time.

Innovation Solution

A system and method for network-based asset operational dependence scoring, which involves monitoring network traffic to calculate an operational dependence score for assets, ranking them based on their services, connections, and data importance, and adjusting vulnerability risk scores accordingly, to prioritize remediation efforts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If IT administrators manually manage and remediate vulnerabilities in large computer networks, then comprehensive security coverage can be achieved, but the time and resources required increase significantly

Engineering Contradiction:
Improvesecurity coverageVSAvoidremediation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system changes the parameter of asset prioritization from uniform treatment to differentiated scoring based on operational dependence metrics. By calculating dependence scores based on network traffic analysis, service relationships, and connection patterns, the system transforms vulnerability management from a time-consuming manual process to an automated prioritization system that maintains security coverage while reducing remediation time through focused resource allocation.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If IT administrators focus remediation efforts on all assets equally, then no critical assets are missed, but resource allocation becomes inefficient

Engineering Contradiction:
Improvesecurity coverageVSAvoidremediation efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system applies local quality by assigning different priority levels to different assets based on their operational dependence scores. Instead of uniform remediation approaches, the system identifies critical assets with high dependence scores and focuses remediation resources on those specific locations in the network, while applying less intensive monitoring to low-dependence assets. This localized approach maintains comprehensive security coverage while significantly improving remediation efficiency through targeted resource allocation.

Inventive Principle:
Principle #3Local quality

3Adaptability or versatility

If the number of executable software files in a network environment increases, then functionality and services improve, but the ability to control, maintain, and remediate these files efficiently deteriorates

Engineering Contradiction:
Improvenetwork functionalityVSAvoidmaintenance difficulty
Core Design Contradiction:
Adaptability or versatilityVSEase of operation

Solution Approach 1:

The system replaces manual mechanical processes of vulnerability management with automated electronic analysis. By implementing automated network traffic monitoring, service dependency analysis, and operational dependence scoring, the system substitutes human administrators' manual tracking and prioritization efforts with computational algorithms that can handle large numbers of software files and assets. This substitution maintains ease of operation even as network functionality and asset numbers increase.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

Data Source

PatentUS8997234B2System and method for network-based asset operational dependence scoring
Publication Date: 2015.03.31 MCAFEE LLC
  • US8997234B2 patent drawing
  • US8997234B2 patent drawing
  • US8997234B2 patent drawing

AI summary

A system and method in one embodiment includes modules for identifying an asset with a vulnerability risk, identifying a service running on a port on the asset, identifying a connection to the port, calculating an operational dependence role of the asset as a function of the service and the connection, and modifying the vulnerability risk based on the operational dependence role. Other embodiments include identifying a protocol of a data packet at the port, classifying the protocol into a protocol category with a protocol importance score, calculating a connection average for the asset, classifying the connection average into a connection category with a connection score, and calculating a service dependence score. Other embodiments include calculating a host dependence score, assigning a data importance score to data communicated by the asset, and calculating the operational dependence role as a function of the host dependence score and data importance score.