Network Security System for Predictive Vulnerability Remediation

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Current network security solutions are inadequate in preemptively identifying and remediating all vulnerable computing resources in a computer network, especially in large and distributed enterprise systems, due to limitations in static vulnerability scanning and incomplete inventories, leading to potential cyberattacks on unscanned or unknown resources.

Innovation Solution

A method and system that analyze network security data from diverse sources using machine learning models to predict and remediate vulnerabilities by extracting feature vectors, generating weighted vulnerability values, and prioritizing risks, including unknown assets, to identify and address potential threats proactively.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Measurement precision

If static vulnerability scanning solutions are used, then known computing resources and vulnerabilities can be detected, but unknown or unscanned computing resources are missed

Engineering Contradiction:
Improvevulnerability detection accuracyVSAvoidcoverage of computing resources
Core Design Contradiction:
Measurement precisionVSAdaptability or versatility

Solution Approach 1:

The system performs preliminary network mapping and asset discovery before vulnerability scanning to identify all computing resources including unknown ones. By first creating a comprehensive inventory through network traffic analysis and host discovery, the system ensures that subsequent vulnerability scanning covers the complete asset base rather than relying on pre-existing inventories.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system introduces network traffic analysis and host discovery mechanisms as intermediaries between network monitoring and vulnerability scanning. These intermediaries gather information about computing resources through passive network observation and active host probing, enabling the system to identify and scan resources that are not part of traditional inventories.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Quantity of substance

If multiple vendor scanning solutions are deployed, then coverage of known vulnerabilities improves, but coordination and comprehensive coverage of all resource types deteriorates

Engineering Contradiction:
Improvenumber of scanning solutionsVSAvoidsystem integration complexity
Core Design Contradiction:
Quantity of substanceVSDevice complexity

Solution Approach 1:

The system merges the functions of multiple vendor scanning solutions into a unified platform that consolidates network mapping, asset discovery, and vulnerability scanning capabilities. By integrating these functions centrally, the system eliminates redundancy and coordination issues while maintaining comprehensive coverage across all computing resource types.

Inventive Principle:
Principle #5Merging (Combining)

Solution Approach 2:

The system creates a universal scanning platform that can handle diverse computing resource types (servers, workstations, network devices, IoT devices, mobile devices) and multiple vulnerability sources (static vulnerabilities, dynamic vulnerabilities, configuration errors) through a single integrated architecture, replacing the need for multiple specialized vendor solutions.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Measurement precision

If comprehensive network mapping is performed, then identification of all computing resources improves, but time required for inventory and classification increases

Engineering Contradiction:
Improveinventory accuracyVSAvoidtime for asset discovery
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The system performs network mapping and asset discovery continuously rather than as a one-time preliminary step. By maintaining ongoing network observation and host discovery processes, the system keeps the inventory updated in real-time, ensuring accuracy while distributing the time requirement across continuous operation rather than concentrating it in a single lengthy phase.

Inventive Principle:
Principle #20Continuity of useful action

Solution Approach 2:

The system employs periodic network scanning and inventory updates to maintain an accurate record of computing resources. By performing discovery operations at regular intervals rather than continuously, the system balances inventory accuracy with time efficiency, updating the asset database periodically to reflect current network conditions.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS11388184B2Network security system and method for preemptively identifying or remediating security vulnerabilities
Publication Date: 2022.07.12 SAUDI ARABIAN OIL CO
  • US11388184B2 patent drawing
  • US11388184B2 patent drawing
  • US11388184B2 patent drawing

AI summary

A system, a method, and a computer program for analyzing network security data from diverse data sources to predict and remediate a vulnerability at a node in a computer network, comprising receiving network security data from a plurality of data sources, extracting feature vectors from the received network security data, applying a machine learning model to the extracted feature vectors to generate a weighted vulnerability value, predicting a computing resource vulnerability at a node in the computer network based on the weighted vulnerability value, and transmitting the predicted computing resource vulnerability to a computing device which is configured to remediate the predicted computing resource vulnerability.