Network Security System for Predictive Vulnerability Remediation
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Current network security solutions are inadequate in preemptively identifying and remediating all vulnerable computing resources in a computer network, especially in large and distributed enterprise systems, due to limitations in static vulnerability scanning and incomplete inventories, leading to potential cyberattacks on unscanned or unknown resources.
Innovation Solution
A method and system that analyze network security data from diverse sources using machine learning models to predict and remediate vulnerabilities by extracting feature vectors, generating weighted vulnerability values, and prioritizing risks, including unknown assets, to identify and address potential threats proactively.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Measurement precision
If static vulnerability scanning solutions are used, then known computing resources and vulnerabilities can be detected, but unknown or unscanned computing resources are missed
Solution Approach 1:
The system performs preliminary network mapping and asset discovery before vulnerability scanning to identify all computing resources including unknown ones. By first creating a comprehensive inventory through network traffic analysis and host discovery, the system ensures that subsequent vulnerability scanning covers the complete asset base rather than relying on pre-existing inventories.
Solution Approach 2:
The system introduces network traffic analysis and host discovery mechanisms as intermediaries between network monitoring and vulnerability scanning. These intermediaries gather information about computing resources through passive network observation and active host probing, enabling the system to identify and scan resources that are not part of traditional inventories.
2Quantity of substance
If multiple vendor scanning solutions are deployed, then coverage of known vulnerabilities improves, but coordination and comprehensive coverage of all resource types deteriorates
Solution Approach 1:
The system merges the functions of multiple vendor scanning solutions into a unified platform that consolidates network mapping, asset discovery, and vulnerability scanning capabilities. By integrating these functions centrally, the system eliminates redundancy and coordination issues while maintaining comprehensive coverage across all computing resource types.
Solution Approach 2:
The system creates a universal scanning platform that can handle diverse computing resource types (servers, workstations, network devices, IoT devices, mobile devices) and multiple vulnerability sources (static vulnerabilities, dynamic vulnerabilities, configuration errors) through a single integrated architecture, replacing the need for multiple specialized vendor solutions.
3Measurement precision
If comprehensive network mapping is performed, then identification of all computing resources improves, but time required for inventory and classification increases
Solution Approach 1:
The system performs network mapping and asset discovery continuously rather than as a one-time preliminary step. By maintaining ongoing network observation and host discovery processes, the system keeps the inventory updated in real-time, ensuring accuracy while distributing the time requirement across continuous operation rather than concentrating it in a single lengthy phase.
Solution Approach 2:
The system employs periodic network scanning and inventory updates to maintain an accurate record of computing resources. By performing discovery operations at regular intervals rather than continuously, the system balances inventory accuracy with time efficiency, updating the asset database periodically to reflect current network conditions.
Data Source
AI summary
A system, a method, and a computer program for analyzing network security data from diverse data sources to predict and remediate a vulnerability at a node in a computer network, comprising receiving network security data from a plurality of data sources, extracting feature vectors from the received network security data, applying a machine learning model to the extracted feature vectors to generate a weighted vulnerability value, predicting a computing resource vulnerability at a node in the computer network based on the weighted vulnerability value, and transmitting the predicted computing resource vulnerability to a computing device which is configured to remediate the predicted computing resource vulnerability.


