Dynamic Vulnerability Scoring via Network Traffic Adjustment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

The Common Vulnerability Scoring System (CVSS) scores can be ambiguous when the number of detected vulnerabilities is high, failing to accurately reflect true risks and leading to erroneous prioritization and remediation of cybersecurity vulnerabilities in computing resource assets.

Innovation Solution

A system and method that adjusts CVSS scores based on network traffic data to generate a prioritized common vulnerability score (PCVSS), allowing for more accurate vulnerability assessment and prioritization by incorporating network traffic adjustment values, enabling efficient and effective remediation.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Adaptability or versatility

If CVSS scores are used to assess vulnerabilities, then a standardized scoring system is provided, but the scores become ambiguous when the number of detected vulnerabilities is high and fail to accurately reflect true risks

Engineering Contradiction:
Improveadaptability of vulnerability assessmentVSAvoidprecision of vulnerability risk assessment
Core Design Contradiction:
Adaptability or versatilityVSMeasurement precision

Solution Approach 1:

The patent transforms the static CVSS score into a dynamic prioritized vulnerability score by introducing network traffic metrics as additional parameters. The system calculates a prioritized score by combining the base CVSS score with network traffic data (such as traffic volume, traffic patterns, and criticality weights) to reflect the actual risk posed by each vulnerability in the specific network context, thereby resolving the ambiguity of standard CVSS scores when multiple vulnerabilities are present

Inventive Principle:
Principle #35Parameter changes

2Reliability

If multiple vulnerabilities are detected in computing resource assets, then comprehensive security coverage is achieved, but the CVSS scores fail to prioritize which vulnerabilities to remediate first

Engineering Contradiction:
Improvecomprehensive vulnerability detectionVSAvoidtime for vulnerability remediation
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system enhances the standard CVSS scoring parameters by incorporating network-specific metrics including traffic volume, traffic patterns, asset criticality weights, and temporal factors. This creates a prioritized vulnerability score that dynamically ranks vulnerabilities based on their actual impact potential, enabling security teams to remediate the most critical vulnerabilities first and reduce overall remediation time

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system implements continuous monitoring of network traffic and vulnerability states, using feedback loops to update prioritized scores as network conditions change. This dynamic adjustment ensures that remediation priorities remain current and reflect the evolving risk landscape, preventing time loss from addressing low-priority vulnerabilities while high-priority ones remain unaddressed

Inventive Principle:
Principle #23Feedback

Data Source

PatentUS11277429B2Cybersecurity vulnerability classification and remediation based on network utilization
Publication Date: 2022.03.15 SAUDI ARABIAN OIL CO
  • US11277429B2 patent drawing
  • US11277429B2 patent drawing
  • US11277429B2 patent drawing

AI summary

A technology solution for remediating a cyberattack risk in a computing resource asset in a network system. The technology solution includes monitoring data traffic directed to the computing resource asset in the network system along with data traffic to one or more additional computing resource assets in the network system, generating network utilization data based on the monitored data traffic to the computing resource asset and the monitored data traffic to the one or more additional computing resource assets in the network system, receiving a common vulnerability score (CVSS) for a vulnerability in the computing resource asset, determining a network traffic adjustment (NTA) value for the common vulnerability score (CVSS) based on the network utilization data, adjusting the common vulnerability score (CVSS) by the network traffic adjustment (NTA) value to generate a prioritized common vulnerability score (PCVSS) for the computing resource asset, and remediating the computing resource asset to resolve the vulnerability based on the prioritized common vulnerability (PCVSS) score.