Remote Network Management Platform for Vulnerability Prioritization

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large enterprises face challenges in managing and securing their complex networks due to the proliferation of custom software applications, which can lead to vulnerabilities that are difficult to detect and prioritize, impacting operational efficiency and security.

Innovation Solution

Integration of configuration items and vulnerability data into a remote network management platform, enabling the calculation of a security threat score based on severity, exploitability, and exposure, and providing notifications to both software engineering and IT operations staff to address vulnerabilities effectively.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If vulnerability detection tools are used to scan custom software applications, then vulnerabilities can be detected, but the complexity of managing and prioritizing vulnerabilities increases due to the large number of computing devices and applications

Engineering Contradiction:
Improvevulnerability detection capabilityVSAvoidnetwork management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces a remote network management platform as an intermediary between vulnerability detection tools and IT operations staff. This platform aggregates vulnerability data from multiple sources, correlates it with configuration item data, and presents prioritized vulnerability information, thereby simplifying the complex task of managing vulnerabilities across thousands of devices and applications.

Inventive Principle:
Principle #24Intermediary (Mediator)

Solution Approach 2:

The patent combines vulnerability detection data with configuration item data (including software inventory, device information, and relationships) into a unified remote network management platform. This merging allows for correlated analysis and prioritization of vulnerabilities based on multiple factors simultaneously, reducing the complexity of separate manual processes.

Inventive Principle:
Principle #5Merging (Combining)

2Reliability

If comprehensive vulnerability scanning is performed across all computing devices, then security coverage is improved, but the time and resources required for analysis and response increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidvulnerability response time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent changes the parameters of vulnerability assessment by introducing a prioritization framework that evaluates vulnerabilities based on multiple dynamic factors including severity, exploitability, exposure, and the number of affected devices. This transforms the static list of vulnerabilities into a prioritized queue that enables faster response by focusing resources on the most critical issues first.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The patent implements feedback mechanisms where vulnerability data is continuously collected, analyzed, and used to update the prioritization of security issues. The system provides feedback to IT operations staff about which vulnerabilities require immediate attention based on real-time data about affected devices, software versions, and security contexts, enabling more efficient resource allocation and faster response times.

Inventive Principle:
Principle #23Feedback

3Measurement precision

If vulnerability data is collected from multiple sources including code analysis and scanning tools, then detection accuracy is improved, but the difficulty of correlating data to specific configuration items increases

Engineering Contradiction:
Improvevulnerability detection accuracyVSAvoiddata correlation difficulty
Core Design Contradiction:
Measurement precisionVSDifficulty of detecting and measuring

Solution Approach 1:

The patent creates a universal configuration item data structure that serves multiple functions: it stores software inventory information, device relationships, version data, and serves as the key for correlating vulnerability data from different sources. This multi-functional configuration item framework enables the system to handle data from code analysis tools, vulnerability scanners, and other sources using a common reference model, thereby reducing correlation difficulty.

Inventive Principle:
Principle #6Universality (Multi-functionality)

4Adaptability or versatility

If the remote network management platform integrates configuration items and vulnerability data, then new features and functionality are enabled, but the system complexity increases

Engineering Contradiction:
Improveplatform functionalityVSAvoidplatform complexity
Core Design Contradiction:
Adaptability or versatilityVSDevice complexity

Solution Approach 1:

The patent segments the remote network management platform into distinct functional modules: configuration item management, vulnerability data collection, data correlation engines, prioritization algorithms, and notification systems. This segmentation allows each component to be developed and maintained independently while working together to provide comprehensive vulnerability management functionality, thereby managing system complexity through modular architecture.

Inventive Principle:
Principle #1Segmentation

Data Source

PatentUS20240394383A1Software vulnerability detection in managed networks
Publication Date: 2024.11.28 SERVICENOW INC
  • US20240394383A1 patent drawing
  • US20240394383A1 patent drawing
  • US20240394383A1 patent drawing

AI summary

A system may include persistent storage containing representations of configuration items discovered in a managed network, where the configuration items include computing devices and software applications installed on the computing devices. One or more processors may be configured to: (i) obtain results of a vulnerability analysis performed on a software application, where the results indicate that the software application exhibits a vulnerability, (i) determine a count of computing devices on which the software application is installed, (iii) calculate a security threat score for the vulnerability, where the security threat score is based on a severity factor of the vulnerability and the count of computing devices, (iv) provide, to a first entity, a first indication of the software application and the vulnerability, and (v) provide, to a second entity, a second indication of the software application, the vulnerability, and the security threat score.