Network Vulnerability Remediation Logic Platform

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in managing and remediating vulnerabilities in network components due to the large number of devices and the need for efficient monitoring and control to prevent false notifications and ensure security.

Innovation Solution

A system and method for monitoring network components to identify vulnerabilities, implementing remediation plans, and suppressing reporting for acceptable vulnerabilities, allowing remote monitoring and control, including freezing or limiting network components, and creating customized exceptions to prevent false notifications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If remote monitoring and control of network components is implemented to improve security, then security is improved, but system complexity increases

Engineering Contradiction:
Improvenetwork securityVSAvoidsystem complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent introduces an intermediary system that acts as a mediator between network components and users/administrators. This intermediary automatically monitors network components, identifies vulnerabilities, determines acceptable use based on policies, and suppresses false notifications. By placing this intelligent intermediary in the middle, the system achieves improved security through automated remote monitoring while avoiding the complexity of direct manual management of numerous network components.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If monitoring of all network components is performed to identify vulnerabilities, then security detection is improved, but false notifications increase

Engineering Contradiction:
Improvevulnerability detection accuracyVSAvoidfalse notifications
Core Design Contradiction:
Measurement precisionVSLoss of information

Solution Approach 1:

The patent applies local quality by treating different network components and vulnerabilities differently based on their specific context. Instead of uniform monitoring and notification for all components, the system evaluates each vulnerability against organization-specific policies, acceptable use definitions, and component criticality. This localized approach allows the system to suppress notifications for acceptable vulnerabilities (reducing false notifications) while maintaining high detection accuracy for actual security threats.

Inventive Principle:
Principle #3Local quality

3Productivity

If remediation actions are automatically implemented for all vulnerabilities, then security response is improved, but operational disruption increases

Engineering Contradiction:
Improvesecurity response efficiencyVSAvoidoperational continuity
Core Design Contradiction:
ProductivityVSEase of operation

Solution Approach 1:

The patent implements preliminary action by pre-defining acceptable use policies and vulnerability thresholds before vulnerabilities occur. The system proactively establishes criteria for what constitutes acceptable versus unacceptable vulnerabilities, and pre-configures suppression rules. When vulnerabilities are detected, the system refers to these pre-established policies to determine appropriate actions, enabling rapid automated response for critical issues while avoiding unnecessary remediation of acceptable vulnerabilities, thus maintaining operational continuity.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS11265340B2Exception remediation acceptable use logic platform
Publication Date: 2022.03.01 BANK OF AMERICA CORP
  • US11265340B2 patent drawing
  • US11265340B2 patent drawing
  • US11265340B2 patent drawing

AI summary

The invention relates generally to monitoring and managing network components, such as monitoring the network components to determine the vulnerabilities of network components, implementing remediation plans for the vulnerabilities, instituting remediation suppression for the vulnerabilities, and taking consequence actions for the vulnerabilities when remediation is no longer suppressed and fails to be implemented. Remediation suppression may be implemented for the vulnerability when the vulnerability is determined to be an acceptable vulnerability. The remediation suppression may be based on a request from a user, based on organization policy, and/or based on logic determining that the vulnerability is acceptable. When the remediation suppression occurs at least a part of the remediation plan, consequence action, and/or reporting is suppressed. While suppression may occur, the remediation suppression, the vulnerabilities, the organization's policies, and/or the network components may still be monitored to monitor changes will change the suppression of the vulnerabilities.