Patch Deployment Index Analytics for Automated Patch Management

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large entities face challenges in efficiently managing the installation and deployment of software patches across multiple computing devices, requiring detailed reporting and analytics to ensure stability and resource optimization.

Innovation Solution

A system and method that determine whether to invoke a patch deployment tool based on historical patch deployment indices, comparing current and historical deployment rates to identify significant changes and trigger automated patch deployment when thresholds are met, utilizing a processor and receiver to analyze and act on patch deployment data.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Productivity

If automated patch deployment tools are invoked for all patches, then deployment speed increases, but resource consumption and system stability risks increase

Engineering Contradiction:
Improvepatch deployment speedVSAvoidsystem stability
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system changes the parameter of deployment automation by dynamically adjusting the automation level based on patch risk classification. High-risk patches are deployed manually while low-risk patches are deployed automatically, optimizing both speed and stability.

Inventive Principle:
Principle #35Parameter changes

Solution Approach 2:

The system performs preliminary analysis of patch deployment indices and historical data before invoking automated deployment tools. This preliminary action identifies patches suitable for automation, preventing resource consumption issues and stability problems before they occur.

Inventive Principle:
Principle #10Preliminary action

2Reliability

If manual verification of patch stability is performed, then system reliability improves, but deployment time increases

Engineering Contradiction:
Improvepatch stabilityVSAvoiddeployment time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system applies manual verification selectively rather than universally. Only patches exceeding the deployment index threshold undergo manual verification, while others are deployed automatically, reducing overall deployment time while maintaining reliability for critical patches.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The system changes the verification parameter by using automated index-based filtering to identify which patches require manual verification. This parameter change reduces the number of patches needing time-consuming manual checks while maintaining stability for high-risk deployments.

Inventive Principle:
Principle #35Parameter changes

3Ease of operation

If detailed reporting of patch deployment is implemented, then deployment control improves, but system complexity increases

Engineering Contradiction:
Improvedeployment controlVSAvoidreporting system complexity
Core Design Contradiction:
Ease of operationVSDevice complexity

Solution Approach 1:

The system extracts only the most critical deployment metrics and anomalies for reporting, rather than reporting all deployment data. This extraction provides effective deployment control while avoiding the complexity of comprehensive reporting systems.

Inventive Principle:
Principle #2Taking out (Extraction)

4Loss of information

If patch deployment monitoring is performed across multiple computing devices, then deployment visibility improves, but resource consumption increases

Engineering Contradiction:
Improvedeployment visibilityVSAvoidresource consumption
Core Design Contradiction:
Loss of informationVSUse of energy by moving object

Solution Approach 1:

The system performs monitoring at selective levels based on patch criticality and deployment index thresholds. Critical patches receive detailed multi-device monitoring while less critical patches receive summarized monitoring, reducing overall resource consumption while maintaining necessary visibility.

Inventive Principle:
Principle #16Partial or excessive action

Data Source

PatentUS9176727B2Infrastructure software patch reporting and analytics
Publication Date: 2015.11.03 BANK OF AMERICA CORP
  • US9176727B2 patent drawing
  • US9176727B2 patent drawing
  • US9176727B2 patent drawing

AI summary

A computer system for determining whether or not a tool for deploying a software patch should be invoked is provided. The system may include a receiver that receives information regarding patch deployment over a first pre-determined amount of time. The system may include a processor configured to determine, based on the historical information, a patch deployment index. The patch deployment index may characterize patch deployment as a number of patches deployed per unit time. The receiver may receive historical information regarding patch deployment over a second amount of time. The processor may use the historical information regarding patch deployment of the second pre-determined amount of time to determine a second patch deployment index. The processor may compare the first deployment to the second patch deployment index. When the difference between the second index and the first index is greater than a pre-determined threshold, the processor may invoke the tool.