Automated Security Patch Update Processor for Enterprise Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Large corporations face significant challenges in managing security patch updates for their computer systems, requiring extensive manual effort and custom scripts due to the frequency of patch releases, which can be costly and labor-intensive, especially when downtime is a concern.
Innovation Solution
A modular and configurable security patch update processor that uses the Microsoft Windows Server Update Services (WSUS) server to automate the scanning, downloading, and installation of patches, allowing system administrators to manage the timing of updates and reboots, reducing the need for custom scripts and minimizing downtime.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If manual patch management with custom scripts is used, then patches can be applied to each system, but the amount of IT department manpower and monthly maintenance work increases significantly
Solution Approach 1:
The patch management system performs self-service by automatically scanning systems, identifying required patches, downloading them from update servers, and applying updates without requiring custom scripts for each patch. The system autonomously manages the entire patch lifecycle, reducing IT department manpower while maintaining complete patch coverage across all systems.
Solution Approach 2:
The patent creates a universal patch management system that handles multiple functions (scanning, identification, downloading, installation, and verification) through a single integrated solution. This multi-functional system replaces numerous custom scripts with one versatile tool that can manage patches across diverse systems and configurations.
2Reliability
If patches are applied frequently to fix vulnerabilities, then system security is improved, but the labor-intensive sorting and testing of vulnerabilities increases workload
Solution Approach 1:
The system continuously monitors systems for vulnerabilities, automatically identifies required patches, and applies updates in a closed-loop feedback process. This automated feedback mechanism eliminates manual sorting and testing of vulnerabilities, maintaining high system security while dramatically improving IT department efficiency by removing repetitive manual tasks.
Solution Approach 2:
The patent replaces manual mechanical processes (IT staff sorting through vulnerabilities, manually testing and applying patches) with an automated computational system. This substitution eliminates labor-intensive activities while maintaining or improving security outcomes, thereby increasing overall IT department productivity.
3Stability of the object's composition
If patches are tested before production deployment, then system stability is ensured, but the time required for patch application increases
Solution Approach 1:
The system performs preliminary actions by automatically scanning and identifying required patches before deployment, preparing the patch installation process in advance. This preliminary identification and preparation reduces the actual deployment time while maintaining system stability through automated verification processes that ensure patches are appropriate for the target systems.
Solution Approach 2:
The patent enables continuous patch management where scanning, identification, downloading, and installation occur in an ongoing automated process rather than discrete manual steps. This continuous operation maintains system stability through consistent monitoring and updates while minimizing downtime by eliminating gaps between patch management activities.
4Reliability
If critical system patches are applied, then security vulnerabilities are fixed, but system downtime occurs which is costly
Solution Approach 1:
The system rushes through the patch application process by automating all steps (scanning, identification, downloading, installation) in rapid succession without manual intervention. This accelerated process minimizes the time systems are taken offline for patching, thereby reducing costly downtime while ensuring complete vulnerability remediation through thorough automated scanning and verification.
Data Source
AI summary
A method, system, and program product are provided for updating software deployed on computers in an enterprise computer network wherein each computer has a software update agent installed to enable the computer to receive software patch updates. The method includes determining a required software component and updates; determining a version of the agent and updating the agent if required; selecting a server from which required updates are to be downloaded; scanning a plurality of software components on a selected computer and comparing the components with updates available on the server to determine required updates; downloading the required patches from the server; and installing the patches on the selected computer. The system includes components that perform the method steps when operated on a computer in the network. A computer readable medium implements the method for updating software deployed on computers in a network.


