Automated Security Patch Update Processor for Enterprise Networks

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Large corporations face significant challenges in managing security patch updates for their computer systems, requiring extensive manual effort and custom scripts due to the frequency of patch releases, which can be costly and labor-intensive, especially when downtime is a concern.

Innovation Solution

A modular and configurable security patch update processor that uses the Microsoft Windows Server Update Services (WSUS) server to automate the scanning, downloading, and installation of patches, allowing system administrators to manage the timing of updates and reboots, reducing the need for custom scripts and minimizing downtime.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual patch management with custom scripts is used, then patches can be applied to each system, but the amount of IT department manpower and monthly maintenance work increases significantly

Engineering Contradiction:
Improvepatch application completenessVSAvoidnumber of custom scripts
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patch management system performs self-service by automatically scanning systems, identifying required patches, downloading them from update servers, and applying updates without requiring custom scripts for each patch. The system autonomously manages the entire patch lifecycle, reducing IT department manpower while maintaining complete patch coverage across all systems.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The patent creates a universal patch management system that handles multiple functions (scanning, identification, downloading, installation, and verification) through a single integrated solution. This multi-functional system replaces numerous custom scripts with one versatile tool that can manage patches across diverse systems and configurations.

Inventive Principle:
Principle #6Universality (Multi-functionality)

2Reliability

If patches are applied frequently to fix vulnerabilities, then system security is improved, but the labor-intensive sorting and testing of vulnerabilities increases workload

Engineering Contradiction:
Improvesystem securityVSAvoidIT department efficiency
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The system continuously monitors systems for vulnerabilities, automatically identifies required patches, and applies updates in a closed-loop feedback process. This automated feedback mechanism eliminates manual sorting and testing of vulnerabilities, maintaining high system security while dramatically improving IT department efficiency by removing repetitive manual tasks.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The patent replaces manual mechanical processes (IT staff sorting through vulnerabilities, manually testing and applying patches) with an automated computational system. This substitution eliminates labor-intensive activities while maintaining or improving security outcomes, thereby increasing overall IT department productivity.

Inventive Principle:
Principle #28Mechanics substitution (Replace mechanical system)

3Stability of the object's composition

If patches are tested before production deployment, then system stability is ensured, but the time required for patch application increases

Engineering Contradiction:
Improvesystem stabilityVSAvoidpatch deployment time
Core Design Contradiction:
Stability of the object's compositionVSLoss of time

Solution Approach 1:

The system performs preliminary actions by automatically scanning and identifying required patches before deployment, preparing the patch installation process in advance. This preliminary identification and preparation reduces the actual deployment time while maintaining system stability through automated verification processes that ensure patches are appropriate for the target systems.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent enables continuous patch management where scanning, identification, downloading, and installation occur in an ongoing automated process rather than discrete manual steps. This continuous operation maintains system stability through consistent monitoring and updates while minimizing downtime by eliminating gaps between patch management activities.

Inventive Principle:
Principle #20Continuity of useful action

4Reliability

If critical system patches are applied, then security vulnerabilities are fixed, but system downtime occurs which is costly

Engineering Contradiction:
Improvevulnerability remediationVSAvoidsystem downtime
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system rushes through the patch application process by automating all steps (scanning, identification, downloading, installation) in rapid succession without manual intervention. This accelerated process minimizes the time systems are taken offline for patching, thereby reducing costly downtime while ensuring complete vulnerability remediation through thorough automated scanning and verification.

Inventive Principle:
Principle #21Skipping (Rushing through)

Data Source

PatentUS12020014B1Security patch update processor
Publication Date: 2024.06.25 SUSE LLC
  • US12020014B1 patent drawing
  • US12020014B1 patent drawing
  • US12020014B1 patent drawing

AI summary

A method, system, and program product are provided for updating software deployed on computers in an enterprise computer network wherein each computer has a software update agent installed to enable the computer to receive software patch updates. The method includes determining a required software component and updates; determining a version of the agent and updating the agent if required; selecting a server from which required updates are to be downloaded; scanning a plurality of software components on a selected computer and comparing the components with updates available on the server to determine required updates; downloading the required patches from the server; and installing the patches on the selected computer. The system includes components that perform the method steps when operated on a computer in the network. A computer readable medium implements the method for updating software deployed on computers in a network.