Predictive Vulnerability Management for Disconnected Endpoints

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Disconnected endpoints in enterprise systems remain vulnerable to security threats due to lack of timely software updates and communications from the endpoint management server, leading to potential security breaches when they reconnect to the network.

Innovation Solution

A predictive vulnerability management system that identifies predicted vulnerabilities for disconnected endpoints and performs preventive actions upon reconnection, including software updates and quarantining, to mitigate risks and protect the network.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If endpoints are disconnected from the network, then network security is maintained by isolating vulnerable devices, but the endpoints cannot receive timely software updates and security patches

Engineering Contradiction:
Improvenetwork securityVSAvoidtime to receive security updates
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary vulnerability assessment and predicts potential security issues while the endpoint is disconnected. By proactively identifying vulnerabilities before reconnection occurs, the system prepares remediation actions in advance, ensuring that security updates are applied immediately upon reconnection rather than waiting for the endpoint to remain disconnected indefinitely.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system dynamically adjusts the management approach based on the endpoint's connection status. While disconnected, the system performs predictive vulnerability analysis using available data. Upon reconnection, the system transitions to active remediation mode, applying updates and patches. This dynamic adaptation allows the system to maintain security effectiveness across varying connection conditions.

Inventive Principle:
Principle #15Dynamics

2Reliability

If endpoints remain connected to the network continuously, then they receive timely security updates, but vulnerable endpoints may expose the network to security threats

Engineering Contradiction:
Improvesecurity update timelinessVSAvoidnetwork security exposure
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system implements a feedback mechanism that continuously monitors endpoint vulnerability status and connection state. Based on this feedback, the system dynamically determines the optimal connection strategy - keeping secure endpoints connected for updates while isolating vulnerable ones. This feedback loop ensures that security decisions are based on real-time endpoint conditions rather than static policies.

Inventive Principle:
Principle #23Feedback

Solution Approach 2:

The system changes the connection parameter (connected vs. disconnected) based on vulnerability assessment results. Endpoints are evaluated on multiple parameters including software version, known vulnerabilities, and patch status. Based on this multi-parameter assessment, the system adjusts the connection state to optimize both security update delivery and network protection, transitioning endpoints between connected and disconnected states as needed.

Inventive Principle:
Principle #35Parameter changes

3Reliability

If predictive vulnerability management is implemented for disconnected endpoints, then security risks are reduced upon reconnection, but system complexity increases due to additional monitoring and analysis requirements

Engineering Contradiction:
Improvesecurity risk reductionVSAvoidvulnerability management system complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The predictive vulnerability management system operates autonomously without requiring continuous human intervention. The system automatically collects endpoint data, assesses vulnerabilities, predicts security risks, and executes remediation actions. This self-service capability reduces the operational complexity burden on administrators while maintaining comprehensive security monitoring and response functions.

Inventive Principle:
Principle #25Self-service

Solution Approach 2:

The system creates a virtual representation or model of the disconnected endpoint's security state based on available data. This copy includes software inventory, vulnerability information, and risk assessment results. By working with this copied security state model rather than requiring direct access to the physical endpoint, the system reduces complexity in monitoring and analysis while maintaining accurate vulnerability tracking.

Inventive Principle:
Principle #26Copying

Data Source

PatentUS11190537B2Vulnerability management of disconnected endpoints
Publication Date: 2021.11.30 CROWDSTRIKE
  • US11190537B2 patent drawing
  • US11190537B2 patent drawing
  • US11190537B2 patent drawing

AI summary

A first latest status of the one or more disconnected endpoints from a memory is retrieved. A set of predicted vulnerabilities for each of the one or more disconnected endpoints from the memory is retrieved. A set of preventive actions and policies associated with the set of predicted vulnerabilities to be performed when each of the one or more disconnected endpoints reconnects to the network is retrieved. The set of preventive actions and policies are retrieved from the memory. A determination is made whether at least one endpoint in the one or more endpoints not connected to the network reconnects to the network. If least one endpoint in the one or more endpoints not connected to the network has reconnected to the network, at least one preventive action from the set of preventive actions and policies on the at least one endpoint reconnected to the network is performed.