Risk-Based Application Control via Vulnerability Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Traditional perimeter defenses fail to prevent client-side exploits, as they do not account for vulnerabilities in client software and user permissions, leading to increased risk of network attacks.

Innovation Solution

A system and method that monitor and assess client applications for vulnerabilities by comparing application or file attributes to a vulnerability database, generating reports, and controlling application execution based on risk information and rules, thereby preventing or limiting the execution of vulnerable applications.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If traditional perimeter defenses (firewalls, web proxies) are used, then network infrastructure security is maintained, but client-side vulnerabilities cannot be prevented

Engineering Contradiction:
Improvesecurity effectivenessVSAvoidclient-side exploit risk
Core Design Contradiction:
ReliabilityVSObject-affected harmful factors

Solution Approach 1:

The system performs preliminary actions by proactively monitoring application execution and comparing attributes against vulnerability databases before exploits can occur. The solution continuously tracks application behavior, versions, and configurations in advance to prevent client-side vulnerabilities from being exploited, rather than reacting after compromise occurs.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The patent introduces an intermediary monitoring and assessment system that sits between traditional perimeter defenses and client applications. This intermediary layer collects application execution data, compares it against vulnerability information, and provides risk-based decisions, effectively bridging the gap between network-level security and application-level vulnerabilities.

Inventive Principle:
Principle #24Intermediary (Mediator)

2Measurement precision

If client-side application monitoring is implemented, then vulnerability identification improves, but system complexity increases

Engineering Contradiction:
Improvevulnerability detection accuracyVSAvoidmonitoring system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The monitoring system is segmented into modular components that collect, process, and analyze different aspects of application execution separately. The system divides complexity by organizing monitoring functions into distinct modules that handle specific tasks (e.g., tracking application launches, monitoring version attributes, detecting execution patterns) and can be independently managed and scaled.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The patent implements a universal monitoring framework that serves multiple functions: collecting execution data, tracking application versions, monitoring behavior patterns, and providing vulnerability assessments. This multi-functional approach consolidates what would otherwise be separate security tools into a single integrated system, reducing overall complexity despite enhanced detection capabilities.

Inventive Principle:
Principle #6Universality (Multi-functionality)

3Reliability

If continuous application monitoring and risk assessment is performed, then security coverage is enhanced, but processing time and resources increase

Engineering Contradiction:
Improvesecurity coverageVSAvoidprocessing time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system applies partial monitoring by focusing assessment resources on applications and execution patterns that pose the highest risk. Rather than uniformly analyzing all application behavior, the monitoring framework prioritizes actions based on vulnerability databases and risk thresholds, conducting detailed analysis only when conditions indicate potential threats, thereby reducing unnecessary processing time.

Inventive Principle:
Principle #16Partial or excessive action

Solution Approach 2:

The monitoring system employs periodic action by continuously updating vulnerability databases and periodically reassessing application risks rather than performing constant intensive analysis. The system maintains security coverage through scheduled updates and triggered assessments, balancing thorough monitoring with processing efficiency by acting at appropriate intervals rather than continuously at maximum intensity.

Inventive Principle:
Principle #19Periodic action

Data Source

PatentUS9467465B2Systems and methods of risk based rules for application control
Publication Date: 2016.10.11 BEYONDTRUST CORP
  • US9467465B2 patent drawing
  • US9467465B2 patent drawing
  • US9467465B2 patent drawing

AI summary

In various embodiments, an agent on a digital device may comprise a monitor module, an application identification module, a vulnerability module, a rules database, and a rule module. The monitor module may be configured to monitor a device for an instruction to execute a legitimate application. The application identification module may be configured to identify one or more attributes of the legitimate application. The vulnerability module may be configured to retrieve risk information based on the one or more attributes of the legitimate application. The risk information may be determined from known vulnerabilities of the legitimate application. The rules database may be for storing a rule associated with the risk information. The rule module may be configured to retrieve the rule from the rule database based on the risk information and to control the legitimate application based on the rule.