Rule-Based Vulnerability Remediation in Managed Networks
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Enterprises face inefficiencies in managing and remediating security vulnerabilities across their networks due to manual and disorganized processes, which can lead to time-consuming and inefficient remediation of security issues.
Innovation Solution
A computing system within a remote network management platform automatically groups and assigns vulnerable configuration items based on predefined rules and priorities, using a database to store information about configuration items and security vulnerabilities, allowing for efficient remediation by matching attributes and assigning tasks to appropriate IT support groups.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Productivity
If manual and disorganized processes are used for managing security vulnerabilities, then flexibility in handling individual cases is maintained, but remediation time and effort increase significantly
Solution Approach 1:
The patent segments the vulnerability management process by grouping configuration items with similar security vulnerabilities together. This segmentation allows remediation activities to be performed on groups of items simultaneously rather than individually, thereby improving productivity and reducing remediation time while maintaining the ability to handle individual cases when needed.
Solution Approach 2:
The patent implements preliminary action by pre-defining groups of configuration items based on their security vulnerabilities and attributes before remediation begins. This advance grouping and preparation of remediation plans enables faster response when vulnerabilities are discovered, eliminating the need to manually analyze and plan for each configuration item individually during the remediation phase.
2Productivity
If configuration items are grouped by security vulnerability and department, then remediation can be focused and efficient, but the complexity of managing multiple grouping criteria increases
Solution Approach 1:
The patent applies universality by creating a multi-functional grouping system that can simultaneously group configuration items by multiple criteria including security vulnerability type, department, and other attributes. This universal grouping mechanism handles diverse grouping requirements through a single standardized process, reducing the complexity that would otherwise arise from managing separate grouping systems for each criterion.
Solution Approach 2:
The patent introduces an intermediary grouping layer that acts as a mediator between the raw configuration item data and the remediation processes. This intermediary grouping structure organizes configuration items according to multiple criteria without requiring direct complex management of all possible combinations, simplifying the overall system by providing a standardized intermediate representation that remediation processes can work with efficiently.
3Productivity
If automatic grouping and assignment systems are implemented, then remediation processes become more efficient and standardized, but the initial setup and configuration complexity increases
Solution Approach 1:
The patent applies preliminary action by pre-configuring grouping rules and assignment criteria during the system setup phase. This preliminary configuration establishes the automatic grouping and assignment mechanisms before they are needed for actual remediation operations, allowing the system to then operate efficiently with minimal manual intervention. The initial setup complexity is paid off through sustained high productivity during remediation operations.
Data Source
AI summary
A computing system may include a database disposed within a computational instance of a remote network management platform that manages a managed network. Additionally, the computing system may include server device(s) disposed within the computational instance. The server device(s) may be configured to: compare, in order of priorities of assignment rules, a particular configuration item to the assignment rules until a matching condition is found, where the comparison includes consideration of one or more of: (i) particular item attributes of the particular configuration item or (ii) particular vulnerability attributes that apply to the particular configuration item; determine a particular remediator identifier related to the matching condition; based on a key and the particular remediator identifier, determine a particular group for the particular configuration item according to grouping rules; and store, in the database, a reference to the particular configuration item in the particular group.


