Server Vulnerability Countermeasure Tailoring

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing methods for addressing vulnerabilities in information processing apparatuses do not consider the network environment, leading to inappropriate application of countermeasures that can decrease usability and are difficult to determine necessity for, due to lack of identification of the network environment.

Innovation Solution

A server apparatus that acquires vulnerability information and network environment details to determine the necessity of countermeasures, transmitting appropriate countermeasure settings to the information processing apparatus based on the analysis of vulnerability and network environment information.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If vulnerability countermeasures are applied without considering network environment, then security is improved, but usability decreases excessively

Engineering Contradiction:
ImprovesecurityVSAvoidusability
Core Design Contradiction:
ReliabilityVSEase of operation

Solution Approach 1:

The patent applies local quality by customizing vulnerability countermeasures according to specific network environments. Different information processing apparatuses receive different countermeasure recommendations based on their individual network conditions (e.g., whether connected to corporate network, public network, or isolated network), rather than applying uniform countermeasures to all devices. This ensures appropriate security measures are applied locally to each device's actual risk profile.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The patent changes parameters by introducing network environment characteristics as additional parameters for determining countermeasure necessity. The system evaluates multiple parameters including vulnerability severity, attack vector, and network environment type to dynamically adjust countermeasure recommendations. This parameter-based approach allows flexible adaptation of security measures to match actual risk levels without unnecessarily impacting usability.

Inventive Principle:
Principle #35Parameter changes

2Reliability

If vulnerability countermeasures are applied uniformly to all apparatuses, then security coverage is improved, but device complexity increases

Engineering Contradiction:
Improvesecurity coverageVSAvoidcountermeasure management complexity
Core Design Contradiction:
ReliabilityVSDevice complexity

Solution Approach 1:

The patent applies universality by creating a standardized countermeasure recommendation framework that works across diverse network environments and apparatus types. The system uses a universal evaluation methodology that can handle various vulnerability types and network configurations through a consistent process, simplifying management while maintaining comprehensive security coverage.

Inventive Principle:
Principle #6Universality (Multi-functionality)

Solution Approach 2:

The patent segments the vulnerability assessment process into distinct evaluation stages: network environment identification, vulnerability information acquisition, countermeasure necessity determination, and recommendation generation. This segmentation allows complex security management to be broken down into manageable steps, reducing overall system complexity while maintaining thorough security coverage.

Inventive Principle:
Principle #1Segmentation

3Measurement precision

If network environment identification is implemented, then countermeasure accuracy is improved, but information processing time increases

Engineering Contradiction:
Improvecountermeasure determination accuracyVSAvoidinformation processing time
Core Design Contradiction:
Measurement precisionVSLoss of time

Solution Approach 1:

The patent applies preliminary action by pre-establishing network environment classification categories and predetermined evaluation criteria for each environment type. Rather than analyzing every possible network condition from scratch, the system prepares advance frameworks for common network scenarios (corporate network, public network, isolated network), enabling faster assessment while maintaining accurate countermeasure determination.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS20240129333A1Server apparatus, information processing apparatus, and storage medium
Publication Date: 2024.04.18 CANON KK
  • US20240129333A1 patent drawing
  • US20240129333A1 patent drawing
  • US20240129333A1 patent drawing

AI summary

A server apparatus includes one or more memories and one or more processors. The one or more processors and the one or more memories are configured to acquire vulnerability information about an information processing apparatus, acquire information about a network to which the information processing apparatus is connected, and transmit, to the information processing apparatus, vulnerability countermeasure information based on the vulnerability information and the information about the network.