Software Execution Risk Scoring for Continuous Vulnerability Assessment

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Organizations face challenges in timely and cost-effective remediation of software vulnerabilities and bugs, with existing systems failing to efficiently prioritize and mitigate risks posed by malware exploits.

Innovation Solution

A continuous vulnerability assessment system that employs agents on computing devices to profile software characteristics, determine cumulative execution times, and assign security risk levels based on vulnerability and usage patterns, enabling prioritized mitigation efforts.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If organizations attempt to remediate all vulnerabilities and bugs, then security coverage is improved, but time consumption and cost increase significantly

Engineering Contradiction:
Improvesecurity coverageVSAvoidremediation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The patent applies local quality by differentiating vulnerability assessment across different software types and usage contexts. Instead of uniform remediation, the system assigns different security risk levels (1-10 scale) based on specific software characteristics, execution frequency, and vulnerability severity. This allows organizations to focus remediation efforts on high-risk areas while reducing effort on low-risk software, resolving the contradiction between comprehensive security coverage and remediation time/cost

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system changes the parameter of vulnerability assessment from binary (vulnerable/not vulnerable) to a continuous risk score (1-10 scale) that incorporates multiple factors including software execution time, vulnerability severity, and exploitability. This parameter transformation enables prioritized remediation by quantifying security risk, allowing organizations to address the most critical vulnerabilities first while maintaining overall security coverage

Inventive Principle:
Principle #35Parameter changes

2Reliability

If organizations remediate all vulnerabilities comprehensively, then security risk is reduced, but cost effectiveness deteriorates

Engineering Contradiction:
Improvesecurity risk reductionVSAvoidcost effectiveness
Core Design Contradiction:
ReliabilityVSEase of manufacture

Solution Approach 1:

The patent implements local quality by tailoring remediation intensity to specific software contexts. The system evaluates each software component's risk profile and assigns appropriate security measures, avoiding uniform expensive remediation across all software. High-risk software receives intensive remediation while low-risk software receives minimal intervention, maintaining security risk reduction while improving cost effectiveness

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system applies partial action by focusing remediation resources on the most critical vulnerabilities rather than attempting to fix all vulnerabilities equally. By identifying and addressing only the top-priority risks based on the risk scoring system, organizations achieve sufficient security risk reduction at lower cost, avoiding the diminishing returns of comprehensive remediation

Inventive Principle:
Principle #16Partial or excessive action

3Reliability

If the system assesses all software vulnerabilities equally, then assessment completeness is improved, but ability to prioritize critical issues deteriorates

Engineering Contradiction:
Improveassessment completenessVSAvoidprioritization capability
Core Design Contradiction:
ReliabilityVSProductivity

Solution Approach 1:

The patent transforms vulnerability assessment from a uniform process to a multi-dimensional risk scoring system. By introducing parameters such as software execution time, vulnerability severity, exploitability, and business criticality, the system maintains assessment completeness while enabling effective prioritization. The continuous risk score (1-10) allows organizations to identify and address critical issues first without missing lower-priority vulnerabilities

Inventive Principle:
Principle #35Parameter changes

4Productivity

If the system focuses on severe vulnerabilities first, then resource efficiency is improved, but comprehensive security coverage may deteriorate

Engineering Contradiction:
Improveresource efficiencyVSAvoidcomprehensive security coverage
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system applies preliminary action by continuously assessing and prioritizing vulnerabilities before they are exploited. The risk scoring system proactively identifies high-risk software combinations, allowing organizations to remediate critical issues before attacks occur. This preventive approach maintains comprehensive security coverage while improving resource efficiency by addressing threats in advance rather than reacting to incidents

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentEP4381405B1Continuous vulnerability assessment system
Publication Date: 2025.08.06 MORPHISEC INFORMATION SECURITY 2014
  • EP4381405B1 patent drawingFigure 1
  • EP4381405B1 patent drawingFigure 2
  • EP4381405B1 patent drawingFigure 3

AI summary

The embodiments disclosed herein are directed to a continuous vulnerability assessment system for detecting exploitable vulnerabilities. For example, an agent executes on a plurality of computing devices. Each agent profiles various pieces of software executing on its respective device and obtains various characteristics thereof. For instance, each agent determines, among other things, the length of time certain software executes on the device. Each agent provides descriptors of the determined characteristics to a vulnerability assessment engine. The engine determines a cumulative length of time that each particular piece of software executed across the plurality of computing devices. The engine also determines whether a vulnerability exists with respect to each particular piece of software, assigns a security risk level for the software based at least on the determined vulnerability and the cumulative length of time, and performs an action to mitigate the determined vulnerability based on the security risk level.