Software Execution Risk Scoring for Continuous Vulnerability Assessment
Find Innovative SolutionsGenerate Solutions
Solution Overview
Problem
Organizations face challenges in timely and cost-effective remediation of software vulnerabilities and bugs, with existing systems failing to efficiently prioritize and mitigate risks posed by malware exploits.
Innovation Solution
A continuous vulnerability assessment system that employs agents on computing devices to profile software characteristics, determine cumulative execution times, and assign security risk levels based on vulnerability and usage patterns, enabling prioritized mitigation efforts.
Engineering Contradictions & Design Principles
Engineering Contradiction Analysis
1Reliability
If organizations attempt to remediate all vulnerabilities and bugs, then security coverage is improved, but time consumption and cost increase significantly
Solution Approach 1:
The patent applies local quality by differentiating vulnerability assessment across different software types and usage contexts. Instead of uniform remediation, the system assigns different security risk levels (1-10 scale) based on specific software characteristics, execution frequency, and vulnerability severity. This allows organizations to focus remediation efforts on high-risk areas while reducing effort on low-risk software, resolving the contradiction between comprehensive security coverage and remediation time/cost
Solution Approach 2:
The system changes the parameter of vulnerability assessment from binary (vulnerable/not vulnerable) to a continuous risk score (1-10 scale) that incorporates multiple factors including software execution time, vulnerability severity, and exploitability. This parameter transformation enables prioritized remediation by quantifying security risk, allowing organizations to address the most critical vulnerabilities first while maintaining overall security coverage
2Reliability
If organizations remediate all vulnerabilities comprehensively, then security risk is reduced, but cost effectiveness deteriorates
Solution Approach 1:
The patent implements local quality by tailoring remediation intensity to specific software contexts. The system evaluates each software component's risk profile and assigns appropriate security measures, avoiding uniform expensive remediation across all software. High-risk software receives intensive remediation while low-risk software receives minimal intervention, maintaining security risk reduction while improving cost effectiveness
Solution Approach 2:
The system applies partial action by focusing remediation resources on the most critical vulnerabilities rather than attempting to fix all vulnerabilities equally. By identifying and addressing only the top-priority risks based on the risk scoring system, organizations achieve sufficient security risk reduction at lower cost, avoiding the diminishing returns of comprehensive remediation
3Reliability
If the system assesses all software vulnerabilities equally, then assessment completeness is improved, but ability to prioritize critical issues deteriorates
Solution Approach 1:
The patent transforms vulnerability assessment from a uniform process to a multi-dimensional risk scoring system. By introducing parameters such as software execution time, vulnerability severity, exploitability, and business criticality, the system maintains assessment completeness while enabling effective prioritization. The continuous risk score (1-10) allows organizations to identify and address critical issues first without missing lower-priority vulnerabilities
4Productivity
If the system focuses on severe vulnerabilities first, then resource efficiency is improved, but comprehensive security coverage may deteriorate
Solution Approach 1:
The system applies preliminary action by continuously assessing and prioritizing vulnerabilities before they are exploited. The risk scoring system proactively identifies high-risk software combinations, allowing organizations to remediate critical issues before attacks occur. This preventive approach maintains comprehensive security coverage while improving resource efficiency by addressing threats in advance rather than reacting to incidents
Data Source
Figure 1
Figure 2
Figure 3
AI summary
The embodiments disclosed herein are directed to a continuous vulnerability assessment system for detecting exploitable vulnerabilities. For example, an agent executes on a plurality of computing devices. Each agent profiles various pieces of software executing on its respective device and obtains various characteristics thereof. For instance, each agent determines, among other things, the length of time certain software executes on the device. Each agent provides descriptors of the determined characteristics to a vulnerability assessment engine. The engine determines a cumulative length of time that each particular piece of software executed across the plurality of computing devices. The engine also determines whether a vulnerability exists with respect to each particular piece of software, assigns a security risk level for the software based at least on the determined vulnerability and the cumulative length of time, and performs an action to mitigate the determined vulnerability based on the security risk level.