Software Image Remediation Using Threat-Intelligence Package Mapping

Resolve Bottlenecks,
Find Innovative Solutions
Generate Solutions

Solution Overview

Problem

Existing software image management systems lack efficient methods to identify and remediate vulnerabilities, leading to potential cybersecurity threats and operational disruptions.

Innovation Solution

A software image update management platform with integrated threat intelligence is used to identify vulnerable software images by leveraging software image recipes, allowing for automated rebuilding and redeployment based on cybersecurity data and code updates, thereby maintaining secure and efficient software image management.

Engineering Contradictions & Design Principles

VSEngineering Contradiction Analysis

1Reliability

If manual vulnerability assessment and remediation processes are used, then security coverage can be comprehensive, but the time required for vulnerability remediation increases significantly

Engineering Contradiction:
Improvesecurity coverageVSAvoidvulnerability remediation time
Core Design Contradiction:
ReliabilityVSLoss of time

Solution Approach 1:

The system performs preliminary actions by continuously monitoring software package updates and pre-identifying vulnerabilities before they are exploited. The image manager proactively scans for vulnerable packages, determines affected software images, and prepares remediation actions in advance, transforming reactive security responses into proactive prevention.

Inventive Principle:
Principle #10Preliminary action

Solution Approach 2:

The system implements feedback mechanisms by continuously monitoring cybersecurity data, analyzing vulnerability information, and using this feedback to automatically trigger remediation workflows. The image manager receives feedback from vulnerability databases, processes this information, and automatically initiates rebuilding of affected software images without human intervention.

Inventive Principle:
Principle #23Feedback

2Reliability

If frequent software image updates are performed to patch vulnerabilities, then security posture improves, but computational resources and operational time are consumed

Engineering Contradiction:
Improvesecurity postureVSAvoidcomputational resource consumption
Core Design Contradiction:
ReliabilityVSUse of energy by moving object

Solution Approach 1:

The system applies local quality by performing targeted updates only on specific software images that contain vulnerable packages, rather than updating all software images universally. The image manager identifies exactly which software images are affected by each vulnerability and applies remediation only to those specific instances, conserving computational resources.

Inventive Principle:
Principle #3Local quality

Solution Approach 2:

The system uses partial action by selecting and remediating only the critical vulnerabilities that affect deployed software images, rather than addressing all possible vulnerabilities in the software ecosystem. This selective approach balances security improvement with resource conservation.

Inventive Principle:
Principle #16Partial or excessive action

3Measurement precision

If comprehensive vulnerability scanning of all software images is performed, then all vulnerabilities are detected, but the complexity of the management system increases

Engineering Contradiction:
Improvevulnerability detection accuracyVSAvoidmanagement system complexity
Core Design Contradiction:
Measurement precisionVSDevice complexity

Solution Approach 1:

The system applies segmentation by breaking down the vulnerability management process into distinct components: package vulnerability scanning, software image composition analysis, affected image identification, and remediation execution. This modular approach maintains detection accuracy while reducing overall system complexity through organized functional separation.

Inventive Principle:
Principle #1Segmentation

Solution Approach 2:

The image manager acts as an intermediary that coordinates between vulnerability data sources, software image repositories, and remediation systems. This intermediary layer simplifies the overall system architecture by centralizing the coordination logic and providing a unified interface for vulnerability management operations.

Inventive Principle:
Principle #24Intermediary (Mediator)

4Productivity

If automated remediation workflows are implemented, then vulnerability response speed increases, but the risk of operational errors increases

Engineering Contradiction:
Improvevulnerability response speedVSAvoidoperational accuracy
Core Design Contradiction:
ProductivityVSReliability

Solution Approach 1:

The system performs preliminary validation actions before executing automated remediation. The image manager verifies vulnerability information, confirms affected software images, and validates remediation plans before implementation. This preliminary checking reduces the risk of operational errors while maintaining automated response speed.

Inventive Principle:
Principle #10Preliminary action

Data Source

PatentUS12511404B1Remediating vulnerabilities using software update management platform with integrated threat intelligence
Publication Date: 2025.12.30 MINIMUS LTD
  • US12511404B1 patent drawing
  • US12511404B1 patent drawing
  • US12511404B1 patent drawing

AI summary

A system and method for vulnerability remediation. A method includes identifying a vulnerable software package among a plurality of software packages based on cybersecurity data indicating a vulnerability; identifying at least one vulnerable software image of a plurality of software images by determining that the at least one vulnerable software image contains the vulnerable software package based on a plurality of files, wherein each of the plurality of software images is built based on a corresponding file of the plurality of files, wherein each file of the plurality of files includes a set of instructions for combining a subset of the plurality of software packages in order to build the corresponding software image of the plurality of software images; and performing at least one remediation action with respect to the at least one vulnerable software image.